Phishing Exposed and How to Stop It Before Anyone Clicks

Sofia Ramirez
Sofia Ramirez Design & Templates Editor at 4OVER4.COM

Phishing is impersonation, not hacking. The messages are built to a pattern, five checks catch them, and a few controls still hold after somebody clicks.

Phishing is a message that borrows a trusted identity to make an ordinary request: sign in, pay this, open that. It works on attention rather than ignorance, so the defense that holds is a rule you follow when you are busy, not a fact you memorised. That rule is never authenticate and never pay from a link. Behind it, the controls worth paying for are the ones that still work after a person clicks: a password manager that refuses to fill a lookalike domain, a security key bound to the real site, and a callback on any change to bank details.

Large format posters printed by 4OVER4 for workplace wall display

Quick answer

A borrowed name, an ordinary request, and one rule that holds

Phishing succeeds because the ask is normal and the sender looks familiar. Bulk campaigns go to everyone, spear phishing is written for one named person, and business email compromise arrives from a genuine supplier mailbox that passes every technical check. Filters and mail authentication clear the noise. What stops the expensive ones is a password manager that will not autofill a lookalike domain, a security key that answers only the real site, and a phone call on any change to bank details.

Where each control breaks the phishing chain A five stage chain runs left to right: message sent, message delivered, message opened, credentials typed, account used. Mail authentication and filtering cut the first two links, the human check cuts the third, a password manager cuts the fourth, and an origin bound security key cuts the fifth. A dashed bypass line shows that a message sent from a real supplier mailbox that has been taken over passes authentication and filtering untouched, so only the last three controls can still stop it. Where each control breaks the phishing chain Every control cuts one link. None of them cuts all five. 1. Sent from a faked name 2. Delivered lands in the inbox 3. Opened link is clicked 4. Typed password on a copy 5. Used attacker signs in SPF, DKIM, DMARC plus the spam filter The human check real domain, reply-to Password manager will not autofill a copy FIDO2 security key bound to the real site Real supplier mailbox, taken over signed correctly, so it passes 1 and 2 Mail authentication protects your own domain from exact spoofing. It says nothing about a lookalike domain, and nothing at all about a genuine account that now belongs to somebody else.

How a Phishing Message Is Actually Built

Printed brochures from 4OVER4 of the kind used for staff onboarding and security policy packs

Every phishing message has the same five parts: a borrowed identity, a pretext, a reason to move now, one action, and the payload waiting behind it. Strip a message down to those five and the sales pitch falls apart.

The pretext is the part that decides whether it works. A fake invoice that lands in accounts payable during the week of a real project is not luck, it is fifteen minutes of reading your website, your LinkedIn hiring posts and a press release. The identity is cheap to fake, the urgency is a template, and the action is nearly always one of three things: sign in here, approve this payment, open this file. What varies is how well the story fits your week.

The delivery route changes the tells, so it helps to know which shape you are looking at.

TypeHow it arrivesWho it targetsThe usual askThe tell that survives
Bulk phishingMass email to scraped addresses.Anyone with a mailbox.Log in to fix a problem with an account.Generic greeting, and a sending domain with no relationship to the brand it names.
Spear phishingOne email written for one person.A named role: finance, HR, an admin.Open this file or approve this request.The details are right, but the domain was registered recently and has no history with you.
Business email compromiseA reply inside a real thread, often from a real supplier account.Whoever pays invoices.Change the bank details before the next payment.The request lands near a genuine payment date and quietly resists a phone call.
SmishingSMS or a chat app.Phone first staff and drivers.Tap a short link to confirm something.A shortened link, and a number that is not the one you already have on file.
QuishingA QR code in an email or printed on paper.Anyone with a phone camera.Scan and sign in.The code resolves to a domain nobody recognises, or the sticker sits on top of the original code.

Business email compromise deserves the extra attention it gets. It is the one that arrives from a genuine, correctly signed mailbox, so every technical check passes, and it is the one that moves real money out of a real account. A payment rule beats a spotting skill here, which is the argument in the cash flow system guide as well.

