Skip to main content

Email Security Guide: Phishing, Spam, and Spoofing Explained

Email SecurityComplete Guide9 min read · June 2026
Hero image: sourcing in progress

Email is the number one attack vector for cyber crime. The NCSC reports that phishing remains the most common technique used against UK organisations and individuals; almost all ransomware infections and business email compromise incidents start with a single email. This guide covers the main email threats, how to protect yourself, and what businesses should do to stop their domain being used to attack others.

Email is your highest-risk account

If a criminal gains access to your email account, they can reset the password for every other account linked to that email address. Your email account is a master key: protecting it with a unique password and two-factor authentication is the single most important thing you can do.

The Main Email Threats

Phishing

Mass emails impersonating trusted organisations (banks, HMRC, Royal Mail, NHS) to steal credentials or financial details. Volume-based: criminals send millions hoping for a small percentage of victims.

Spear phishing

Targeted phishing using personal information to make the email more convincing. Uses your name, role, recent transactions, or employer. More sophisticated and harder to spot.

Business email compromise (BEC)

An attacker gains access to or impersonates a business email account (typically a finance director or CEO) and requests urgent wire transfers or changes to payment details. Causes significant financial losses.

Email spoofing

Emails that appear to come from a legitimate address but were sent from elsewhere. Technical controls (SPF, DKIM, DMARC) prevent your domain being spoofed. Weak email providers allow incoming spoofed mail.

Malware attachments

Malicious files disguised as invoices, delivery notifications, or HR documents. Opening them installs malware, ransomware, or keyloggers on your device.

Personal Email Protection

Use a strong, unique password for your email, not reused anywhere. Your email is the master key to all other accounts.
Enable two-factor authentication on your email account: this is the single most effective protection.
Never click links in unexpected emails: go directly to the website by typing the URL.
Never open attachments you were not expecting, even from known senders. Call the sender on a known number to confirm.
Check the actual sender address, not just the display name; look for subtle misspellings.
Forward suspicious emails to report@phishing.gov.uk (NCSC service) before deleting.

Check your email security. Free.

Cyber Nova AI gives you a personalised checklist covering email security, two-factor authentication, and password hygiene, the three controls that prevent most email-based attacks.

Start for free →

Related guides

Frequently asked questions

How do I tell if an email is genuine or phishing?

Check the sender's actual email address (not just the display name). Look for urgency pressure ('your account will be closed in 24 hours'). Hover over links without clicking to see the real URL: it should match the organisation's domain. Genuine banks, HMRC, and companies will never ask for your password or full card number by email. When in doubt, go directly to the organisation's website by typing the URL yourself.

My email has been hacked. What should I do?

Change your email password immediately using a different device if you think a device may be compromised. Enable two-factor authentication. Check your account settings for forwarding rules, filters, and connected apps; criminals often add a hidden forwarding rule so they continue receiving your emails after you change the password. Change passwords on any account that uses the same email address for password resets. Alert your contacts that your email was compromised so they know to ignore suspicious messages that appeared to come from you.

What is email spoofing?

Email spoofing is when a criminal sends an email that appears to come from a legitimate address: your bank, HMRC, or even someone in your contacts. Basic spoofing can be done by anyone without accessing the real account. More sophisticated spoofing exploits weak SPF (Sender Policy Framework) or DMARC records. For businesses, implementing SPF, DKIM, and DMARC records prevents criminals from spoofing your domain to attack your clients.