How to recognise and safely handle a suspicious email that appears to come from a colleague or manager (internal impersonation)
Summary
This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email that appears to come from a colleague or manager (internal impersonation). Follow the steps below to fix the issue.
Common Causes
Email scams that impersonate a colleague, manager, or even the CEO are one of the most common cyber threats facing Australian small businesses. These messages often look legitimate, use a real staff member's name in the display, and may reference a real project, invoice, or deadline to feel believable. The goal is usually to trick you into clicking a link, opening an attachment, transferring funds, or handing over your Microsoft 365 password. Knowing what to look for, and what to do before you act, is the best defence.
Common Warning Signs
Internal impersonation emails can be very convincing, but most contain at least one red flag. Pause and check for any of the following before responding or clicking anything:
- Urgency or pressure — phrases like "I need this in the next 30 minutes" or "please don't loop anyone else in" are designed to stop you thinking.
- Unusual request — a manager asking you to buy gift cards, change bank details, or wire money to a new account.
- External or lookalike email address — the display name shows your colleague, but the actual address is something like
[email protected]or[email protected]instead of[email protected]. - Link mismatch — hovering over a button or link reveals a different URL to the one shown in the text.
- Unexpected attachments — especially
.html,.zip,.exe, or password-protected files you weren't expecting. - Generic greeting — "Hi there" instead of your actual name, even from someone you speak to daily.
- Requests to bypass normal process — being told not to follow standard approval or finance procedures.
Quick Fix Steps
If you have received a suspicious email that appears to come from inside your organisation, follow these steps in order:
- Do not click any links or open any attachments. Move your mouse over (but do not click) any links to preview the real URL.
- Check the sender's full email address. In Outlook, double-click the sender's name to view the underlying
Fromaddress. Confirm it matches your colleague's real address exactly. - Verify out-of-band. Contact the person directly using a method you already trust — a phone call, a Teams message, or walking over to their desk. Do not reply to the email or use any contact details listed within it.
- Report the email using the Outlook Report Button. With the message selected, click Home > Report > Phishing. This sends the message to Microsoft and your organisation's security team.
- Delete the email from your Inbox and Deleted Items once it has been reported.
- Change your Microsoft 365 password immediately if you clicked a link, opened an attachment, or entered your credentials. See Password reset (Windows login) for guidance.
- Open a support ticket so the 220 team can review your account for signs of compromise. Open a Ticket
Detailed Instructions
Inspecting the Sender's Real Address
The display name on an email can be spoofed in seconds, but the underlying address is harder to fake. To check it in Microsoft Outlook:
- Open the suspicious message.
- Double-click the sender's name at the top of the email.
- A properties window will open showing the actual
Fromaddress, theReply-Toaddress, and the mail server that delivered it. - Compare the domain (the part after the
@) carefully against the real address of your colleague. Look for swapped letters, extra words, or unusual country codes.
In Outlook on the web, click the three dots (...) next to the reply button and choose View > View message source for full header details.
Verifying the Request Safely
Even if the email looks like it came from your manager, never act on a sensitive request based on email alone. Use a separate channel:
- Phone call — call the person on the number already saved in your contacts, not a number listed in the email.
- Microsoft Teams — send a new chat message from within the app. If the email is a scam, the real account owner will not see your Teams message reply.
- In person — if the colleague is in the same office, a quick conversation is the fastest way to confirm.
Reporting Through Outlook
The built-in Report Button sends the message to Microsoft and, if your organisation has configured it, to the internal security team. To use it:
- Select the suspicious message (do not open it fully).
- On the Home ribbon, click Report.
- Choose Phishing from the dropdown.
- Click Report in the confirmation dialog.
If your version of Outlook does not show the Report button, your organisation may use the Report Phishing add-in instead. Look for a shield or flag icon on the ribbon or in the message window.
If You Have Already Clicked or Replied
Acting quickly can limit the damage. Complete these steps straight away:
- Disconnect from the network if you downloaded or ran an attachment. Turn off Wi-Fi or unplug the network cable.
- Do not enter any further information on any webpage that opened.
- Change your Microsoft 365 password from a different, trusted device. Use Password reset (Windows login) for step-by-step help.
- Enable or re-check multi-factor authentication (MFA) on your account. If you did not have MFA on, request it from 220 immediately.
- Check your mailbox rules in Outlook for any rules you did not create — attackers often add rules that auto-forward or hide replies.
- Review recent sign-in activity at
https://mysignins.microsoft.comand sign out of any sessions you do not recognise. - Notify your manager and the 220 team by submitting a ticket at Open a Ticket so we can audit your account and any connected systems.
Checking for Malicious Mailbox Rules
A common sign of compromise is an attacker adding a rule that hides their activity. To check in Outlook on the web:
- Click the Settings gear icon, then View all Outlook settings.
- Go to Mail > Rules.
- Review every rule. Delete anything you did not create, especially rules that move messages to a folder you do not recognise, mark them as read, or forward them to an external address.
- Repeat the check under Mail > Forwarding to make sure no automatic forwarding has been enabled without your knowledge.
Preventing Future Impersonation Emails
While no single control will stop every scam, a combination of the following will dramatically reduce your risk:
- Multi-factor authentication (MFA) on every Microsoft 365 account — this is the single most effective control against credential theft.
- Staff training and simulated phishing — regular, short awareness sessions keep warning signs fresh in everyone's mind.
- Clear internal processes — finance and procurement teams should have documented approval workflows that cannot be bypassed by a single email request.
- Email filtering and anti-spoofing — Microsoft 365 Defender and DMARC policies help block impersonation before it reaches your inbox.
- A no-blame reporting culture — staff who click a suspicious link should feel safe reporting it immediately. Fast reporting limits damage far more than fear of punishment.
Still Having Issues?
💻 Open a Ticket