Spot the fake.

Fake "security alert" emails are the #1 way small businesses get hit — and this year, nearly half of them were written by AI. Four signs catch almost every fake. One rule beats them all.

SPOT THE FAKE A business owner giving a suspicious email a skeptical look on her laptop

Last year 46% of small businesses got a phishing email written by AI. This lesson: how to spot one in seconds — without clicking anything.

In 6 Minutes

What you'll walk away with

01

Spot the four signs of a fake email

Pressure, link mismatch, credential asks, generic greetings — the tells that catch almost every phishing attempt.

02

One rule that beats every fake

Works today, works tomorrow — including against AI-written phishing, which 46% of owners saw last year.

03

Practice on a real-world fake

A scenario quiz on the exact email from the title slide — and what to do with a fake the moment you find one.

Why This Lesson

The fake email doesn't attack your website. It attacks you.

Phishing is now the single most common cause of small business security incidents — ahead of unpatched software, weak passwords, everything. One click on a lookalike link can hand over your admin login, your customer data, or your payment details.

26%of small business security incidents start with phishing — the #1 cause (ESET, 2026)
46%of small businesses received AI-generated phishing attempts last year (VikingCloud, 2026)
Sign 1 of 4

Urgency. "Act in 24 hours or else."

Real providers don't threaten you into clicking. Countdown timers, "final warning," "act immediately" — pressure is the tell, because pressure only works if you don't stop to think.

What real looks like: your host's dashboard shows the same alert, calmly dated — no countdown.

Sign 2 of 4

The link doesn't match the story.

On a computer, hover over the link — don't click — and the real destination appears at the bottom of your browser. If the email says it's from your host but the link goes somewhere else entirely, that's your answer.

Lookalike domains are the trick: "yourhost-secure.net" is not your host. Extra words, swapped letters, odd endings.

Sign 3 of 4

Asking for a login or payment.

No legitimate host, registrar, or platform needs you to type your password through a link in an email. Full stop. If an email asks for login details or payment through a link, treat it as fake until proven otherwise.

The absolute version: your own support team will never email you asking for your password. Ever.

Sign 4 of 4

"Dear customer" — not your name.

Vendors you actually do business with know who you are. "Dear customer," "Dear account holder" — a generic greeting from a company that knows your name is a red flag. Small tell, big signal.

Bonus tell: odd grammar and stiff phrasing. AI phishing is fixing this — so don't rely on typos. Rely on the other three signs.

The One Rule

Don't use the email to respond. Go back yourself.

1

Not by replying. A reply only confirms your address is live.

2

Not by clicking the link. That's the trap itself.

3

Open your browser, type your provider's address the way you always do, and check your account there.

4

If there's a real problem, it'll be waiting in your dashboard. Real alerts live there too.

Walkthrough

The malware alert, decoded. Click each flag.

4

Generic greeting — they know your name

1

Deadline pressure — "24 hours or suspension"

3

Credential ask — login through an email link

2

Link mismatch — lookalike domain, not your host

Knowledge Check

An email says your domain will be suspended in 12 hours. What's the safe move?

A

Click the link — 12 hours is too risky to ignore

The deadline is the manipulation. Fake sites harvest your login in seconds — and 12 hours of "risk" beats a stolen password.
B

Don't click. Open a new tab, type your host's address yourself, and check your account

Correct. Pressure + lookalike link = treat as fake. The "go back yourself" rule works every time — and if there's a real problem, it'll be in your dashboard.
C

Reply and ask if it's legitimate

Replying confirms your email is live and invites more attacks. Never reply to verify.
D

Click the link carefully — read the URL first, then decide

Lookalike domains are built to fool exactly that check. Never evaluate a suspicious link by reading it harder — verify through your own dashboard instead.
What If It's Real?

Real alerts live in your dashboard.

Here's the part that makes the rule reliable: genuine security notices almost always appear inside your provider's own dashboard — calmly, dated, no countdown. So the rule works both ways. Ignore the panic in the email. Check the source of truth. If the dashboard confirms it, act. If the dashboard is quiet, the email was bait.

YOUR RESPONSE PLAYBOOK A business owner checking her website's security
  • Suspicious email? Don't click — go back yourself
  • Check your provider's dashboard for the same alert
  • Confirmed real? Handle it — or hand it to whoever manages your site
  • Not sure what you're looking at? That's the moment to ask for help

Spot the fake — or never face it alone.

The last piece of website management is the human part: when an alert turns out to be real, someone has to handle it. That's us — a real person who reads your alerts, filters the fakes, and emails you when it's done. From $49/month, month-to-month, no contract.