The Five Checks That Catch Almost Everything

Custom printed notepads from 4OVER4 used at a desk for callback notes and verification logs

Spotting advice usually arrives as a list of twenty warning signs, which nobody recalls under pressure. Five is about the limit of what a person uses in real life, and these five are ordered from fastest to most reliable.

  1. Read the address, not the name. The display name is free text the sender chooses. Expand it and look at the domain after the @ sign.
  2. Check where a reply would go. A message that looks like it comes from your director but replies to a different address is finished right there.
  3. Look at the real destination of the link, then do not use it. Hover on a desktop and read the status bar. Then open the site through your own bookmark or by typing the domain, because a genuine alert will still be there when you arrive.
  4. Let the password manager vote. If it does not offer to fill the login page, the domain is not the one it saved. That is a string comparison, and it beats human eyesight at the end of a long day.
  5. Call back for anything about money or access. Use a number you already had, never the one in the message. One call is cheap insurance against the most expensive category of fraud there is.

Two honest limits. On a phone the sending address hides behind the display name and there is nothing to hover over, so mail read on a phone deserves more suspicion rather than less. And a message from a supplier whose mailbox is already compromised passes every header check you can run, because it genuinely is from them. That is why check five is the one that carries real weight and the other four are triage.

Put the Rule Where the Decision Gets Made

Large format posters printed by 4OVER4 for wall display in an office or break room

Nothing printed blocks a phishing email. What paper does is put the rule in front of the person at the moment they are deciding, which is the moment their laptop is the thing they no longer trust. A policy in a shared drive is invisible during those thirty seconds. A card taped to a monitor is not.

Four pieces cover most of it. A desk card, business card size, carrying the callback rule and the internal address for reporting a suspicious message, which is the one thing people forget when they panic. Standard business cards start at $17.57 and print in quantities where every desk gets one. A wall poster in the break room or above the shared printer, big enough to read from across the room and worth rotating each quarter, since a poster that has hung for two years is furniture. Standard posters start at $108.75, and the poster sizes guide covers what reads at what distance.

Then a short brochure in the onboarding pack, giving new starters the escalation path on day one instead of month four. Standard brochures start at $57.11. Finally a notepad beside the phone in accounts payable, printed with the four questions to ask on a verification callback, so the log is written rather than remembered. Standard notepads start at $93.37, and the notepad sizes and uses guide explains sheet counts and formats. For an awareness push in a single month, standard flyers from $39.54 are the cheapest way to put the same message on every desk at once.

One thing to check on your own printed work while you are at it. If you print QR codes on posters, table cards or mailers, print the plain web address beside the code, point it at a domain you own rather than a shortener, and walk past your own display now and then to be sure nobody has stuck a different code over yours. The marketing materials range covers the formats, and a blank template keeps the artwork at the right size.

What Each Defense Actually Stops, and What It Misses

Standard business cards printed by 4OVER4, the format used for desk reference cards

Security budgets get spent on the control that is easiest to buy rather than the one that closes the gap in front of you. Read the third column first, because that is where the next incident lives.

ControlWhat it stopsWhat it missesWhat it costs you
SPF, DKIM, DMARC at rejectMail that fakes your exact domain.Lookalike domains, free mail accounts using your name in the display field, and real accounts taken over.A staged rollout, since jumping straight to reject can bounce forwarded mail and list traffic.
Filtering gatewayBulk campaigns and known bad links, at volume.Mail written for one person, and anything sent from a clean, genuine mailbox.A license per seat and a quarantine that somebody has to review.
FIDO2 keys or passkeysCredential theft outright, because the credential answers only the real domain.Malware, and any fraud that never involves signing in.Hardware per person, and a recovery plan for the day a key is lost.
App codes or push approvalPassword only theft, which is most of the bulk noise.Real time relay, where the fake page collects the code and spends it in seconds, plus approval fatigue late at night.Very little, which is why it is the floor rather than the finish line.
Password manager for everyoneA password typed into a lookalike domain, since it will not autofill.Somebody who overrides it and copies the password across by hand.The license, plus about a week of migration grumbling.
Callback rule on bank changesThe invoice fraud that costs the most per incident.Credential phishing, which never touches a payment.One phone call per change, and a finance team confident enough to make it.

