A phishing email in 2026 rarely looks suspicious. It arrives as a payroll notice, a shared document or a Microsoft 365 password warning, written in fluent English and styled exactly like the real thing. The tell is almost never the wording — it is the sender address, the link destination and the manufactured urgency. Check those three things every time and you will catch the majority of what lands in your inbox.
TL;DR
- Check the sender's full email address first, not the display name — the domain is the tell.
- Hover over links before clicking: the destination domain must match the story the email tells.
- Urgency is the attacker's tool. Real organisations rarely give you 24 hours to act.
- A sign-in link you did not request is a lure — especially for myGov, Microsoft 365 and email portals.
- Report anything suspicious through your report button; one in three untrained staff click, trained teams report.
How to spot a phishing email: the 9 red flags
Run this list on any email that asks you to click, log in, pay or reply:
- Sender domain mismatch. The display name says "Payroll" but the address is payroll@hr-portal-support.com or a free Gmail account. Compare the domain after the @ against the one the real service uses — one swapped letter (micros0ft.com, anz-bank.com.au) is the whole trick.
- A link that doesn't match its label. Hover (or long-press on mobile) before clicking. If the button says "View invoice" but the destination is a lookalike domain or a link-shortener, it is a lure.
- Manufactured urgency. "Your account will be suspended in 24 hours." "Final notice." "Payment failed — act now." Genuine organisations give you time, and urgent pressure is how attackers stop you from checking.
- Generic or odd greeting. "Dear customer" from a service that knows your name is a flag, but so is your full name in an email from a colleague who has never used it.
- Unexpected attachments. An invoice you never ordered, a "voice message" or a zipped "document" from an unknown sender. Attachments from outside your usual circle get reported, not opened.
- A request to change payment details. Any email asking you to update a supplier's bank account is treated as fraud until verified by phone, using the number you already have — never the one in the email.
- A sign-in link you did not request. myGov will never email you a sign-in link, and Microsoft 365 does not expire passwords by email. Reset links you did not trigger are credential-harvesting pages.
- MFA prompts you didn't start. A push notification asking you to approve a sign-in is not a technical glitch — approving it hands over the account. Deny it and report it.
- Too good, or too bad, to be true. Tax refunds, parcel fees on a package you did not order and overdue-bill threats from agencies you have never dealt with are all recurring scam patterns.
The common lures right now
| Lure | What it looks like | The tell |
|---|---|---|
| Microsoft 365 password expiry | A branded "password expires in 72 hours" email | Microsoft does not email expiry warnings; check the sending domain |
| myGov / Centrelink impersonation | "Your Medicare details need updating" | myGov never sends sign-in links by email or text |
| Invoice and payment redirection | A supplier's "updated bank details" letter | Verify by phone on a number you already hold, every time |
| Shared document | "Sarah shared 'Payroll_2026.xlsx'" | The invitation comes from a personal or lookalike account |
| IT help desk reply | "Your mailbox is full, confirm credentials" | Your real IT team is reachable through a known channel |
Australia's National Anti-Scam Centre collects these patterns on Scamwatch, which publishes current alerts and takes reports from the public.
Why spotting matters: the numbers
Before any training, 33.2% of employees are likely to click a malicious email or comply with a fraudulent request — one in three. Twelve months of continuous security awareness training and simulated phishing cuts that figure to 4.2%, an 87% reduction (KnowBe4, 2026 Phishing by Industry Benchmarking Report).
The stakes behind one click: roughly 60% of data breaches involve a human element — an error, a clicked link or a manipulated employee (Verizon, 2025 DBIR). And in Australia the average self-reported cybercrime cost to a small business is $56,571 per incident (ASD, Annual Cyber Threat Report 2024-25).
The six-second check
Before you act on any email that wants something from you:
- Sender. Read the full address after the @. Does the domain match the organisation it claims to be?
- Link. Hover. Does the destination match the story?
- Context. Were you expecting this? Does the request make sense from this sender, at this hour, in this tone?
If any one of the three fails, stop. You can report a suspicious email in under a minute; recovering a hijacked mailbox takes weeks.
Trained staff spot more — and report more
Recognition is a habit, not a talent. Teams running regular phishing simulations practise the six-second check on realistic lures every month, and the click-prone share of staff falls from 33.2% to 4.2% over a year of security awareness training. Report rate is the metric to watch alongside clicks: a rising report rate means staff are flagging lures even when they hesitate.
What to do when you spot one
- Do not click, reply, open attachments or call numbers listed in the email.
- Use your report-phishing button or forward it through the approved internal channel — ask IT which route applies before you need it.
- If you already clicked, say so immediately. A fast report is worth more than a perfect silence.
- Report scam attempts to Scamwatch, and cybercrime to ReportCyber.
FAQ
What is the single biggest phishing red flag? The sender's domain. Display names are trivially faked; a mismatched or lookalike domain is the tell in most phishing emails.
Can phishing emails have perfect spelling and grammar? Yes — most now do. Fluent, well-formatted email is the 2026 norm for phishing; the old "bad grammar" rule catches almost nothing.
How do I check where a link really goes? Hover over it on desktop, or press and hold on mobile, and read the destination domain. On unknown shorteners, do not click at all.
Is an email from my CEO asking for a quick payment real? Verify by phone or in person before paying anything. Executive impersonation is one of the most expensive scams a business can receive.
What if the email looks exactly like our real payroll provider? Log in by navigating to the provider's site yourself — never through the emailed link. If the notice was real, the same message is waiting in your account.
Should I reply to ask if it's genuine? No. Replying confirms your address is live and hands the attacker information. Report it instead.
What percentage of staff fall for phishing without training? 33.2% globally before any training (KnowBe4, 2026) — one in three employees.
One last thing
Report the email even when you are sure it is fake and even when you did not click. Reports are how the rest of the team hears about a live campaign within minutes instead of after payroll asks why nobody warned them.