Cyber Secure

How to spot a phishing email before it costs you

← Back to blog

September 20, 2026 · 4 min read

Most successful scams don't rely on clever hacking — they rely on someone in a hurry clicking without checking. These five checks take under a minute and catch the vast majority of phishing emails we see land in New Zealand inboxes.

1. Check who it's really from

The display name can say anything. Tap or hover on the sender's name to see the actual email address behind it — a message claiming to be from your bank or Xero should come from that company's real domain, not a lookalike or a free email address.

2. Slow down on urgency

"Your account will be suspended," "invoice overdue — pay immediately," "unusual sign-in detected" — manufactured urgency is the single biggest tell. Legitimate organisations very rarely demand instant action by email.

3. Hover before you click

On a computer, hover over any link without clicking to see where it actually leads, shown at the bottom of the screen. On a phone, press and hold. If the address doesn't match the company it claims to be from, don't click it.

4. Be suspicious of unexpected attachments

An invoice, delivery notice or "signed document" you weren't expecting — especially a .zip, .exe, or a Word or Excel file asking you to "enable content" — is one of the most common ways ransomware gets a foothold. If in doubt, ring the sender on a number you already have, not one in the email.

5. Check for the small stuff

Slightly odd phrasing, an unfamiliar greeting, a logo that's not quite right or a reply-to address that doesn't match the sender are all worth a second look. Scammers have gotten better at this, but the small inconsistencies are usually still there if you're looking for them.

Already clicked something?

Disconnect the device from Wi-Fi, don't enter any more details anywhere, and get in touch straight away — the sooner we look at it, the more options there are. If you gave away a password, change it immediately on a different device and turn on multi-factor authentication if it isn't already on.

Want your whole team trained to catch these, plus monitoring that catches what slips through? That's what Cyber Secure is for.