How to spot scam and fraudulent emails

Why scam and fraudulent emails are still a common threat
Email remains one of the most direct ways for attackers to reach people. Despite better filters and more awareness, fraudulent messages keep landing in inboxes because they exploit something technology cannot fully protect: human trust. A well-crafted message can look exactly like a note from a manager, a supplier, or a familiar service. Attackers know that a busy professional scanning dozens of emails is more likely to click without thinking. That single moment of distraction is what the whole scam is designed around. In France, as elsewhere, organisations of every size receive these attempts daily, from crude mass mailings to carefully targeted messages aimed at a specific team or role. The cost is not only financial. A successful scam can expose customer data, damage relationships, and force colleagues to spend days cleaning up. Understanding why these emails persist helps you treat every message with a healthy, calm level of scrutiny rather than fear. The goal is not to distrust everyone, but to build a reliable habit of checking before you act. Awareness spread across a whole team is far stronger than any single filter, because each person becomes an extra line of defence for their colleagues.
Common types of scam and fraudulent emails to recognise
Scam emails come in several recognisable forms, and knowing the categories makes them easier to spot. Phishing is the most widespread: a message pretending to be from a trusted organisation, asking you to log in, confirm details, or update a password through a fake page. Spear phishing is a targeted version, using your name, job title, or recent activity to feel more convincing. Business email compromise, sometimes called CEO fraud, impersonates a senior colleague and pressures you to make an urgent payment or share sensitive information. Invoice fraud sends fake or altered bills, often changing bank details so payments go to the attacker. Then there are prize and lottery scams promising money you never entered to win, and fake delivery notices claiming a parcel is waiting behind a small fee. Extortion emails may claim to have compromising material and demand payment. Each type has a different hook, but they share the same aim: to make you act quickly and bypass your usual checks. Recognising the pattern behind a message matters more than memorising every variation, because attackers constantly change the surface details while the underlying trick stays the same.
A step-by-step checklist to identify a suspicious email
Having a simple routine turns instinct into a reliable process. When an email arrives, pause before clicking anything and work through a short mental checklist. First, ask whether you were expecting this message at all. An unexpected request, especially one involving money, passwords, or personal data, deserves extra care. Second, check the sender's full email address rather than just the display name, because names are easy to fake. Third, read the tone: does it create urgency, threaten consequences, or promise a reward? Fourth, look at how you are addressed. Generic greetings like 'Dear customer' from an organisation that knows your name can be a clue. Fifth, hover over any link without clicking to see where it really leads. Sixth, be cautious with attachments you did not request, particularly files that ask you to enable content or macros. Seventh, notice spelling, grammar, and formatting that feels slightly off. Finally, trust your instinct. If something feels wrong, it often is. No single sign proves a scam on its own, but several together should stop you from acting. Keeping this checklist visible near your desk or in your team's shared notes helps it become second nature over time.
Warning signs in the sender, subject line, and links
The most telling clues are often hidden in plain sight. Start with the sender. Attackers frequently use addresses that look almost right, swapping a letter, adding a word, or using a public domain in place of a company one. A message claiming to be from your bank but sent from a free email service is an immediate red flag. The subject line is another giveaway. Scam emails lean heavily on urgency and emotion, with phrases about suspended accounts, unpaid invoices, or limited-time offers designed to make you react. Be wary of subjects that demand immediate action or threaten a penalty. Links are where many scams succeed. Before clicking, hover your cursor over a link and check the address that appears. If the visible text says one thing but the destination is a different or oddly spelled site, do not click. Shortened links that hide the true destination should be treated with caution when they arrive unexpectedly. Mismatched details are the common thread: the display name does not match the address, the link text does not match its target, or the request does not match how the organisation normally contacts you. Learning to spot these mismatches quickly is one of the most valuable skills you can build.
How to verify a suspicious message before acting
When a message raises doubts, verification is your safest next step, and it should always happen through a separate channel. If an email appears to come from a colleague asking for a payment or sensitive file, contact that person directly by phone or in person using a number you already know, not one provided in the email. If a message claims to be from your bank, a supplier, or a service, go to their official site by typing the address yourself or use a bookmark you saved earlier. Never rely on the contact details inside the suspicious email, because those can lead straight back to the attacker. For invoice or payment changes, confirm any new bank details through an established contact before sending anything. Take your time. Scammers rely on pressure, so slowing down is itself a defence. If you work in an organisation with an IT or security team, forwarding the message to them for a check is always acceptable and encouraged. It is far better to ask a question that turns out to be unnecessary than to act on a message that turns out to be fraud. Verification costs a few minutes; a successful scam can cost far more.
