How to Spot a Phishing Email Targeting Your Small Business

How to Spot a Phishing Email Targeting Your Small Business

Phishing emails targeting small businesses have gotten significantly harder to spot. They used to be easy — obvious typos, generic greetings, requests that made no sense. Now they impersonate specific vendors, professional associations, and payment platforms your business actually uses, and they’re often formatted well enough that a quick scan doesn’t catch them.

This is a practical guide to what to look for before you click anything.

Start with the sender address, not the display name

The display name — the friendly “From” name that shows up in your inbox — can say anything. “Microsoft Support,” “Your Bank,” “Membership Services” — any of these can be set to display by anyone sending from any address. The actual sending address is what matters.

In most email clients, you can hover over the display name or click a “details” arrow to see the real address underneath. Look at the domain — the part after the @ symbol — and ask: is this actually the company it’s claiming to be? Legitimate communications from major organizations come from their actual domain. A renewal notice claiming to be from a professional association but sent from a generic or unrelated domain is a red flag regardless of how official the email looks.

Understand what authentication failures tell you

When an email fails DKIM or DMARC authentication, your email provider has determined that the message wasn’t sent from a server authorized to send on behalf of that domain. Most email clients don’t surface this clearly — they don’t put a red banner saying “authentication failed” — but many will show a warning, move the message to spam, or display a generic sender avatar instead of a recognized logo.

If you use Gmail, clicking the three-dot menu and selecting “Show original” will display the full email header including authentication results. Seeing “DKIM: FAIL” or “DMARC: FAIL” next to a sender claiming to be a trusted organization is definitive. Legitimate senders from major platforms pass both.

The urgency/threat pattern

Phishing emails rely on getting you to act before you think. The patterns are consistent:

  • Immediate action required or your account will be suspended
  • Unpaid charge that will auto-renew unless you call/click now
  • Suspicious activity detected on your account
  • Your membership/subscription has been flagged

Urgency is manufactured specifically to bypass the moment of pause where you’d think to verify independently. A legitimate organization that needs something from you will give you time and offer a way to verify through a channel you control — by going to their website directly in your browser, not through a link in the email.

Never use the contact information inside the email

This is the most important operational rule. If an email claims there’s a problem with your account and gives you a phone number to call or a link to click, do not use either to investigate. Go directly to the organization’s official website by typing the address yourself, or call a number you find independently. Phishing emails frequently include phone numbers that connect to the fraudster’s call center, staffed to collect payment details or account credentials from people who called to “verify” something.

Verify through a second channel before acting on any financial request

Any email requesting payment, requesting login credentials, or creating urgency around a financial account should be verified through a separate channel before you do anything. This is true even if the email looks exactly right, uses your real name, and references actual details about your account. Sophisticated phishing emails sometimes do. The second-channel check is what catches it.

What to do when you’re not sure

  • Don’t click any links in the email
  • Don’t call any number listed in the email
  • Go to the organization’s official website directly and log in from there
  • If you manage a team, forward a warning before others encounter the same email
  • If someone already clicked something or entered credentials, treat it as a confirmed breach: change passwords immediately and contact your financial institution if any payment information was involved

The WordPress connection

If your business runs a WordPress site, this applies in two directions: your email is a target, and your site is a target. Outdated plugins, weak admin passwords, and no two-factor authentication are the web equivalent of the same vulnerabilities phishing exploits in email. A post on WordPress security basics is coming — but if you want to look at your hosting environment’s built-in security features in the meantime, both Cloudways and Kinsta include malware scanning and firewall features as part of their managed hosting environments.

Disclosure: This post contains affiliate links. If you sign up through one, I may earn a commission at no extra cost to you.