← All articles
Security7 min read

The Phishing Email Doesn't Have Typos Anymore

Almost everyone who has sat through a security awareness session was taught the same rule: phishing emails are badly written. Look for the typos, the odd grammar, the strange formatting, the greeting that says "Dear Valued Customer". For about twenty years that rule was genuinely useful, because the people sending these emails often weren't writing in their first language and volume mattered more to them than polish.

That rule is now worse than useless, and it's worth being precise about why. It isn't merely that it stopped catching things. It's that it taught a generation of staff the inverse — that a fluent, well-formatted, professionally worded email is probably legitimate. Generative AI can produce that for nothing, at any volume, in any register. The rule has been quietly inverted into a vulnerability.

What changed, concretely

Three things happened at roughly the same time. Text generation got good enough that fluency costs nothing. Personalisation got cheap, because scraping a target's role, employer, colleagues and recent activity from public sources can be automated end to end. And voice cloning got good enough to matter, which means an email is no longer the only channel in the attack.

The result is that the economics flipped. Spear phishing — the carefully researched, individually written attack — used to be reserved for high-value targets because a human had to write each one. That constraint is gone. A small business in Middlesex County can now receive the quality of attack that was previously aimed at large corporate finance departments.

The tells that still work

The useful signals were always structural rather than stylistic. They're about who sent the message, what it wants, and whether it's trying to prevent you from checking. None of them care how well it's written.

  • The sending domain, read character by character. Not the display name, which is free to set to anything. Look for the extra hyphen, the .net where it should be .com, the l standing in for an i.
  • Any request that changes where money goes. New bank details, updated remittance advice, a different account for this one invoice. This is the single highest-value attack against a small business.
  • Any request for credentials, however it's dressed. Real services do not ask you to confirm your password by email.
  • Pressure to act before you can verify — a deadline, a cutoff, a penalty for delay, or an explanation of why the sender can't take calls right now.
  • An attempt to move you to a channel you can't check: a personal mobile number, a WhatsApp thread, a reply-to that differs from the sender.
  • Links whose destination doesn't match the text. Hover on a computer, press and hold on a phone, and read the real address before clicking.

The rule that does most of the work

If you adopt one thing from this article, make it this: any change to payment details is verified by voice, on a number you already hold, before anything is paid. Not a number in the email. Not by replying to the email. A number from your own records, or from the last invoice you know was genuine.

This one rule defeats the entire category of attack that costs small businesses the most money, and it does so regardless of how convincing the email is, how well it's written, or how much the attacker knows about your business. It works precisely because it doesn't depend on anyone spotting anything.

What to change in your training

If your security awareness material still tells people to look for spelling mistakes, that material is now teaching a false negative. Replace it. The lesson worth teaching is that legitimacy is judged from the sender and the request — and that the well-written, entirely plausible message deserves the same treatment as the clumsy one.

It's also worth being honest with staff about the second-order effect: because good writing no longer signals legitimacy, real emails from real colleagues will occasionally get questioned. That is the correct outcome, and the culture has to make it cheap to ask.

The part you can fix technically

Alongside the human side, there's a technical question worth answering: can someone send email that appears to come from your domain? That depends on your SPF, DKIM and DMARC records, and a surprising number of small businesses have them missing or half-configured. If they are, an attacker doesn't need to register a look-alike domain — they can use yours.

Our free email spoofing check reads those records and tells you what's exposed, and the wider IT audit covers the rest of the picture. If you'd rather someone simply set it up properly and keep an eye on it, that's part of what managed IT support covers.

Rather have someone handle it? This is part of our managed it support service across Middlesex, Somerset and Mercer County.

Need a hand?

We handle this for New Jersey businesses and homes

Whether it's a one-off problem or ongoing support, we're happy to take a look — and to tell you honestly if you don't need us.

Keep reading