Free phishing checklist: spot phishing in 8 steps

Phishing is responsible for the vast majority of all cyberattacks. With this free checklist, every employee can recognise a suspicious email or message. No email address needed, no form: print the checklist out, pin it up at the desk or share it with your team.

1

Is the sender genuine?

Check the full email address, not just the display name. Watch for strange domains, extra characters or an almost-but-not-quite company name (for example @micros0ft-support.com).

2

Are you being pressured?

Phishing plays on urgency and fear: "act within 24 hours", "your account will be blocked", "final warning". Pressure to act quickly is a classic alarm signal.

3

Is the greeting strange?

An impersonal greeting ("Dear customer") from a company that knows your name, or conversely a suspiciously personal tone from a stranger, can indicate a mass-sent or targeted phishing attempt.

4

Where does the link really lead?

Hover over a link (without clicking) and look at the real address. Does the domain differ from the company, or do you see a strange string of characters or a shortened URL? Do not click.

5

Is there an unexpected attachment?

Unexpected attachments, especially file types such as .zip, .html or documents that ask for macros, are dangerous. Not expecting the file? Do not open it and verify with the sender via another channel.

6

Is it asking for data or money?

Does the message ask for your password, login details, a payment or an urgent transfer? Trustworthy organisations never ask for this by email. Always verify via a known, official channel.

7

Do the language and layout add up?

Watch for spelling mistakes, strange sentence structure, blurry logos or a layout that differs slightly from the real company. Note: AI is making phishing increasingly flawless, so spelling mistakes are sometimes absent.

8

Is it too good or too strange?

An unexpected prize, refund or an unusual request from "the director" to arrange something quickly: when in doubt, always verify. Report suspicious messages to your IT or security contact.

Want your whole team to learn to spot phishing?

A checklist is a good start, but real resilience comes from practice. With Lumyo's phishing training and simulations, your whole team learns to recognise suspicious messages - and you measure the progress.

View phishing training Get in touch