Home › Knowledgebase › KB-522

How to recognise and safely handle a suspicious email that appears to come from a colleague or manager (internal impersonation)

Summary

This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email that appears to come from a colleague or manager (internal impersonation). Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Email scams that impersonate a colleague, manager, or even the CEO are one of the most common cyber threats facing Australian small businesses. These messages often look legitimate, use a real staff member's name in the display, and may reference a real project, invoice, or deadline to feel believable. The goal is usually to trick you into clicking a link, opening an attachment, transferring funds, or handing over your Microsoft 365 password. Knowing what to look for, and what to do before you act, is the best defence.

Common Warning Signs

Internal impersonation emails can be very convincing, but most contain at least one red flag. Pause and check for any of the following before responding or clicking anything:

Never trust the display name alone. In Outlook and most email clients, the sender's name can be set to anything. Always check the full email address by clicking on the sender's name or expanding the header details.

Quick Fix Steps

If you have received a suspicious email that appears to come from inside your organisation, follow these steps in order:

  1. Do not click any links or open any attachments. Move your mouse over (but do not click) any links to preview the real URL.
  2. Check the sender's full email address. In Outlook, double-click the sender's name to view the underlying From address. Confirm it matches your colleague's real address exactly.
  3. Verify out-of-band. Contact the person directly using a method you already trust — a phone call, a Teams message, or walking over to their desk. Do not reply to the email or use any contact details listed within it.
  4. Report the email using the Outlook Report Button. With the message selected, click Home > Report > Phishing. This sends the message to Microsoft and your organisation's security team.
  5. Delete the email from your Inbox and Deleted Items once it has been reported.
  6. Change your Microsoft 365 password immediately if you clicked a link, opened an attachment, or entered your credentials. See Password reset (Windows login) for guidance.
  7. Open a support ticket so the 220 team can review your account for signs of compromise. Open a Ticket

Detailed Instructions

Inspecting the Sender's Real Address

The display name on an email can be spoofed in seconds, but the underlying address is harder to fake. To check it in Microsoft Outlook:

  1. Open the suspicious message.
  2. Double-click the sender's name at the top of the email.
  3. A properties window will open showing the actual From address, the Reply-To address, and the mail server that delivered it.
  4. Compare the domain (the part after the @) carefully against the real address of your colleague. Look for swapped letters, extra words, or unusual country codes.

In Outlook on the web, click the three dots (...) next to the reply button and choose View > View message source for full header details.

Verifying the Request Safely

Even if the email looks like it came from your manager, never act on a sensitive request based on email alone. Use a separate channel:

Tip: If the email claims to be from your CEO or a senior manager and asks you to keep it confidential, that is itself a major warning sign. Genuine leadership requests can wait five minutes for a verification call.

Reporting Through Outlook

The built-in Report Button sends the message to Microsoft and, if your organisation has configured it, to the internal security team. To use it:

  1. Select the suspicious message (do not open it fully).
  2. On the Home ribbon, click Report.
  3. Choose Phishing from the dropdown.
  4. Click Report in the confirmation dialog.

If your version of Outlook does not show the Report button, your organisation may use the Report Phishing add-in instead. Look for a shield or flag icon on the ribbon or in the message window.

If You Have Already Clicked or Replied

Acting quickly can limit the damage. Complete these steps straight away:

  1. Disconnect from the network if you downloaded or ran an attachment. Turn off Wi-Fi or unplug the network cable.
  2. Do not enter any further information on any webpage that opened.
  3. Change your Microsoft 365 password from a different, trusted device. Use Password reset (Windows login) for step-by-step help.
  4. Enable or re-check multi-factor authentication (MFA) on your account. If you did not have MFA on, request it from 220 immediately.
  5. Check your mailbox rules in Outlook for any rules you did not create — attackers often add rules that auto-forward or hide replies.
  6. Review recent sign-in activity at https://mysignins.microsoft.com and sign out of any sessions you do not recognise.
  7. Notify your manager and the 220 team by submitting a ticket at Open a Ticket so we can audit your account and any connected systems.

Checking for Malicious Mailbox Rules

A common sign of compromise is an attacker adding a rule that hides their activity. To check in Outlook on the web:

  1. Click the Settings gear icon, then View all Outlook settings.
  2. Go to Mail > Rules.
  3. Review every rule. Delete anything you did not create, especially rules that move messages to a folder you do not recognise, mark them as read, or forward them to an external address.
  4. Repeat the check under Mail > Forwarding to make sure no automatic forwarding has been enabled without your knowledge.

Preventing Future Impersonation Emails

While no single control will stop every scam, a combination of the following will dramatically reduce your risk:

Need help? If you have received a suspicious email, clicked a link, or are unsure whether a message is genuine, contact the 220 support team straight away at app.220.com.au.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket