Let us be honest about the setting. It is 4:47 on a Thursday. You have eleven unread messages, a customer on hold, and an email that says an invoice is overdue. The link is right there. Nobody in that moment is going to "carefully examine the sender's domain". So here is a guide built for the three seconds you actually have.
The three-second checks
- Were you expecting it? Unexpected invoice, unexpected parcel, unexpected password reset. "Unexpected" is the single best red flag there is.
- Is it in a hurry? "Within 24 hours", "account will be suspended", "final notice". Real organisations are boring and slow. Urgency is a tool.
- Hover, don't click. Rest the mouse on the link (or long-press on a phone) and read where it actually goes. If the text says Microsoft and the address says something-else.net, that is your answer.
- Who is it really from? The display name says your bank. The address behind it says a Gmail account with numbers in it. Display names are free to fake.
- Would they really ask this? Your CEO does not need gift cards. Your bank does not need your password. Your IT provider will never email a link asking you to "verify" anything — we know your name and your phone number.
The move that beats all of them
Don't use the link. If the email says your Microsoft account has a problem, open Microsoft the way you always do and look. If a supplier says an invoice is overdue, phone the number you already have for them — not the one in the email. Going in the front door takes thirty seconds and defeats almost every phishing attempt ever written.
If you clicked anyway
It happens to careful people. What matters is speed and honesty: close the page, do not enter anything further, and tell your IT team immediately. At Spicsoft, a call that starts "I think I clicked something" is treated as urgent and without judgement — we would much rather hear it at 4:48 than discover it on Monday. The systems we run are built on the assumption that someone, someday, will click; a reported click is a contained one.
A habit worth building
Forward suspicious emails to your IT team rather than deleting them. It costs you nothing, and it tells us who is being targeted and how — which is how we tune the filters so the next one never reaches you.

