BETABOX Technologiescybersecurity

What to do if you get a phishing email

What to do if you get a phishing email: clear warning signs, common mistakes to avoid and extra protection with reliable, trusted security tools.

What to do if you get a phishing email

Nobody should panic at the sight of a suspicious email. Phishing is common and, although many messages end up in the spam folder, no filter is perfect. That is why it is worth knowing what to do if you get a phishing email when one turns up. This guide, in clear and direct language, explains the most frequent warning signs and the recommended actions for protecting accounts and money.

Clear signs for spotting a phishing email

Subject lines that are too attention-grabbing

Scammers compete for attention. They tend to use words such as “urgent”, “prize”, “money” or “giveaway”. The goal is to prompt quick clicks. If the subject line looks exaggerated or out of context, that is a warning.

Suspicious calls to action

The message pressures you to click, pay or open an attachment. The aim is to pull you out of your email and take you to an unsafe site, where they will try to steal data or trigger payments you do not need to make.

Urgency and time running out

Phrases such as “Expires in 24 hours” are meant to speed up decisions and prevent thought. That haste is deliberate: where there is panic, there is less verification. Security is built on the opposite: calm and checking.

Language errors or a mix of languages

You will see messages written in several languages at once, with strange mistakes in grammar or spelling. That mix is usually a sign of automation or of copying and pasting from dubious sources.

A sender address that does not fit

If the sender does not match the recipient's reality (for example, an Italian account contacting someone in Brazil with no context), it is worth being suspicious. It is also typical to see domains that look like the original but are slightly altered.

What to do when you find a suspicious email

\1. Delete it without opening it if your suspicion is high.

\2. Report the phishing attempt:

• Outlook: use “Report message” → “Phishing” (or, in a Spanish interface, “Reportar mensaje” → “Phishing”).

• Gmail: open the three-dot menu and choose “Report phishing”.

\3. Block the sender when appropriate.

\4. Alert your team (where applicable), so that other people do not fall for it.

What you should not do

Do not open attachments

Attachments can contain malware or redirect you to fake sites. That includes images, HTML and even “voice messages” in unusual formats. One frequent case: an .svg file that promises audio. On opening it, the person ends up on a page that imitates Google Voice, and then on another site that asks for the username and password of their email account. The trick: there was no audio; it was bait to steal credentials.

Practical rule: if the message was not expected, do not open any attachment. None at all.

Do not click on links

This is the golden rule. Many emails mix languages, use compromised real senders or promise prizes. Sometimes the link appears twice to reinforce the action. It is also common to see shorteners such as TinyURL used to hide the real destination. A link that starts with tinyurl.com/… could lead anywhere.

Quick check: hover the cursor over the link (without clicking) and look at the real URL. If there is any doubt, it is better not to open it.

Do not believe promises or threats

“Congratulations! Claim your prize” or “Your account will be suspended if you do not confirm right now” are well-known hooks. Sometimes the email looks “more serious” because it uses Google Forms or other legitimate tools. That does not guarantee safety. If you did not enter a giveaway, there is no prize. If a large platform needs to verify something, it will do so from its official site, not from a strange link.

Additional good practices

  • Check the sender's domain. Tiny differences (my-bank.com vs. my-bank.co) change everything.
  • Type the official address into your browser instead of using links from the email.
  • Turn on two-step verification (2FA) on important accounts.
  • Update your browser, operating system and applications.
  • Keep backups of critical information.
  • Train your team: sharing real examples improves detection.
  • Use antispam filters and security policies across the organization.
  • Centralize reporting: a clear internal channel speeds up the response.

What if the email has already been opened?

  • Do not enter passwords or payment details.
  • Close the tab and change passwords if anything was typed in.
  • Review recent activity on the account.
  • Apply 2FA if it is not already active.
  • Run a scan with the security solution you have installed.
  • Inform the IT or security team so they can assess the scope.

Extra protection with a security solution

Following these rules reduces the risk considerably, but it does not eliminate it 100%. That is why it is advisable to have a reliable security solution that blocks phishing links and sites in real time.

Every year, independent labs evaluate cybersecurity products. In June 2025, for example, AV-Comparatives awarded the Approved certificate to Kaspersky Premium for Windows for its effectiveness against phishing. That technology architecture is shared across its home and business portfolio, which extends the recognition to other editions (Kaspersky Standard, Plus and Premium) and to corporate solutions (Kaspersky Endpoint Security for Business and Kaspersky Small Office Security).

Actionable summary

  • Stay calm.
  • Be suspicious of exaggerated subject lines, urgency and prizes.
  • Do not open unsolicited attachments or links.
  • Verify senders and domains carefully.
  • Report the phishing in Outlook or Gmail.
  • Strengthen your security with 2FA, updates and a reliable solution.
  • Communicate internally to prevent further incidents.

With good judgment and the right protection, anyone can avoid falling into phishing traps and keep their information safe.

Related articles

Contact

Request a complimentary assessment

Tell us what your company needs and a BETABOX advisor will get in touch to schedule a call at your convenience. The initial assessment is 100% free of charge.