ServerNova · Docs
Emails

Protect Yourself Against Phishing

By Atticus Sondergaard·Updated July 30, 2026·5 min read

Phishing is the most common way attackers get into a business — not by breaking through firewalls, but by tricking a person into handing over a password, approving a login, or paying a fake invoice. The good news: almost every phishing attempt has tells, and once you know them, you'll spot them fast. This article covers what phishing is after, how to recognize it, and exactly what to do when one lands in your inbox.

What Phishing Is Really After

A phishing message is any email, text, or call designed to manipulate you into doing something that helps an attacker. They're usually after one of four things:

  • Your password — by sending you to a fake login page that looks identical to the real one.

  • An MFA approval — by triggering a sign-in prompt and hoping you tap "Approve."

  • Money — a fake invoice, a "urgent" wire transfer, or a request to change vendor banking details.

  • A foothold — getting you to open an attachment or click a link that installs malware.

The attacker doesn't need to be sophisticated. They just need you to act before you think.

The Tells

Most phishing shares the same handful of red flags. Any one of these is reason to slow down; two or more is reason to report it.

  • A sender address that doesn't match the name. The display name says "Microsoft Support" but the actual address is a random Gmail or a lookalike domain like rnicrosoft.com (that's an "r" and "n," not an "m").

  • Manufactured urgency. "Your account will be deleted in 24 hours." "Pay this today or we lose the contract." Pressure is the point — it short-circuits your judgment.

  • A request for something sensitive. Passwords, MFA codes, payment, gift cards, or banking changes. Legitimate IT and vendors do not ask for these by email.

  • Links that don't go where they claim. The text says one thing; the actual destination is something else. Always preview before clicking (see below).

  • Unexpected attachments. Especially .html, .zip, or Office files asking you to "enable content."

  • A tone that's slightly off. A request from your CEO that feels rushed, secretive, or out of character. Trust that instinct.

The Kinds You'll Actually See

Type

What it looks like

Credential phishing

A fake login page for Microsoft 365, Google, or a bank, harvesting whatever you type.

Business Email Compromise (BEC)

An email appearing to come from your boss or a vendor asking for an urgent payment or a banking change.

MFA fatigue

Repeated sign-in approval prompts, hoping you'll tap "Approve" just to make them stop.

Quishing & smishing

A QR code in an email or a text message that takes you to a malicious site.

Never approve a sign-in prompt you didn't start. If your phone buzzes with an MFA approval and you weren't actively logging in, someone has your password. Deny it and report it immediately.

Check Before You Click

Two quick habits stop most attacks cold:

  • Preview every link. On a computer, hover your mouse over the link and read the real destination in the bottom corner of your screen. On a phone, press and hold the link to preview it. If it doesn't match what you expect, don't tap it.

  • Verify money and account requests out of band. If an email asks you to send a payment, change banking details, or buy gift cards, confirm it by calling the person on a phone number you already have — never the number in the email. This single habit prevents the most expensive attacks there are.

When you're unsure about an email, the safest move is to not interact with it at all — don't click, don't reply, don't open attachments. Report it and let the support team take a look.

When a Suspicious Email Lands

You spotted one. Here's what to do:

  • Don't click anything — no links, no attachments, no "unsubscribe."

  • Don't reply. A reply tells the attacker your address is live and monitored.

  • Report it using your email client's report-phishing button, or forward it to the support team. Reporting is what protects your coworkers, who likely got the same message.

  • Delete it after reporting.

If You Already Clicked

Mistakes happen, and speed matters more than blame. If you clicked a link, entered a password, or approved a prompt, act right away — in this order:

  1. Stop. Don't enter any more information on the page.

  2. Change your password from a device you trust, if you entered it anywhere.

  3. Contact the support team immediately. Tell them exactly what you clicked or entered. The faster we know, the faster we can sign the attacker out and lock things down.

  4. Watch for follow-on activity — unexpected emails sent from your account, new sign-in alerts, or messages your contacts received that you didn't send.

If you entered your password on a suspicious page, treat it as compromised. Change it and notify the support team now — even if it's after hours, even if you're not sure. A 10-minute head start is the difference between a non-event and a breach.

Why Attackers Love a Deadline

Nearly every phishing attempt manufactures urgency, because urgency is the enemy of good judgment. "Act now," "final notice," "the wire has to go out today" — these phrases exist to stop you from doing the one thing that defeats the attack: pausing to verify. When a message makes you feel rushed or anxious, that feeling is the strongest signal of all. Slow down. Verify through a channel you trust. The legitimate request will still be there in five minutes; the fake one falls apart the moment you check.

The One Rule That Covers Most of It

If you remember nothing else: when an email asks you to log in, pay, or approve something, and anything about it feels off — verify before you act. A quick phone call or a message to the support team costs you a minute. Getting it wrong can cost the company a great deal more, and we would always rather check a hundred harmless emails than miss the one that wasn't.

Was this helpful?