The display name says your bank or your boss; the actual address is a jumble or a lookalike domain (micros0ft-support.com). On a phone, tap the name to reveal the real address before you trust anything else about the message.
Your account will be closed today. The invoice is overdue. The gift cards are needed in an hour. Urgency is the attacker's tool for turning off your judgment. Real organizations almost never require action within minutes.
Hover over any link (or long-press on a phone) and read the real destination. If the text says your bank but the destination is an unrelated domain, you have your answer. When in doubt, do not click; type the site address yourself.
Invoices you were not expecting, voicemail attachments, shipping labels for packages you did not order. Attachments are how malware arrives. Verify with the sender through a different channel before opening anything unexpected.
Wire transfers outside the approval process, payroll changes by email, a vendor suddenly announcing new bank details. Any money-moving request that arrives only by email deserves a phone call to a number you already had, not one from the email.
Rules only help if everyone applies them every time. Continuous phishing awareness training, with short lessons and simulated tests, turns these checks into habit. ComDirect deploys training programs your team will actually complete, typically for a few dollars per user per month.
Key takeaways
- Check the real sender address, not the display name.
- Urgency is the weapon. Slow down when a message speeds you up.
- Verify links before clicking and attachments before opening.
- Money never moves on email alone. Call a number you already had.