Skip to content
Let’s plan the right software for your processes. Call us for a demo or a quote: +90 546 737 48 29

TR EN DE

How to spot a phishing email

Phishing is a type of fraud in which an email that appears to come from an organisation you know tricks you into handing over your password or card details, or into making a money transfer. Attackers may pose as a courier company, a bank, a government service, a software provider or a company executive. The tips below help you recognise a suspicious email within a few seconds.

In brief

  • Look at the sender's real address and watch for urgent language.
  • Check where a link leads before you click; read the domain name from right to left.
  • Be suspicious of attachments you were not expecting and of "our bank account has changed" requests.
  • If you clicked, change your password straight away and turn on two-factor authentication.
On this page

Steps to recognise a suspicious email

  1. Check the sender address and the language

    The display name ("Delivery Notification") and the real sender address can be different; click the address or hover over it to see it in full. Watch for small differences in the domain name. Urgent and threatening language such as "Your account will be closed within 24 hours" or "final warning" is used to make you act without thinking. Spelling mistakes used to be an important clue; today fake emails can be written in flawless English too.

    Drawing of a fake email with numbered markers: different sender address, urgent language, suspicious link and attachment : Enlarge
  2. Check the address before you click a link

    On a computer, hover the mouse over the link (on a phone, press and hold the link); the real address appears. The text on the button and the address it leads to can be different. If in doubt, do not use the link; go to the organisation's website by typing the address into your browser yourself, or use its app.

    Drawing: the real link address appears when hovering over a button : Enlarge
  3. Recognise lookalike domain names

    Attackers use domain names that look very much like the real one: changing a single character (1 instead of l), inserting a hyphen or an extra word, using a different extension, or putting the real name at the front as if it were a subdomain (the actual domain of company.com.example-site.xyz is example-site.xyz). Read the domain name from right to left.

    Examples: a real domain name next to fake addresses with a changed character, an added word and a disguised subdomain : Enlarge
  4. What should you do straight away if you clicked?

    1. Change the password of the account whose details you entered immediately; change it on any other accounts where you use the same password too.
    2. Turn on two-factor authentication for the account.
    3. If you entered card details, call your bank.
    4. If you opened an attachment, disconnect the device from the network and tell the person responsible for IT in your company.
    5. If it is a company email account, report the incident to the IT team; other people may have received the same email.
    Flowchart: change the password, two-factor authentication, bank, disconnect the device, report : Enlarge

Attachments to watch out for

  • Attachments you were not expecting, such as invoices, delivery documents or "payment receipts".
  • Compressed files (.zip, .rar), .html files or executable files.
  • Office documents that ask you to "enable content" or allow macros when opened.
  • A password-protected zip with the password written in the email: this can be used to get past browser protections.

Executive and IBAN fraud

Emails using the name of an executive or a supplier ask for an urgent payment, or give a new IBAN saying "our bank account has changed". Before paying on a request like this, verify it by calling the person on a phone number you already know; do not use the number in the email.

Reporting

Before deleting a suspicious email, report it to your company's IT team. Use the "report phishing" or "mark as junk" options in your email program. You can report phishing attempts that use an organisation's name to the organisation being impersonated and to your national CERT.

If you manage a website, your hosting panel and admin panel passwords are also phishing targets. For measures on the website side, start with the Website security guide.

Frequently asked questions

The site shows a padlock icon; is it safe?

The padlock icon only shows that the connection is encrypted. Fake sites can obtain an SSL certificate too. For details, see the guide What is SSL?

I only opened the email and did not click anything; is that a problem?

Usually, simply opening an email does no harm in itself; the risk lies in clicking a link, opening an attachment or entering information. Even so, report the email and delete it.

Would my bank or a government service ask for my password by email?

No. Trustworthy organisations do not ask for passwords, card details or verification codes by email. A request like that is a sign of phishing.

BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.

Related guides

Let us review the security of your software together

BYK Yazılım supports the websites and software it develops with updates and security. Contact us with your questions.

Contact us Our corporate website service