Infographics

The Anatomy of a Phishing Email

Visual guide to identifying phishing emails - perfect for training materials.

Guides, reports, webinars, and field notes on cyber compliance, cloud posture, policy management, vendor risk, AI governance, and security awareness.

  • Infographic

The Anatomy of a Phishing Email

Understanding Phishing Attacks

Phishing emails are designed to trick recipients into taking actions that compromise security—clicking malicious links, downloading malware, or revealing sensitive information. Understanding the anatomy of these attacks is the first step in defending against them.

Common Elements of Phishing Emails

1. The Sender

Phishing emails often impersonate trusted entities:

  • Display Name Spoofing: "IT Support" but from external-domain.com
  • Look-alike Domains: micros0ft.com instead of microsoft.com
  • Compromised Accounts: Real accounts that have been hacked

Defense: Always check the full email address, not just the display name.

2. The Subject Line

Designed to grab attention and create urgency:

  • "URGENT: Your account will be suspended"
  • "You have a new message from HR"
  • "Invoice #12345 attached"
  • "Password reset required immediately"

Defense: Be skeptical of urgent or threatening subject lines.

3. The Body

Phishing emails use psychological manipulation:

  • Fear: "Your account has been compromised"
  • Greed: "You've won a prize"
  • Curiosity: "See who viewed your profile"
  • Authority: "Message from your CEO"
  • Time Pressure: "Act within 24 hours"

4. The Link

The payload—where the real attack happens:

  • Hover to Reveal: The displayed text often differs from the actual URL
  • Shortened URLs: bit.ly and similar services hide the destination
  • Typosquatting: paypa1.com instead of paypal.com

Defense: Hover over links before clicking. When in doubt, navigate directly to the website.

5. The Call to Action

What the attacker wants you to do:

  • Click a link
  • Download an attachment
  • Reply with sensitive information
  • Call a fake support number
  • Transfer money

Red Flags Checklist

  1. Generic greeting ("Dear Customer" instead of your name)
  2. Grammatical errors and awkward phrasing
  3. Mismatched or suspicious URLs
  4. Requests for sensitive information
  5. Unexpected attachments
  6. Threats or excessive urgency
  7. Too-good-to-be-true offers

When in Doubt

If an email seems suspicious:

  1. Don't click any links or download attachments
  2. Report it to your security team
  3. Verify through an alternative channel if needed

Related insights