Free tool
Can you spot the AI phishing email?
Eight emails. For each one, decide whether it is legitimate or a phishing attempt, and we'll tell you what actually gives it away. Takes about three minutes, and there is no sign-up.
Most of us were taught to look for bad spelling, broken grammar and odd formatting. That advice is now worse than useless: an attacker can generate fluent, perfectly formatted business English for nothing, and staff who were taught the old rule will read a well-written email as a safe one. The tells that still work are about the sender and the request — not the prose.
Action required: your password expires in 24 hours
Microsoft 365 Security <no-reply@m365-security-alerts.net>
Your Microsoft 365 password for victor@medinatechsolutions.com is scheduled to expire within 24 hours.
To avoid interruption to your email and shared files, please confirm your current credentials using the secure portal below. This process takes less than a minute.
Keep your current password →
Questions we get about this
Can you still spot a phishing email by its spelling and grammar?
No, and teaching people that rule now does harm. Generative AI writes fluent, correctly formatted business English at no cost, so poor writing has stopped being a reliable signal — and staff trained to look for it will read a well-written phish as safe. The durable tells are structural: who actually sent it, what it is asking you to do, and whether it is trying to move you off a channel where you could verify.
What is the single most dangerous email a small business receives?
One that changes where money goes. A supplier announcing new bank details is the highest-value attack there is, and it usually reads as entirely routine. Verify any change to payment details by voice, on a number from your own records rather than one supplied in the email.
Should I use an AI detector to check whether an email was written by AI?
We would not rely on one. AI text detectors produce both false positives and false negatives at rates that make them unsafe for this decision, and knowing an email was machine-written does not tell you it is malicious — plenty of legitimate business email is drafted with AI now. Judge the sender and the request instead.
How can I check whether criminals can send email pretending to be my business?
That depends on your domain's SPF, DKIM and DMARC records. If they are missing or misconfigured, an attacker can send mail that appears to come from your own domain and passes basic checks. Our free email spoofing check reads those records and tells you what is exposed.
Reading on this
- The Phishing Email Doesn't Have Typos AnymoreWhy the advice everyone was trained on stopped working, and what replaces it.
- Someone Called Sounding Exactly Like Your BossVoice cloning needs about thirty seconds of audio. The callback rule that defeats it.
- Your Staff Are Pasting Company Data Into ChatGPTNobody is being reckless. That is what makes it hard to see.