Two patterns fall out of that table. The controls at the top are cheap and stop volume, and the controls further down are the only ones still working when a message arrives from a real, signed, trusted mailbox. Most companies buy the top half and stop. Rolling out the bottom half is a change management job more than a technical one, which is covered in the change management playbook.

The First Hour After Somebody Clicks

Printed flyers from 4OVER4 of the kind used for a company wide awareness push

Assume the click happens, because eventually it does. The size of the loss is set almost entirely by what happens in the following hour, so this sequence is worth printing and pinning up before you need it.

  1. Change the password from a different device, then revoke active sessions. A reset on its own leaves a stolen session token signed in and working.
  2. Check mailbox rules and forwarding. The standard first move inside a captured mailbox is a rule that files replies from finance into an archive folder, so the real owner never sees the conversation happening in their name.
  3. Look for a new authenticator or app password. An added second factor is a back door that survives every password reset you do afterwards.
  4. If money or bank details were in scope, call the other party on a number from your own records, and tell your bank in the same hour. Recall windows on transfers are measured in hours, not days.
  5. Keep the message with full headers. A screenshot loses the routing information that shows where it really came from.
  6. Tell everyone what it looked like. The same pretext almost always lands on several desks in the same morning.
  7. Do not punish the person who reported. The cost of the incident is set by the delay, and the delay is set by whether reporting feels safe.

Write those seven lines down, put them where the people who need them work, and rehearse the callback once so it is not the first time anyone has done it. If you are building the wider plan around it, the small business marketing guide shows which of your contact details are public and therefore already in an attacker's notes.

Wally explains phishing

The name is borrowed, the request is normal

Wally, the 4OVER4 mascot with a 4, holding a fishing hook baited with a fake login page while he checks the real web address on a printed desk card

Wally gets an email from his own bank, or so the name says. He reads the address after the @ sign instead of the friendly name, and it belongs to nobody. Then he does the thing that works even when the address looks perfect: he ignores the link, opens the site from his own bookmark, and finds no alert waiting. For anything about money he picks up the phone and calls the number he already had. Wally keeps that rule on a card at his desk, because nobody reads a policy at the moment they need it.

Print security awareness posters →

Specs and pricing

Formats for an awareness program, with starting prices

Posters for the wall, flyers for a single month push, notepads for the callback log at the finance desk. Live configuration choices and starting prices straight from the 4OVER4.COM configurator.

Standard Posters
Standard Posters
From $108.75
Default size 11" x 17"
Paper Type
9 options
Ink Color
2 options
Finish
2 options
Folding
10 options
Scoring
1 option
Perforation
2 options
Paper stocks
9
Configurable groups
7
Standard Flyers
Standard Flyers
From $39.54
Default size 4.25" x 5.5"
Paper Type
7 options
Ink Color
2 options
Finish
2 options
Folding
1 option
Scoring
1 option
Perforation
1 option
Paper stocks
7
Configurable groups
9
Standard Notepads
Standard Notepads
From $93.37
Default size 4.25" x 5.5"
Paper Type
1 option
Ink Color
2 options
Sheets/Pad
2 options
Three-Hole Punch
1 option
Proof Options
3 options
Paper stocks
1
Configurable groups
5

Print it

Put the rule on the wall and on the desk

Standard Posters
Standard Posters
From $108.75
70 ordered
View and customize
Standard Brochures
Standard Brochures
From $57.11
150 ordered
View and customize
Standard Business Cards
Standard Business Cards
From $17.57
303 ordered
View and customize

By the numbers

Posters and desk pads that keep the rule in sight

150,000+ Businesses served
25+ Years printing
1,000+ Products
99.8% On-time delivery

Common Questions

Your phishing questions, answered

What is phishing, in plain terms?

