← Back to Bits
Security Microsoft 365 IT Support
📅 17 July 2026

That Email Looked Real

That Email Looked Real

Someone in your business will click a dodgy email this year.

Not because they are careless. Because the email looked like a delivery notice, a bank alert, a Microsoft sign-in warning, or a message from the boss asking for "a quick favour". Phishing works when it feels ordinary.

This is not a lecture about never clicking anything. That advice is useless. This is about recognising the pattern, slowing down for thirty seconds, and putting proper controls in place so one bad click does not become a bad month.

What phishing actually is

Phishing is when someone pretends to be a trusted person or service so they can steal a login, a payment, or enough information to pretend to be you later.

Common flavours:

  • Fake login pages that look like Microsoft 365, your bank, or a shipping company
  • Invoice and payment scams ("Please pay this urgently, new bank details attached")
  • Boss or supplier impersonation ("Are you free? Need you to buy gift cards / transfer funds")
  • Attachment bait ("Updated roster" / "Overdue invoice" that drops malware)
  • Link bait that takes you somewhere almost right, except one letter is wrong

The goal is usually credentials or money. Sometimes both.

Why "it looked real" is the whole trick

Scammers do not send emails that say "I am a scammer, please click here".

They copy logos. They use your company name. They create urgency. They write just well enough to pass a busy Tuesday afternoon skim. Modern phishing can even look like it came from someone you know, because display names are easy to fake and stolen mailboxes get reused.

So if your only defence is "I would notice", you are already behind. Busy people miss details. That is not a character flaw. It is how work happens.

Red flags worth pausing for

You do not need a cybersecurity degree. You need a habit of checking a few boring things:

  1. The sender address, not just the name. "Microsoft Support" can still be microsoft-support@randommail.xyz. Hover (or long-press on mobile) and look at the actual address.
  2. Urgency plus fear. "Your account will be locked in 1 hour" and "Wire this now or the deal falls through" are classics for a reason.
  3. Unexpected attachments or links. Especially .html, .zip, or "secure document" links you were not expecting.
  4. Odd payment changes. New bank details by email alone should always get a second check through a known phone number or Teams call.
  5. Slightly wrong domains. micros0ft.com, rnicrosoft.com, extra hyphens, weird country endings.
  6. Requests that skip normal process. If your company never buys gift cards for "a client", do not start today because an email asked nicely.

One red flag is a reason to slow down. Two is a reason to stop and ask someone.

What to do instead of guessing

If an email feels off:

  • Do not click the link in the email to "check"
  • Go to the real site yourself (type it, use a bookmark, or open the Microsoft 365 app)
  • Contact the person through a channel you already trust (call them, message them in Teams)
  • Forward suspicious mail to whoever handles IT for you, or to your Microsoft 365 admin

In Microsoft 365, reporting tools and Safe Links / Safe Attachments (depending on your licence) help, but they are not magic forcefields. They reduce risk. They do not replace common sense.

MFA: the control that actually saves you

Passwords get phished. That is the point of many of these emails.

Multi-factor authentication (MFA) means a stolen password is not enough. The attacker also needs your phone prompt, authenticator app, or hardware key. For Microsoft 365, MFA is one of the highest-value switches a small business can turn on.

If your staff can sign into Microsoft 365 with only a password, you are one convincing login page away from someone reading your email, SharePoint, and Teams history.

Use the Microsoft Authenticator app where you can. Avoid SMS codes if you have a better option. Do not share MFA approvals with "IT support" who cold-called you. Real Microsoft support does not cold-call your mobile asking you to read out a code.

If you already clicked

Stay calm. Speed matters more than embarrassment.

  1. Disconnect from whatever you just did (close the tab, stop entering more details)
  2. Change the password for that account from a device you trust
  3. Check MFA is on, and review recent sign-in activity in Microsoft 365
  4. Tell whoever looks after your IT immediately
  5. Watch for follow-up scams ("We noticed unusual activity, click here again")

If you entered Microsoft 365 credentials on a fake page, treat it as urgent. Email is often the master key to password resets everywhere else.

The Reality Check

  • Perfect staff do not exist. Controls do.
  • Training helps. MFA helps more.
  • One shared "admin" mailbox password across five people is how incidents get worse.
  • If invoices and bank details routinely move by email with no second check, the process is the vulnerability, not the person who clicked.

You can teach people to spot phishing and still get caught on a bad day. Build the system so a bad day is recoverable.

The Bottom Line

Phishing works because it looks real enough, arrives at the wrong moment, and asks for one quick action.

Slow down on urgency. Check the real sender. Never trust payment changes from email alone. Turn on MFA for Microsoft 365. Have a simple "I think I clicked something" process that does not involve hiding under a desk.

If you want this set up properly (MFA, reporting, Safer defaults in Microsoft 365, a short staff briefing that does not put everyone to sleep), we can do that. Getting phished is expensive. Making one click less catastrophic is usually not. 🔒

Alex

Alex

Director