Phishing email examples, red flags marked

Phishing email examples built on the emails office workers click most in tests, each with its red flags marked in pen, and real company mail that looks worse.

Phishing email examples

One example of each kind of phish, as it would land in a work inbox. Each red flag is underlined and numbered, and the list under the email says what each one is.

A file shared with you

A document, spreadsheet or scan someone shared, behind a sign-in page that only looks like your company's. The most-clicked test phish of late 2025 was a shared document named after the company's own IT help desk.

Subject
Document shared with you: Example Inc. IT Help Desk Info
From
Docs no-reply@docs-example.example.net
To
sam@example.com

IT Help Desk shared a document with you.

Example Inc. IT Help Desk Info

Open: https://docs-example.example.net/d/it-help

Sign in with your work account to view.

Red flags

  1. docs-example.example.netLookalike domain
  2. https://docs-example.example.net/d/it-helpWrong destination
  3. Sign in with your work account to viewLogin request

Company files live on files.example.com and open without a second sign-in. This one wants your password at the door.

A chat app saying someone needs you

An email that claims to come from the work chat app: your manager is trying to reach you, or you were added to a team. Chat notices took two places in the late 2025 top ten of test subjects.

Subject
Your manager is trying to reach you
From
Chat noreply@chat-notify.example.net
To
sam@example.com

You have missed messages from your manager.

Latest: Are you free, need you on something before 3

Reply in chat: https://chat-notify.example.net/msg/4471

You are getting this email because your status is Away.

Red flags

  1. need you on something before 3Urgency
  2. https://chat-notify.example.net/msg/4471Wrong destination

Your manager does not wait for email to find you. The chat app lives on chat.example.com, and this notice comes from example.net.

Show 10 moreShow fewer phishing email examples

An HR policy to read and sign

A new dress code, vacation rule or conduct policy, with a deadline to acknowledge it. Half of the late 2025 top ten came from HR.

Subject
HR: Updated Dress Code Policy, effective Monday
From
HR Department hr@example-hr.example.net
To
sam@example.com

Hi Sam,

Our dress code has been updated for all staff, including video calls.

Read and acknowledge it by Friday: https://example-hr.example.net/policy/dress

Sign in with your work account to acknowledge.

Red flags

  1. example-hr.example.netLookalike domain
  2. Sign in with your work account to acknowledgeLogin request

Policies live on the intranet, which never asks you to sign in again. The address puts example first and still ends in example.net.

Pay, benefits and rewards

A reimbursement, a bonus, a review or open enrollment ending today. Money, benefits or time off featured in about a sixth of the most-clicked test links of late 2025.

Subject
HR: Reimbursement approved, confirm your payment details
From
Expense Reimbursements reimburse@example-expenses.example.net
To
sam@example.com

Hi Sam,

Your reimbursement of $284.16 has been approved.

Confirm your bank details so it can be paid this week: https://example-expenses.example.net/pay

Red flags

  1. example-expenses.example.netLookalike domain
  2. Confirm your bank detailsPersonal data

Reimbursements arrive with your salary, in the account payroll already has. You also never claimed $284.16 of anything.

Training you have not done

A reminder that your training is past due, with a threat to your access. Training past due and assigned training both made the late 2025 top ten, and real reminders read the same.

Subject
HR: Training Past Due, final notice
From
Learning Team learning@example-training.example.org
To
sam@example.com

Hi Sam,

Your required security training is 9 days past due.

Complete it today to keep your system access: https://example-training.example.org/course

Red flags

  1. example-training.example.orgLookalike domain
  2. to keep your system accessThreat

Overdue training is the most believable email in any inbox, which is why phishing tests copy it. This course lives on example.org, not on the company's learning site.

An IT warning about your account

Your mailbox is full, your settings changed, your internet use was flagged, or a license is waiting. The fix is always a sign-in page or an attachment.

