How to Spot and Avoid Phishing Emails Targeting Your Business
Phishing emails trick staff into revealing passwords, paying fake invoices or installing malware. Learn the warning signs, common scams aimed at businesses, and what to do if someone clicks.

Phishing is one of the most common ways criminals break into businesses. Instead of hacking systems directly, attackers send convincing messages that persuade someone to hand over a password, approve a payment or open a harmful attachment.
Phishing works because it targets people, and anyone can be caught off guard when busy. This guide explains the warning signs and practical steps to protect your team.
What phishing looks like
A phishing message pretends to come from someone you trust, such as a bank, supplier, government office, delivery company, colleague or your own IT or hosting provider. It usually asks you to do something quickly: log in, verify details, pay an invoice, or download a document.
Phishing is not limited to email. The same tricks appear in SMS messages, WhatsApp chats, social media messages and phone calls.
Common phishing scams aimed at businesses
Fake login pages
You receive an email saying your mailbox is full, your password has expired, or a shared document is waiting. The link leads to a page that looks like your webmail or cloud login. Anything you type goes straight to the attacker.
Invoice and payment fraud
An email appears to come from a known supplier saying their bank details have changed, or a “director” urgently asks the accounts team to make a payment. These scams can cost businesses large sums because the payment looks legitimate.
Domain and hosting renewal scams
Website owners often receive messages warning that their domain will be suspended unless they pay immediately through a link. Always check renewal status by logging in to your provider’s official client area directly, never through the link in the message.
Mobile money and delivery scams
SMS or WhatsApp messages claim a payment was sent by mistake, a parcel is waiting, or a prize has been won, and ask you to send money or share a PIN or verification code. Legitimate providers will never ask for your PIN.
Malicious attachments
Files disguised as quotations, purchase orders or CVs may contain malware. Be especially cautious with compressed files, macros in documents, and unexpected file types.
Warning signs to look for
- Urgency or threats: “Act within 24 hours or your account will be closed.”
- Mismatched sender address: The display name says your bank, but the email address is from an unrelated domain.
- Look-alike domains: Small spelling changes such as extra letters, swapped characters or a different extension.
- Suspicious links: Hover over a link (or press and hold on mobile) to see the real destination before clicking.
- Requests for secrets: Passwords, PINs, one-time codes or full card numbers.
- Unexpected changes: New bank details, new payment instructions or unusual requests from a senior manager.
- Generic greetings: “Dear customer” instead of your name, though targeted attacks may use your real name.
- Poor formatting: Odd grammar, blurry logos or inconsistent branding, although many phishing emails now look very professional.
Practical steps to protect your business
Verify through a separate channel
If a message asks for payment, changed bank details or login credentials, confirm it by calling the person or company on a phone number you already know, not one provided in the message.
Use two-factor authentication
Enable two-factor authentication on email, hosting control panels, banking and social media accounts. If a password is stolen, the attacker still needs the second factor. Never share one-time codes with anyone.
Set up email authentication for your domain
If your business uses email on its own domain, configure SPF, DKIM and DMARC DNS records. These help receiving mail servers detect messages that pretend to come from your domain, reducing the chance criminals can impersonate you to your customers.
Create a payment verification rule
Agree an internal rule that any new payee or change to bank details must be verified by phone and approved by two people. This single process stops many invoice fraud attempts.
Train your team regularly
Share real examples of suspicious messages, explain the warning signs, and make it easy and blame-free for staff to report anything suspicious.
Keep devices updated
Install operating system, browser and antivirus updates promptly so malicious attachments are less likely to succeed.
What to do if someone clicks
- Do not panic, and act quickly. Speed limits the damage.
- Change the password of any account where details were entered, and any other account using the same password.
- Enable two-factor authentication if it was not already on.
- Check email settings for new forwarding rules or filters an attacker may have added.
- Contact your bank immediately if payment details were shared or a payment was made.
- Scan the device for malware if an attachment was opened.
- Warn colleagues and contacts in case they receive similar messages from your account.
- Report it to your IT support or hosting provider so they can help investigate.
A quick phishing checklist
- Was I expecting this message?
- Does the sender’s actual email address match the organisation?
- Does the link go where it claims to?
- Is it asking for a password, PIN, code or payment?
- Is it creating pressure to act immediately?
- Can I verify it using a contact method I already trust?
Final thoughts
Technology helps, but alert people are the strongest defence against phishing. Build simple verification habits, protect accounts with two-factor authentication, and encourage your team to pause and check before clicking.
Salama Hosting will never ask you for your password by email. If you receive a suspicious message about your domain, hosting or email service, log in to your client area directly or contact support@salamahosting.com to confirm.

