How to spot a phishing email
Phishing is a type of fraud in which an email that appears to come from an organisation you know tricks you into handing over your password or card details, or into making a money transfer. Attackers may pose as a courier company, a bank, a government service, a software provider or a company executive. The tips below help you recognise a suspicious email within a few seconds.
In brief
- Look at the sender's real address and watch for urgent language.
- Check where a link leads before you click; read the domain name from right to left.
- Be suspicious of attachments you were not expecting and of "our bank account has changed" requests.
- If you clicked, change your password straight away and turn on two-factor authentication.
On this page
Steps to recognise a suspicious email
-
Check the sender address and the language
The display name ("Delivery Notification") and the real sender address can be different; click the address or hover over it to see it in full. Watch for small differences in the domain name. Urgent and threatening language such as "Your account will be closed within 24 hours" or "final warning" is used to make you act without thinking. Spelling mistakes used to be an important clue; today fake emails can be written in flawless English too.
: Enlarge -
Check the address before you click a link
On a computer, hover the mouse over the link (on a phone, press and hold the link); the real address appears. The text on the button and the address it leads to can be different. If in doubt, do not use the link; go to the organisation's website by typing the address into your browser yourself, or use its app.
: Enlarge -
Recognise lookalike domain names
Attackers use domain names that look very much like the real one: changing a single character (1 instead of l), inserting a hyphen or an extra word, using a different extension, or putting the real name at the front as if it were a subdomain (the actual domain of
company.com.example-site.xyzisexample-site.xyz). Read the domain name from right to left.
: Enlarge -
What should you do straight away if you clicked?
- Change the password of the account whose details you entered immediately; change it on any other accounts where you use the same password too.
- Turn on two-factor authentication for the account.
- If you entered card details, call your bank.
- If you opened an attachment, disconnect the device from the network and tell the person responsible for IT in your company.
- If it is a company email account, report the incident to the IT team; other people may have received the same email.
: Enlarge
Attachments to watch out for
- Attachments you were not expecting, such as invoices, delivery documents or "payment receipts".
- Compressed files (.zip, .rar), .html files or executable files.
- Office documents that ask you to "enable content" or allow macros when opened.
- A password-protected zip with the password written in the email: this can be used to get past browser protections.
Executive and IBAN fraud
Emails using the name of an executive or a supplier ask for an urgent payment, or give a new IBAN saying "our bank account has changed". Before paying on a request like this, verify it by calling the person on a phone number you already know; do not use the number in the email.
Reporting
Before deleting a suspicious email, report it to your company's IT team. Use the "report phishing" or "mark as junk" options in your email program. You can report phishing attempts that use an organisation's name to the organisation being impersonated and to your national CERT.
If you manage a website, your hosting panel and admin panel passwords are also phishing targets. For measures on the website side, start with the Website security guide.
Frequently asked questions
The site shows a padlock icon; is it safe?
The padlock icon only shows that the connection is encrypted. Fake sites can obtain an SSL certificate too. For details, see the guide What is SSL?
I only opened the email and did not click anything; is that a problem?
Usually, simply opening an email does no harm in itself; the risk lies in clicking a link, opening an attachment or entering information. Even so, report the email and delete it.
Would my bank or a government service ask for my password by email?
No. Trustworthy organisations do not ask for passwords, card details or verification codes by email. A request like that is a sign of phishing.
BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.
Related guides
- What is two-factor authentication and how do you turn it on?Add a second layer of security to your accounts: verification methods and the general route for Google and Microsoft accounts.
- How to create a strong password. What is a password manager?Long passwords that are never reused, passphrases, and how to use a password manager.
- What is SSL? What does SSL do on a website and in email?What https and the padlock on a website and the SSL setting in an email program protect, and how they differ.
- What is ransomware? The 3-2-1 backup ruleHow to protect yourself against ransomware, the 3-2-1 backup rule and what to do during an attack.
Let us review the security of your software together
BYK Yazılım supports the websites and software it develops with updates and security. Contact us with your questions.
Contact us Our corporate website service