Subject
IT: Internet usage report for your account
From
IT Department it-reports@example-it.example.net
To
sam@example.com

Attachment: Internet_Usage_Report.html

Hi Sam,

Our web filter flagged unusual browsing on your account this month.

Review the attached report and sign in to dispute any entries.

Red flags

  1. example-it.example.netLookalike domain
  2. Internet_Usage_Report.htmlRisky attachment
  3. sign in to dispute any entriesLogin request

Nobody wants a list of their browsing, which is why it gets opened. The report is a web page in disguise, and IT's real address ends in example.com.

A meeting that already started

A meeting that is live without you, a seat to reserve, or a project invite that expires. The hurry is the whole trick.

Subject
The Strategy Meeting is LIVE. Please Enter
From
Video Meetings meetings@video-join.example.net
To
sam@example.com

The Q4 strategy meeting has started and the host is waiting for you.

Join now: https://video-join.example.net/j/q4-strategy

Sign in with your work account to join.

Red flags

  1. the host is waiting for youUrgency
  2. https://video-join.example.net/j/q4-strategyWrong destination
  3. Sign in with your work account to joinLogin request

A meeting you were never invited to, already started, with a host waiting. Real invites sit in your calendar, and nobody waits for anyone.

A package that needs a fee

A delivery held at customs or missed at your desk, released for a small fee or your date of birth.

Subject
Import Duty/Tax Payment Needed
From
Customs Clearance clearance@customs-fees.example.org
To
sam@example.com

Your international package is held at customs.

Pay the $6.95 import duty within 48 hours or the package will be destroyed.

Pay duty: https://customs-fees.example.org/pay

Red flags

  1. Your international package is held at customs.Out of the blue
  2. within 48 hoursUrgency
  3. the package will be destroyedThreat

You ordered nothing from abroad. The 48 hours are there so you pay before you remember that.

An invoice to pay

An invoice or a payment problem, often sent as a web page: about a quarter of the attachments opened in late 2025 tests were HTML files.

Subject
Invoice Payment Process
From
Accounts Receivable ar@supplier-billing.example.org
To
sam@example.com

Attachment: INV-2026-1187.html

Hello,

Please process the attached invoice before the end of the month.

Open the file and sign in to view the amount due.

Red flags

  1. INV-2026-1187.htmlRisky attachment
  2. Please process the attached invoiceSurprise invoice
  3. sign in to view the amount dueLogin request

An invoice is a PDF or a line in the finance system, never a web page with a sign-in box. Real suppliers also say which supplier they are.

A favor from the boss

A senior name in a hurry: gift cards for a client, a quiet payment, your cell number. Only scammers ask to be paid in gift cards.

Subject
Quick favor, keep it between us
From
Office of the CEO ceo.office.private@webmail.example.net
To
sam@example.com

Hi Sam,

I need 10 coffee shop gift cards for a client today.

Buy them, scratch off the backs and email me the codes.

I am in meetings all day, so no calls please.

Red flags

  1. webmail.example.netOdd sender
  2. 10 coffee shop gift cardsGift cards
  3. scratch off the backs and email me the codesStrange request

The CEO has an assistant and a company card. Neither of them is you.

Payroll and bank changes

Payroll or a supplier changing where money goes. In a 2025 campaign against university staff, an HR compensation update led to a sign-in page, and the attackers then moved salaries to their own accounts.

Subject
2026 Compensation and Benefits Update
From
HR Department hr@example-compensation.example.net
To
sam@example.com

Hi Sam,

Your updated compensation statement has been shared with you.

View statement: https://example-compensation.example.net/doc/cs26

Sign in with your work account and confirm your direct deposit details.

Red flags

  1. example-compensation.example.netLookalike domain
  2. Sign in with your work accountLogin request
  3. confirm your direct deposit detailsPersonal data

A 2025 campaign used this subject on university staff, then changed where their pay went. Your pay stub lives in the HR portal and never needs your bank details again.

A sign-in code or prompt

A request to read back the code your phone shows, or to tap Approve on prompts you never asked for. Anyone who asks for your code is a scammer.