How to respond safely when you spot a scam email
Once you have identified a message as suspicious, your actions matter. Do not click any links, open attachments, or reply, as even replying can confirm your address is active and invite more attempts. Do not enter credentials or personal details anywhere the email directs you. If you have already clicked a link but not entered anything, close the page and avoid interacting further. Should you have entered a password, change it immediately on the genuine site and on any other account using the same password, and enable extra login protection where available. If you suspect financial information was shared, contact your bank without delay. Inform your IT or security team as soon as possible, because a scam sent to you was likely sent to others too, and early warning helps them protect everyone. Preserve the email rather than deleting it straight away if your organisation asks to examine it, but follow their guidance. Staying calm is important. Mistakes happen to careful people, and a fast, honest response limits the damage far more effectively than silence caused by embarrassment. The sooner a problem is flagged, the sooner it can be contained.
How to report scam emails and support your colleagues
Reporting is one of the most powerful yet underused defences. When you report a scam, you help your organisation block similar messages, warn others, and understand what threats are active. Most workplaces have a simple way to report, such as a dedicated button in the email client or an address to forward suspicious messages to. If you are unsure of the process, ask your IT or security team and make a note of it for next time. Beyond internal reporting, phishing and fraud can also be reported to national channels in France, which help authorities track wider campaigns. Supporting colleagues goes further than reporting alone. If you notice a scam circulating, a quick heads-up to your team can stop someone else from falling for it. Newcomers in particular benefit from knowing it is normal to ask for a second opinion on a doubtful email. Creating a culture where people share what they see, without blame, turns individual awareness into collective strength. Someone who reports a mistake early should be thanked, not criticised, because their honesty protects everyone. The more openly a team talks about threats, the harder it becomes for any single scam to succeed quietly.
Building lasting habits to stay alert to email fraud
Spotting scams reliably is less about one dramatic realisation and more about steady, repeated habits. Make a brief pause before acting on any email a normal part of your routine, especially for requests involving money, credentials, or urgency. Keep your software and email client updated so technical protections stay current, and use strong, unique passwords supported by extra login protection wherever possible. Refresh your awareness regularly, because attackers change their methods and last year's advice can miss new tricks. Short, practical reminders work better than long training sessions that are quickly forgotten. If you lead a team, weave awareness into everyday work rather than treating it as a one-off event, and share real examples of scams that were caught so lessons feel concrete. Encourage everyone to speak up when something looks wrong, and treat every report as a useful contribution. Over time, these small behaviours compound into a strong instinct that protects both you and the people around you. No one becomes perfect at this, and that is fine. The aim is a resilient habit of checking, verifying, and reporting that makes fraud far harder to pull off across your whole organisation.
Example
Quick reference: common scam email signals and what to do
| Warning sign | What it looks like | Recommended action |
|---|---|---|
| Mismatched sender | Display name looks right but the address is odd or from a free service | Do not reply; verify through a known channel |
| Urgent or threatening tone | Account suspension, penalty, or limited-time pressure | Slow down; treat urgency as a red flag |
| Suspicious links | Link text does not match the real destination when hovered | Do not click; type the official address yourself |
| Unexpected attachments | Files you did not request, asking to enable content | Do not open; confirm with the sender directly |
| Requests for credentials or payment | Asks to log in, confirm details, or change bank information | Verify separately and report to your IT team |
FAQ
How can I tell if an email is really from my bank or a service I use? Genuine organisations rarely ask you to confirm passwords or full account details by email. If in doubt, do not use any link in the message. Instead, go to the official site by typing the address yourself or using a saved bookmark, or contact them using a number you already trust. Checking through a separate channel is the safest way to confirm.
What should I do if I clicked a link in a suspicious email? Stay calm and act quickly. If you did not enter any information, close the page and avoid further interaction. If you entered a password, change it immediately on the genuine site and anywhere you reused it, and enable extra login protection if available. If financial details were involved, contact your bank, and inform your IT or security team so they can help and warn others.
Is it safe to reply to a scam email to ask if it is genuine? No. Replying can confirm to the attacker that your address is active, which often leads to more attempts. It also risks continuing a conversation designed to manipulate you. To check whether a message is genuine, always use a separate, trusted channel such as a known phone number or the organisation's official website, never the contact details in the email itself.
How should I report a scam email at work? Most organisations have a reporting button in the email client or an address to forward suspicious messages to. If you are unsure, ask your IT or security team and note the process for next time. Reporting helps block similar messages and protects your colleagues. In France, phishing and fraud can also be reported through national channels that track wider campaigns.
What if I am not sure whether an email is a scam? Uncertainty is a good reason to pause rather than act. It is always acceptable to ask a colleague or your IT team for a second opinion, and no one should feel embarrassed for doing so. A quick check that turns out unnecessary is far better than acting on a fraudulent message. When in doubt, verify before you click, reply, or pay.
Read next
Get structured security awareness guidance for you and your team.