Phishing emails: the forward-button trick (and the rules around it)
Pete Gypps20 May 2026 · updated 27 August 2026
7 min read1,110 words
Pressing Forward usually reveals the sender’s real email address. Calling the client on a number you already have on file stops bank-detail fraud. The rest is process, written down where every staff member can find it.
Phishing emails work because they hide behind a recognised name. Most attacks succeed not because the email was clever, but because the person receiving it had no process to fall back on. They reacted to the email in their inbox instead of running a check.
The good news: the checks that catch nearly every phishing attempt take seconds and need no special tools. They just need to be written down somewhere staff can find them when they’re about to forward £8,000 to a "new bank account" their supplier has supposedly switched to.
The forward-button trick
This is the single check that catches the most fakes. When an email looks suspicious, but the sender name reads correctly (e.g. "John Smith from BigSupplier Ltd"), press Forward.
When Outlook (or Gmail, or any mail client) prepares the forward, it includes the original sender’s full email address in the quoted body of the forwarded message. That’s where the lie usually shows. The friendly display name might say "John Smith", but the real email behind it could be "john.smith@bigsupplier-secure-portal.com", "j.smith.92@xyz.co", or some other domain that has nothing to do with the supplier you actually deal with.
Important caveat: a determined attacker can fake the real sender address too, particularly if the supplier’s domain isn’t set up with proper SPF, DKIM and DMARC records. The forward trick catches roughly the lazier four-out-of-five attacks that actually reach inboxes. It is one check, not the only check.
If money is involved, always call
This is the rule that protects finance teams from the most expensive scam in business: the bank-details switch. The pattern is always similar. An email arrives, apparently from a supplier or client you do business with regularly. They have a new bank account. Please use it for the next invoice. There’s often a polite reason, "treasury reorganisation", "switching providers", "audit ran late this quarter".
“Never assume the email is real. Always call the contact on a number from your own system (not from the email, not from a signature in the email) and confirm verbally.”
Phone numbers in email signatures can be edited to ring an attacker’s burner. The "reply to" email can be a lookalike domain. The only number you can trust is the one you already have on file from when you first set up the relationship.
The same rule applies to anyone asking you to log in to something, change a password, "verify" your account, or move money. Pick up the phone using the number you already have. Three minutes on a phone call has saved more businesses from invoice fraud than any other single security control.
Red flags every staff member should know in five minutes
A short, memorable list, the kind that fits on the back of a printed handbook page. Train the whole team on these before anything fancier.
Urgency. "Respond by end of day" or "this account will be suspended in 24 hours" is a manipulation tactic. Real businesses give you notice.
Unexpected attachments, especially .zip, .iso, .htm, .lnk, or invoices from suppliers you haven’t engaged.
Mismatched links. Hover over the link before clicking (don’t tap on mobile). The address that pops up should match what the link text says. If the link text reads "microsoft.com/login" but the real URL is "microsoft.com-loginsecure.ru", that’s the attack.
Slight misspellings in the sender domain. "rnicrosoft.com" (rn looks like m) is a classic. So is using a Cyrillic letter that visually matches a Latin one.
Personal info the sender shouldn’t know, but also info the sender should know but doesn’t. Both are signals.
Requests that bypass normal process. "Pay this directly, don’t bother routing it through accounts", that’s exactly when accounts needs to be involved.
Anything that asks you to disable security warnings, click "Enable Editing", or run a macro.
Write it down, the staff handbook is the actual answer
The checks above only work if your staff remember them when they’re busy, stressed, or being pressured by an email that looks like it came from a senior person. The way to make them remember is to write the process down, in a tech handbook every staff member can find on day one and refer back to whenever.
A good tech handbook covers, at minimum, phishing checks, bank-details verification, password rules (use a manager, no reuse, MFA everywhere), what to do when you suspect you’ve been phished, who to escalate to, and the response steps for lost devices. It doesn’t need to be long. It needs to be specific to your business and easy to find.
What to do if you suspect you’ve been phished
Speed matters. If you’ve clicked a link, entered credentials, or sent money to a wrong account, don’t wait until morning hoping nothing happened.
Stop using the affected account or device immediately.
Tell your IT lead or MSP straight away, even if you’re not sure.
If credentials were entered, change the password from a clean device and revoke active sessions. In Microsoft 365 admin: sign the user out of all sessions, force MFA re-enrolment.
If money has moved, contact your bank within minutes, they have a recall window measured in hours, not days, and the sooner you call the better the chance of getting it back.
Report the email, in Outlook, use Report Message → Phishing so Microsoft’s filters learn from it.
Document what happened, when, and what you did about it. Insurance, incident reviews and improving the handbook all need this.
Process over cleverness
Phishing is solved more by process than by being clever about every email. Press Forward when you’re unsure. Call the client on the number you already have. Write the rules down. Train your team to recognise pressure tactics. Have a clear response plan when something gets through.
These checks won’t catch every attack, nothing does, but they catch the ones that put UK businesses out of pocket every week. That’s the bar to clear. Future posts in this series will cover password managers, MFA done properly, lost-device response, and the day-one tech induction every new hire deserves.
A short, opinionated list of the security and tooling decisions every employer owes their staff in 2026. Phishing training, password managers, the no-emailed-link rule, and MFA explained plainly for people who don’t spend their day thinking about this.