The misspelled phishing email is gone
Most of us learned to spot a phishing email by its mistakes. The misspelled company name, the Dear Customer greeting, the bank that supposedly sent half a finished letter. Those tells trained a generation, and the training was honest for its time, because the emails of that era really were written badly.
The emails that land now are written well. America's cyber security agency CISA puts it plainly in its current guidance: poor grammar and misspellings used to be a common phishing sign, but with AI some phishing emails now have perfect grammar and spelling, so that check can no longer be relied on. The tools that tidy up everybody's writing also tidy up the scams.
What arrives in a business inbox now is usually a competent forgery: a sender address that looks right, a plausible story, and nothing in the spelling to catch the eye. Squinting harder is not the answer, because there is nothing there to see. What still works is a small set of questions about how the message behaves, which is what the rest of this piece covers, along with the free UK route for reporting one and the part of the problem that lives on your own domain.
The five levers the scams pull
The National Cyber Security Centre sorts the tell-tale signs into five levers a phishing email pulls: authority, urgency, emotion, scarcity and current events. They are worth naming in the language of a working business, because the pressure is easier to notice than the forgery.
Authority is the message claiming to be from somebody official: the bank, HMRC, a manager, a supplier's accounts department. Urgency is the invented deadline, respond within 24 hours or face a fine. Emotion is panic, fear, hope or curiosity, whichever one gets the reaction going. Scarcity is something in short supply, and current events are the news story or the tax season the message borrows to make itself feel timely.
None of the five is a technical trick. Each is pressure on a person, and they all aim at the same thing: getting you to act before you think. An email you have all morning to sit with is a much weaker scam than the same email claiming the account closes at four o'clock, which is why so many of them invent the deadline.
The questions that still work
Appearance has retired as a test. Behaviour has not. Three questions about what the message is doing catch most of what the cosmetic checks miss.
Did I expect this? Most genuine email that matters was expected: the invoice you knew was coming, the reply to the message you sent. An unexpected message is not automatically a scam, but it earns a closer look rather than an instant reply.
Is it trying to move me fast? Urgency in the message should raise suspicion rather than lower it. Genuine organisations rarely need an answer inside the hour, and the ones that do are usually reachable by phone to check.
Does it want to move money or details somewhere new? This is the big one, and the one worth treating as a rule. A message that redirects a payment, asks for a login or sends you somewhere to type credentials is asking the one question that matters, whatever the story around it looks like. Sender addresses and logos are decorations; behaviour is the tell.
CISA's advice on what to do instead matches: do not click the links or attachments, do not reply, and if the message might be genuine, contact the company through a method you already had, such as their official website or a phone number you already hold.
The one no checklist catches
There is a version no list catches, including the questions above, and it deserves its own section. The email arrives from a real supplier, in a real thread you are both part of, and almost everything about it is genuine. The address is real because the account is. The conversation history is real because the thread is. The only false thing in the message is the request, and no check of the sender's appearance will find it, because there is nothing wrong with the sender.
This is the quiet version of invoice fraud, the bank-detail switch: somebody gets into a genuine email account, usually with a phished password, reads the invoices going back and forth long enough to learn the amounts and the tone, and then changes the bank details at the moment a real payment is due. What UK firms have lost to it, and the one phone call that defeats it, are covered there in full.
The habit that survives it is verification through a channel the message did not supply. If an email says the bank details have changed, ring the number from your contacts or the last genuine invoice, not the number printed under the email announcing the change. The one thing the criminal cannot do is answer your supplier's actual phone.
You spotted it. Now report it

Spotting is half the job, and the other half takes about a minute. You can forward a suspicious email to report@phishing.gov.uk, free, even if you are not certain it is a scam. Suspicious text messages go to 7726, also free, which reports them to your mobile provider. Both are UK routes, which matters because most of the guides ranking for this search hand out American addresses.
The National Cyber Security Centre analyses what arrives and may work with hosting companies to remove malicious links, and it acts on every message it receives, though it cannot tell you the outcome. Forwarding costs a minute. What it buys is the links inside that email going down for everybody the scam has not reached yet, which is a better return than the delete key ever pays.
The same trick can be played as you
The last part is the one most spotting guides never mention, and it is the one a business owner has the most stake in. The same forgery can be sent wearing your name. Phishing was the most prevalent breach type in the UK government's Cyber Security Breaches Survey 2025/2026: 38% of businesses that identified a breach or attack in the previous twelve months experienced phishing, and among those affected, 51% experienced phishing only, up from 45% the year before. For 69% of affected businesses, phishing was the most disruptive breach they had. Too small to be hacked? takes those figures apart in detail.
The same survey estimated 5.19 million cyber crimes against UK businesses in twelve months, the vast majority phishing related, and it only counts phishing where an employee engaged with it, so the raw volume of scam email is higher still. The National Cyber Security Centre's small business guide is blunt about who this reaches: small businesses are just as likely to experience online crime as larger ones, and "if you think your business is too small to be a target, think again".
The uncomfortable part for the owner is what the incoming scam says about the outgoing one. If an email can be forged to look like it came from a supplier, it can be forged to look like it came from you, and your customers receive it in the same trusting state you were in this morning. Small firms across Lincolnshire carry this from both sides of the same inbox, and it is one of the few threats where the fix is not on the website at all but on the domain's public email records.
The free security check reads those records and grades them in seconds. It is passive, so nothing touches your website or your inbox, and there is no sign-up. If the grade shows gaps, closing them is what the email security setup does, £49 one-off including VAT, with the records live within 48 hours, sold on its own with no website required.
The questions that come up
What happens when I forward a scam email to report@phishing.gov.uk? The National Cyber Security Centre analyses what it receives and may work with hosting companies to remove the malicious links. It acts on every message, though it cannot tell you the outcome. Forwarding is free and worth doing even when you are not certain the email is a scam.
Can phishing emails have perfect grammar? Yes. CISA's guidance notes that with AI, some phishing emails now have perfect grammar and spelling, so the old read-it-for-mistakes check can no longer be relied on. What still works is looking at what the message does: whether it was expected, whether it manufactures urgency, and whether it wants to move money or details somewhere new.
The same forgery can be sent as you, and whether it lands depends on the email records on your domain. The check takes seconds and asks for nothing.