Subject
Verify your account now
From
Information Security security@example.com
To
sam@example.com

We saw a sign-in to your account from a new country.

To block it, reply with the 6-digit code we just sent to your phone.

Red flags

  1. Information SecurityKnown name
  2. a sign-in to your account from a new countryAccount problem
  3. reply with the 6-digit codeCode request

The security team's mailbox was taken over, so the address was real. The code on your phone is the second check on your account, and sending it lets them in.

Real emails that look like phishing

Company mail breaks the same rules: a deadline, a threat, Dear Employee, a link to an outside vendor. These are real, and each one gives you a way to check it that the email doesn't control.

Security Awareness Training

Subject
ACTION REQUIRED: Mandatory phishing training overdue
From
Security Awareness Training noreply@training-portal.example.net
To
sam@example.com

Dear Employee,

Your mandatory phishing awareness training is overdue. Complete it within 48 hours or your account may be suspended.

Start here: https://s.example.net/phish101, or from the Training tile on the intranet.

Real mail, with red flags anyway

  1. Dear EmployeeGeneric greeting
  2. your account may be suspendedThreat
  3. https://s.example.net/phish101Short link

Real, and it breaks three rules of the course it links to. It asks for nothing, and the Training tile on the intranet opens the same course without the short link.

IT Service Desk

Subject
Verify your password reset request
From
IT Service Desk servicedesk@it.example.com
To
sam@example.com

Dear User,

We received a request to reset your password. If this was not you, your account may be at risk.

Verify your request within 24 hours: https://login.example.com/verify

Real mail, with red flags anyway

  1. Dear UserGeneric greeting
  2. your account may be at riskAccount problem
  3. within 24 hoursUrgency

Real. IT wrote Dear User, a scare and a deadline. The link stays on login.example.com, the page you sign in on every morning.

Show 2 moreShow fewer real emails that look like phishing

Payroll

Subject
IMPORTANT: Payroll is migrating to a new portal
From
Payroll payroll@example.com
To
sam@example.com

Dear Employee,

Payroll is migrating to a new portal. Log in by Friday or your pay stubs will not be available.

New portal: https://paydesk.example.org, with the Company sign-in button.

The move is announced on the Payroll page of the intranet.

Real mail, with red flags anyway

  1. Dear EmployeeGeneric greeting
  2. your pay stubs will not be availableThreat
  3. https://paydesk.example.orgWrong destination

Real. Payroll picked a vendor on example.org, wrote Dear Employee and set a deadline. The Company sign-in button sends you to your own login page, and the intranet says the same.

Subject
From
Office of the CEO ceo-office@example.com
To
sam@example.com

Dear Team Member,

As I said at Monday's all-hands, I want to hear from every one of you.

Take the survey before it closes: https://s.example.net/ceo-pulse

It is anonymous, and the link is pinned in the staff channel too.

Real mail, with red flags anyway

  1. survey closes in 24 hoursUrgency
  2. Dear Team MemberGeneric greeting
  3. https://s.example.net/ceo-pulseShort link

Real. The CEO's office sent the whole company a short link on a 24-hour clock, then asked why phishing tests go so badly. It asks for no sign-in, and the staff channel has the same link.

The red flags, explained

Every red flag on this page, from US and UK government security guidance.

Urgency
It gives you minutes or hours to act, so you react before you think.
Threat
It warns of something bad, like a locked account or lost pay, if you do not respond at once.
Emotion
It tries to make you scared, excited or curious enough to click first.
Too good
It offers a prize, a bonus or free money you never asked for.
Generic greeting
It opens with Dear user or Dear customer instead of your name, because it went to thousands of people.
Odd sender
The address is on a free public mail service, or is a jumble that means nothing.
Lookalike domain
The address or link is a near miss of the real domain, with a letter or an ending changed.
Risky attachment
It carries a dangerous file type, sometimes hidden inside a zip file, that can infect your computer when opened.
Login request
It wants your password, or sends you from the email to a sign-in page that passes it to someone else.
Code request
It asks for a verification code, and anyone who asks for one is a scammer.
Approve prompts
It asks you to approve sign-in prompts you did not start, which is how a stolen password gets past the second check.
Personal data
It asks for card numbers, bank details, an ID number or a date of birth by email.
Bank change
It says the bank account for a payment has changed and asks you to use the new one.
Gift cards
It asks you to buy gift cards and send the codes, a payment no real business asks for.
Strange request
It asks for something odd, or out of character for the person it claims to be from.
Surprise invoice
It carries an invoice or an overdue bill you do not recognize.
Account problem
It says something is wrong with your account and pushes you to act.
QR code
It asks you to scan a QR code, which hides the link from some mail filters and moves you to your phone.
Known name
It comes from a name you trust, sometimes from a real colleague's account that was taken over.
Bad spelling
It has poor spelling and grammar while claiming to come from a careful, official sender.
Out of the blue
You were not expecting the email, and you do not recognize the address it came from.

Why these phishing emails work

They look like your own company

All ten of the subject lines clicked most in late 2025 tests named something inside the company, and the top two carried the company’s own name. Nearly nine in ten of the 20 links clicked most pretended to come from a real domain.

That’s why the examples above read like an ordinary Tuesday at the office, down to the dress code and a gentle reminder about training.

PDFs, Word files and web pages

About half of the 20 attachments opened most in late 2025 tests were PDFs. A quarter were Word files and a quarter HTML files. An HTML file opens in the browser as a web page, which is how a fake sign-in box arrives as an attachment.

The QR code moves you to your phone

The QR codes scanned most in 2025 tests pointed at IT and HR, and a new drug and alcohol policy topped one quarter’s list. A code takes you off the work laptop, past mail filters that don’t scan images, and onto a phone your employer may not protect.

How to check an email before you click

Checks that work on any inbox

  • Read the address and every link from the right. files.example.com.share-view.example.net belongs to example.net, whatever it says first.
  • Ask what it wants. A password on a page you didn’t open yourself, the code on your phone, gift cards or new bank details are the asks that cost money.
  • Check through a channel you already know: the intranet, the app you use every day, a phone number you already have. Never use the link, number or reply address in the email.
  • Treat a deadline as a reason to slow down, even one that says EOD. Real deadlines survive a phone call.
  • Gift cards are never a real payment. No real business asks to be paid in them.
  • New bank details for a supplier or your salary get confirmed by phone, on the number already on file.

The look decides less than you’d think. Real company mail uses the same deadlines, threats and generic greetings, and an FYA label asks for action just as a phish does. UK guidance does ask companies to make their own email easy to tell from a phish.

What to do with a phishing email

Don’t click, reply or open the attachment. Use your mail app’s report button, labeled Report phishing in the big mail apps; a message reported that way leaves your inbox. If you already clicked, tell IT at once and reset any password you entered there.

To practice on five emails a day, play Phish or IT, where your own company’s mail looks worse than the phish. The other work email examples cover the emails you’d rather write, from sign-offs to leaving cards.

Questions about phishing emails

What are examples of phishing emails?

The ones that work look like internal mail: a shared document, a new HR policy, a reimbursement, overdue training, or a chat notice that your manager wants you. Older ones ask for gift cards, a package fee or the code on your phone.

What are the red flags of a phishing email?

A sign-in page that isn't your company's, a request for a code, gift cards or bank details, and an address or link that nearly matches the real one. Urgency, threats and Dear Employee count too, though real company mail uses them as well.

How do I report a phishing email?

Use the report button in your mail app. In Outlook it's Report, then Report phishing; in Gmail it's More, then Report phishing. If your company has its own report button or address, use that, so IT sees it too.

What should I do if I clicked a phishing link at work?

Tell your IT team straight away, and change any password you typed on the page. The sooner IT hears, the sooner it can lock the account. A good security team thanks you, because people who fear blame report late or never.