Knowledge Base
Engineer Login
Back to Knowledge Base

How to Identify and Report Phishing Emails

Security & antivirus phishing email security awareness By Kerry · Updated 03/05/26 07:41 AM
Phishing emails attempt to steal credentials, financial information, or install malware by impersonating trusted senders. Train all staff to recognize the warning signs: urgency ('Your account will be closed in 24 hours'), mismatched sender domains (the display name says Microsoft but the actual email address is @random-domain.com), unexpected attachments, and requests for passwords or payment information. To check a suspicious link before clicking, hover over it (on desktop) to see the actual URL in the status bar. If the domain doesn't match the claimed organization, it's phishing. On mobile, press and hold the link to see the URL. When in doubt, go directly to the company's website by typing the URL manually rather than clicking the email link. If you receive a phishing email: do not click any links or open attachments. Report it using the 'Report Phishing' button in Outlook (installed by your IT team) or forward it to IT. If you accidentally clicked a link or entered credentials, immediately change your password and contact IT — time is critical for limiting damage. Document the sender address and subject line before deleting.