ACS Blog

 

The Simple Checklist Every Employee Should Follow Before Opening an Email

May 12, 2026 | How-To

Email is still the number one way cybercriminals get into small businesses. And it’s not because your spam filter is broken — it’s because modern phishing emails are convincing enough to fool smart, experienced professionals.

The solution isn’t to stop using email. It’s to give your team a simple, repeatable process for evaluating every email before they click, reply, or download anything. Think of it like a pre-flight checklist — quick, easy, and designed to catch the things people miss when they’re moving fast.

The 6-Point Email Safety Checklist

Print this out. Post it near your team’s workstations. Make it part of your onboarding. The goal is to make these checks automatic — something your team does without thinking.

1. Check the Sender — Not Just the Name

Phishing emails often display a familiar name (like your CEO or a vendor) but use a completely different email address underneath. Don’t just glance at the name — look at the actual email address.

Watch for subtle tricks: a lowercase “L” replaced with a “1”, an extra letter in the domain name, or a completely different domain that looks close to the real one (like @micros0ft.com instead of @microsoft.com).

2. Look for Urgency or Pressure

Phishing emails almost always try to rush you. “Your account will be suspended in 24 hours.” “Wire this payment immediately.” “Respond now or lose access.”

Legitimate companies rarely communicate this way. If an email makes you feel like you have to act right now, that’s actually a reason to slow down and verify.

3. Hover Before You Click

Before clicking any link in an email, hover your mouse over it (without clicking) and look at the URL that appears. Does it match the company the email claims to be from? Does it look like a normal web address, or is it a long string of random characters?

If anything looks off — or if you’re not sure — don’t click. Go directly to the company’s website by typing the address into your browser instead.

4. Be Suspicious of Attachments

Unexpected attachments are one of the most common ways malware gets delivered. Be especially cautious with:

  • Files ending in .exe, .zip, .scr, or .js
  • Word or Excel files that ask you to “enable macros” or “enable content”
  • Any attachment from someone you don’t know or weren’t expecting to hear from

When in doubt, contact the sender through a different channel (phone call, text, or a new email — not by replying) to confirm they actually sent the attachment.

5. Watch for Grammar and Formatting Red Flags

While phishing emails have gotten much more polished in recent years, many still contain telltale signs: awkward phrasing, inconsistent formatting, generic greetings (“Dear Customer” instead of your name), or logos that look slightly off.

None of these alone are conclusive, but they’re worth noticing — especially in combination with other warning signs.

6. When in Doubt, Verify

This is the most important step. If something about an email feels off — even if you can’t put your finger on exactly what — don’t act on it. Instead:

  • Call the sender directly using a known phone number (not one from the email)
  • Forward the email to your IT team or provider and ask them to check it
  • Report it using your company’s reporting process (if you have one — and you should)

It’s always better to take 30 seconds to verify than to spend weeks recovering from a breach.

Make This Part of Your Culture

The checklist works — but only if your team actually uses it. Here’s how to make it stick:

  • Include it in onboarding for every new employee
  • Post it visibly — break rooms, shared spaces, or as a desktop wallpaper
  • Reinforce it with simulated phishing tests that give your team real practice
  • Celebrate good catches — when someone reports a suspicious email, acknowledge it publicly
  • Don’t punish mistakes — if someone clicks a bad link, use it as a learning opportunity, not a disciplinary event

The Takeaway

You don’t need a cybersecurity degree to protect your business from email threats. You just need a simple, consistent process that your entire team follows every day. This checklist is that process.

Want a printable version of this checklist for your office — or help setting up phishing simulations for your team? Reach out to us and we’ll get you set up.