February 17, 2026
Don’t Click That Button: How to Identify Phishing Emails

I was reminded this week how important it is for anyone running a business (or even just existing on the internet today) to know how to identify phishing emails.

A client reached out this week to let me know she’d received a phishing attempt… pretending to be Siteground. Since Siteground is the hosting company I recommend to all of my clients, I immediately took notice. She said the email seemed legitimate in every way… except for two small things:

  1. It said that she needed to update her billing information and she had just been in her account and done that, so that didn’t seem right.
  2. It mentioned a Pro Subscription and she was pretty sure that wasn’t the type of account she had.

She did exactly what she should have in that situation — she logged into her Siteground account directly and checked their support articles, which gave her a number of helpful tips to look at to help identify phishing emails going forward. I thought those tips (plus some bonus ones I’ve learned on my own) were worth passing along.

Screenshot of phishing email pretending to be Siteground

How to Identify Phishing Emails

Spammers these days get ever more sophisticated, making it increasingly difficult to tell if an email is actually from the business it says it is. Often these emails look incredibly legitimate — they use the right colors and logos, and sound professionally written. They claim to be about believable things tied to your business.

In fact, the prevalence of phishing emails were a significant factor behind the increased email requirements Gmail and Yahoo laid out in 2024.

So what red flags might suggest an email isn’t quite what it seems?

Anytime an email asks you to do anything that might involve your debit card or another form of payment, it’s worth taking a pause and verifying if it’s really from who it says it’s from. It’s also worth taking a second look if an email wants you to verify any of your details or “update” an account by sharing information after clicking a link. Anything asking for personal information, such as login details, your name, or an address are also always worth double checking.

Check the Sender Address

If an email (or text message) asks you to provide a company with information about you or your business, begin by double checking the sender’s email address. Does it come from a domain that matches the business it’s claiming to be?

For example, Siteground emails will always come from noreply@siteground.com. Scammers often use similar-looking domains, like “sietground.com” or “siteeground.com,” so take the time to look carefully. You may have seen this meme going around, with a few other common examples:

screenshot showing key differences to help identify phishing emails - like looking for cyrillic letters.

If you’re ever unsure, you can always look at previous emails that business has sent you to compare. If you’re still unsure, the best course is always to avoid clicking on the link in the email and instead visit the business’ website directly to login and check your account or contact their support to ask if it’s legitimate.

Check the URL Links (Without Clicking)

In most browsers, you can also check the link of a button or URL without actually clicking on it by hovering your mouse over it instead. Legitimate URLs should pass the same test as the sender email tips above — they should obviously belong to the business that is contacting you.

Occasionally, if a service provider uses an outside service for something like invoicing or bookkeeping (like I do, for example), you may get emails that ARE legitimate that don’t seem to lead to the right address. In this case it’s always worth double checking. A quick email to your service provider will usually verify whether or not the email actually came from them.

Compare the Email to Other Emails from That Business

There are a few other quick checks that you can do to help identify phishing emails by comparing an email to other emails you’ve received from that business.

  • Is the greeting the same? Businesses will often use the same greeting on all of their communications. For example, Siteground typically starts with “Hello” followed by your registered name. If an email instead addresses you with your email address instead of your name, it’s likely a scam.
  • Is the signature the same? Almost all businesses have a standard sign off for business communications and use the same general “footer” on all of their emails. Usually that’s because the software they use to send those emails has you set up a reusable template. If the signature or footer of the email looks different, there’s a good chance it’s a phishing email.
  • Does the overall email layout match? Similarly, setting up a template means that emails from the same business typically look very similar… the layout, font, colors, and logo placement are likely to be almost identical from email to email.

What to Do About A Phishing Email

If you receive an email and you’re pretty sure it’s a phishing attempt – what should you do? (Other that NOT clicking the links or buttons…)

The first thing to do is to log into your account from that business independently of the email. You can do this by going directly to their website (without clicking any links in the email). After you log in, just look through your account information to make sure everything looks correct and  that you don’t see anything that looks suspicious. Essentially, you’re looking for anything that might suggest your account has been compromised somehow.

You might even want to take a moment and change your password for that account — just to make sure that no one can access it who shouldn’t be able to.

Then, since you’re already on the business’ website anyway, it’s a good idea to let them know that you received a phishing email pretending to be them. Often, if businesses identify phishing emails with common elements, they notify their clients to help keep anyone from getting caught up in the attempts. They may also want a copy of the email so they can keep track of it for legal purposes.

While you’re certainly under no obligation to report it — most businesses do appreciate if you do.

This is also why it’s important as a business yourself to use a professional email address… because it helps clients be sure you’re not a spammer, pretending to be you.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *