The seven red flags

  1. Urgency and threats — "act now or your account is closed."
  2. Mismatched sender — display name vs. actual address.
  3. Generic greetings where a real sender would use your name.
  4. Unexpected attachments, especially documents asking you to enable content.
  5. Links that don't match — hover to see the true destination.
  6. Requests for credentials or payment changes.
  7. Subtle misspellings in domains and brand names.

Make it a habit

When in doubt, don't click — verify through a known channel. Print this list for the break room and reinforce it with periodic security awareness training.