Suspicious vs. Non-Suspicious Emails: Even When They Look Familiar
Email is still one of the most common ways attackers try to trick employees—and one of the easiest ways to fall victim is assuming an email is safe just because it comes from a familiar name. Unfortunately, that assumption is exactly what cybercriminals rely on.
What Makes an Email Suspicious?
An email should raise red flags if it includes any of the following signs, even if it appears to come from a coworker, vendor, or executive you know:
Urgent or threatening language like “Immediate action required” or “Your account will be locked.”
Requests for passwords, MFA codes, gift cards, wire transfers, or other sensitive information.
Unexpected attachments or links you weren’t expecting to receive.
Sender addresses that look almost right but contain extra letters, misspellings, or look-alike domains.
Requests that don’t match someone’s normal behavior, such as a coworker asking for something unusual.
Instructions to bypass standard processes or keep the request confidential.
It’s important to remember: attackers often compromise real email accounts or convincingly spoof trusted senders. A recognizable name does not guarantee an email is safe.
What Legitimate Emails Usually Look Like
Emails are more likely to be legitimate when the request follows normal business processes, arrives when you expect it, avoids urgency or pressure, and doesn’t ask for sensitive information or unusual actions. The sender’s tone and email address should also closely match past communications.
Even then, trust your instincts—if something feels off, it probably is.
What to Do If You’re Unsure
Do not reply to the email to ask if it’s legitimate. Attackers often monitor compromised inboxes and will respond pretending to confirm the request.
Instead, verify the message using a separate, trusted method:
Call the sender using a known phone number.
Send a new message (don’t reply) using an address from your contacts.
Confirm the request through Teams, Slack, or in person.
The Golden Rule
Never verify a suspicious email by replying to it.
Always use a separate, trusted communication channel.
Staying cautious for an extra minute can prevent a costly security incident.
