How to Recognize and Report Phishing and Spoofing Emails?
Every day, cybercriminals send millions of fake emails designed to look like they come from trusted sources—such as your bank, your hosting provider, or even your own company’s management.
These fall into two categories:
-
Phishing: Emails designed to trick you into giving away passwords, credit card numbers, or downloading malicious attachments.
-
Spoofing: A technique where scammers forge the "From" address of an email so it appears to be sent from someone you know.
Learning how to spot these threats protects your business data and keeps your email account secure.
1. How to Spot the Red Flags?
Phishing attacks have become highly sophisticated, but scammers almost always leave clues. Use the following checklist when reviewing a suspicious message:
Check for Fake Email Headers (The "From" Address)
Scammers can easily change the "Display Name" on an email to say whatever they want (e.g., "Company Support").
-
Look past the name: Always look at the actual email address inside the brackets next to the name.
-
Watch for look-alikes: A real email might be
[email protected], while a spoofed domain might look like[email protected]or[email protected].
Unmask Deceptive Links
Never click a link in an email without checking where it goes first.
-
The Hover Trick: Hover your mouse cursor over the link or button without clicking it. A small box will pop up showing the real web destination (URL).
-
Analyze the URL: If the text says "Click here to login to your Webmail" but the hover text shows a completely unrelated website (like
[http://fake-login-site.xyz](http://fake-login-site.xyz)), do not click it.
Psychological Triggers
-
Urgency Cues: Phishing relies on panic. Look out for phrases like "Your account will be suspended in 24 hours" or "Unauthorized login attempt detected—reset your password immediately."
-
Generic Greetings: If an email from an organization you do business with addresses you as "Dear Customer" or "Dear Email User" instead of your actual name, treat it with caution.
-
Spelling & Grammar Errors: While some modern phishing emails use perfect English, many still contain odd phrasing, random capitalization, or blatant typos.
2. What to Do If You Receive a Suspicious Email?
If an email looks suspicious, your best defense is caution. Follow these safety rules:
-
Do NOT click any links: Clicking can take you to a fake login page designed to steal your password.
-
Do NOT download malicious attachments: Files ending in
.exe,.scr,.zip, or even macro-enabled Word/Excel documents can install malware or ransomware on your computer. -
Verify out-of-band: If the email claims to be from a colleague or a known supplier asking for money or a password change, call them or message them on WhatsApp to verify. Do not reply directly to the email.
3. How to Safely Report and Handle Spam/Phishing?
When you find a phishing or spam email in your mailbox, do not just delete it. Reporting it helps train the server's spam filters to block similar attacks from reaching you or your colleagues in the future.
In Webmail (Roundcube)
-
Log into your Webmail account.
-
Click on the suspicious email to highlight it.
-
Click the Spam button (often shaped like a stop sign or a hand icon) in the top menu bar. This moves the email to your Junk folder and alerts the system.
In Mail Clients (Outlook / Thunderbird)
-
Outlook: Right-click the message, hover over Junk, and click Block Sender or Report Junk.
-
Thunderbird: Click the Junk button on the message header area.
⚠️ Important Note: If you believe you accidentally clicked a link and entered your email password into a suspicious page, change your email account password via Webmail or cPanel immediately and contact your system administrator.