2. Spotting phishing emails
Links and attachments
Links and attachments are the payload of most phishing emails. The message exists only to get you to interact with one of them.
The text is not the link
The clickable text of a link and its real destination are two separate things. An email can display "https://www.yourbank.co.uk" while actually pointing at an attacker's site. Buttons like "Review document" or "Verify account" hide the destination entirely.
What checking a link safely means
Checking a link safely means seeing where it really goes without clicking it:
- On a computer, hover your mouse over the link and read the destination in the preview or status bar
- On a phone, press and hold the link until a preview of the address appears, then read it carefully before deciding
- Read the domain right to left, as covered in the previous lesson, and ignore familiar words earlier in the address
If the destination looks wrong, or you simply cannot tell, do not click. Instead, go direct: open your browser and type the organisation's address yourself, use a saved bookmark, or open their official app. If the message was genuine, whatever it wanted you to see will be there when you log in normally. This one habit defeats the majority of credential phishing outright.
Be aware that shortened links (bit.ly and similar) and links that pass through redirect services hide the final destination. Treat them with extra caution in any unexpected message.
Attachments
Unexpected attachments deserve the same suspicion as links. Common patterns include:
- Fake invoices, remittance advice, purchase orders, or CVs
- Office documents that ask you to "enable macros" or "enable content" when opened. That prompt is a major red flag, as enabling macros can run malicious code
- HTML attachments that open a fake login page directly on your machine, bypassing web filters
- Archive files (.zip, .rar) used to smuggle malicious files past scanners
The test is always the same: were you expecting this, from this person, in this format? If not, verify with the sender through a separate channel, such as a phone call or Teams message, before opening anything. Never verify by replying to the email itself, because if the account is compromised, the attacker answers.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice