You received a suspicious email — how to check it and report it
A practical checklist for spotting phishing, what to do with a suspect message, and the steps to take if you already clicked.
- phishing
- security
- reporting
On this page
Filtering catches the overwhelming majority of malicious mail, but the messages designed specifically for your company are the ones that get through. Those are worth knowing how to spot.
The short version: when something feels off, it usually is. Send it to us and let us look.
The checks that actually catch things
Look at the real sender address. Not the display name — anyone can set that to Bank of America or your CEO’s name. In Outlook, hover over the sender or click the name to reveal the actual address. Look for lookalike domains: iconiumnetwork.com missing an s, rn standing in for m, or a legitimate company name followed by something unrelated.
Check whether the reply address differs from the sender. Hit Reply — without sending — and see where it is addressed. A mismatch is a strong signal.
Hover over links before clicking. The destination appears at the bottom of your window. If the text says one thing and the destination says another, that settles it.
Weigh the urgency. Phishing manufactures time pressure so you act before you think: your account closes today, an invoice is overdue, the CEO needs a payment made before a meeting. Genuine urgent business almost never arrives as a first email from an unfamiliar address.
Notice what it is asking for. Credentials, payment, gift cards, a changed bank account, or “just confirm this for me quickly” — those are the goals. A message combining urgency with any of them deserves a phone call to verify.
Be sceptical of unexpected attachments. Especially anything you have to enable content in, or a PDF whose only content is a button.
Trust the small wrongnesses. A signature block that is not quite right, a greeting your colleague never uses, an address that is close but not exact. People who work together notice these things — that instinct is worth acting on.
The ones aimed at your company specifically
These are harder because they use real context:
- A reply inside a genuine thread. If a supplier’s mailbox is compromised, the attacker replies to a real conversation with a fake invoice. Nothing about the thread looks wrong, because most of it is not.
- Bank detail changes. Any request to update payment details, however routine it seems, gets verified by phone on a number you already hold.
- The executive request. Short, informal, sent from a phone, asking for something unusual and asking you to keep it quiet. The secrecy is the tell.
- A fake internal notice. Voicemail notifications, quarantine digests, shared documents, HR policy updates. If it asks for your Microsoft password, it is fake — no genuine internal system needs you to re-enter it from an email link.
What to do with a suspicious message
- Do not click anything. Not links, not attachments, not the unsubscribe link.
- Do not reply, even to tell them off. It confirms the address is live.
- Report it. Forward the message to support@iconiumnetworks.com — forward as an attachment if you know how, since that preserves the technical headers we need. If not, a normal forward is fine.
- Leave the original in place until we come back to you.
- If it claims to be from a colleague or supplier, verify by phone using a number you already have.
We will look at it, tell you plainly whether it is malicious, and block the sender for everyone at your company if needed. Reporting one message often protects several colleagues who received the same thing.
If you already clicked
Do not sit on it. Speed is the whole game here.
You clicked a link but entered nothing: low risk, but tell us. We will check what the page was and whether anything downloaded.
You entered your password: call 440-991-9980 now. Change your password immediately from another device if you can. See Suspicious sign-in alert, or you think your account was compromised.
You opened an attachment or a file downloaded: disconnect the computer from the network — unplug the cable or turn Wi-Fi off — leave it powered on, and call us. Leaving it running preserves what we need to see. SentinelOne may have already stopped it, but we need to confirm.
You made a payment or changed bank details: call us and your bank immediately, in that order or in parallel. Same-day intervention sometimes recovers funds; next-day rarely does.
Nobody here will make you feel foolish. These messages are professionally built to work, they catch experienced people every week, and telling us quickly is the single most useful thing you can do.
Not sure about a message? Call 440-991-9980 or forward it to support@iconiumnetworks.com. There is no such thing as wasting our time with a false alarm — checking is exactly what we are here for.
Did this fix the problem?
If you followed these steps and it's still not working, get in touch and mention this article — You received a suspicious email — how to check it and report it — so we can skip the basics.