Fake "security alert" emails are the #1 way small businesses get hit — and this year, nearly half of them were written by AI. Four signs catch almost every fake. One rule beats them all.
Last year 46% of small businesses got a phishing email written by AI. This lesson: how to spot one in seconds — without clicking anything.
Pressure, link mismatch, credential asks, generic greetings — the tells that catch almost every phishing attempt.
Works today, works tomorrow — including against AI-written phishing, which 46% of owners saw last year.
A scenario quiz on the exact email from the title slide — and what to do with a fake the moment you find one.
Phishing is now the single most common cause of small business security incidents — ahead of unpatched software, weak passwords, everything. One click on a lookalike link can hand over your admin login, your customer data, or your payment details.
Real providers don't threaten you into clicking. Countdown timers, "final warning," "act immediately" — pressure is the tell, because pressure only works if you don't stop to think.
What real looks like: your host's dashboard shows the same alert, calmly dated — no countdown.
On a computer, hover over the link — don't click — and the real destination appears at the bottom of your browser. If the email says it's from your host but the link goes somewhere else entirely, that's your answer.
Lookalike domains are the trick: "yourhost-secure.net" is not your host. Extra words, swapped letters, odd endings.
No legitimate host, registrar, or platform needs you to type your password through a link in an email. Full stop. If an email asks for login details or payment through a link, treat it as fake until proven otherwise.
The absolute version: your own support team will never email you asking for your password. Ever.
Vendors you actually do business with know who you are. "Dear customer," "Dear account holder" — a generic greeting from a company that knows your name is a red flag. Small tell, big signal.
Bonus tell: odd grammar and stiff phrasing. AI phishing is fixing this — so don't rely on typos. Rely on the other three signs.
Not by replying. A reply only confirms your address is live.
Not by clicking the link. That's the trap itself.
Open your browser, type your provider's address the way you always do, and check your account there.
If there's a real problem, it'll be waiting in your dashboard. Real alerts live there too.
Generic greeting — they know your name
Deadline pressure — "24 hours or suspension"
Credential ask — login through an email link
Link mismatch — lookalike domain, not your host
Click the link — 12 hours is too risky to ignore
The deadline is the manipulation. Fake sites harvest your login in seconds — and 12 hours of "risk" beats a stolen password.Don't click. Open a new tab, type your host's address yourself, and check your account
Correct. Pressure + lookalike link = treat as fake. The "go back yourself" rule works every time — and if there's a real problem, it'll be in your dashboard.Reply and ask if it's legitimate
Replying confirms your email is live and invites more attacks. Never reply to verify.Click the link carefully — read the URL first, then decide
Lookalike domains are built to fool exactly that check. Never evaluate a suspicious link by reading it harder — verify through your own dashboard instead.Here's the part that makes the rule reliable: genuine security notices almost always appear inside your provider's own dashboard — calmly, dated, no countdown. So the rule works both ways. Ignore the panic in the email. Check the source of truth. If the dashboard confirms it, act. If the dashboard is quiet, the email was bait.
The last piece of website management is the human part: when an alert turns out to be real, someone has to handle it. That's us — a real person who reads your alerts, filters the fakes, and emails you when it's done. From $49/month, month-to-month, no contract.