Phishing is a message that pretends to come from someone you trust so you will hand over a password, a payment, or access to a system. It arrives by email, text, chat or a QR code, and it asks for something you do every week: confirm your login, approve an invoice, open a shared file. Nothing is broken into. The attacker uses your own habits and a borrowed identity, which is why technical staff fall for it as often as anyone else when the pretext lines up with a real project.

How do I tell a phishing email from a real one?

Read the actual address rather than the display name, since the friendly name is free text an attacker chooses. Check whether reply-to points somewhere different from the sender. Look at where a link really goes before you touch it, then open the site through your own bookmark instead of the link anyway. The strongest check is the least effort: if your password manager does not offer to fill in the login page, the domain is not the one it saved, and that is a machine comparing strings rather than your eye at 4pm.

Does DMARC stop phishing?

It stops one specific kind. With SPF and DKIM published and DMARC set to p=reject, mail that claims to come from your exact domain and is not signed gets rejected before it lands, which kills the classic fake invoice sent as your own billing address. It does nothing about a lookalike domain registered a week ago, nothing about a free mail account carrying your CEO name in the display field, and nothing about a genuine supplier mailbox that has been taken over, because that mail is properly signed by the supplier. Move to p=reject in stages too, since forwarded mail and mailing lists can break when you jump straight there.

Is SMS or app-based two-factor good enough?

It is the floor, not the ceiling. Any code you can read and type can be relayed: the fake page asks for the code, passes it to the real site inside its valid window, and the attacker is in. Push approvals add fatigue, where the tenth prompt at 11pm gets tapped to make it stop. A FIDO2 or passkey style security key removes the whole class of attack because the credential is bound to the real domain and simply will not answer a copy. Put keys on the accounts that matter first: email, finance, and anything that can reset other passwords.

Are QR codes a phishing risk?

Yes, and it has a name, quishing. A QR code hides its destination, so the usual habit of reading a link before tapping it does not apply, and a filter that scans text often does not read the image. Two habits fix most of it. When you scan, check the domain on the preview screen before the page loads. When you print a code on a poster, flyer or table card, print the plain web address next to it so a reader can compare, point it at a domain you own rather than a shortener, and walk your own display once in a while to make sure nobody has stuck a different code over yours.

What do I do if I already typed my password into a fake page?

Work in this order. Change the password from a different device, then revoke active sessions, because a reset on its own leaves a stolen session token working. Check the mailbox for new rules and forwarding addresses, since the first move inside a mailbox is usually a rule that hides replies from finance. Look for a new authenticator or app password added to the account, which is a back door that survives the reset. If bank details were in scope, call the other party on a number from your own records and tell your bank the same hour. Then keep the original message with full headers, and tell colleagues what it looked like, because the same pretext usually arrives at several desks.

★ 4.810,000+ reviewsacross Google, Trustpilot, Facebook & 4OVER4.com
5Written guarantees
G7Certified printer
150K+Businesses served
25+Years printing

Get Started

Posters run 50 for $108.75, notepads 25 for $93.37

Print the callback rule on a desk card, the report address on a break room poster, and the escalation path in the onboarding brochure. Pick your size, upload the artwork, and we ship it.

Legal Disclaimer

Gold Standard guarantees apply to all standard orders placed through 4over4.com. Price match requires verifiable proof of a competitor's published price for an equivalent product with matching specifications and turnaround time. Satisfaction guarantee covers manufacturing defects and print quality issues. Contact support with order number and documentation. On-time delivery rate based on tracked orders 1999 to 2026. Individual results may vary based on shipping carrier performance.

FSC Certified Printer #C013635
G7 Certified Color Accuracy
25+ Years Since 1999
150,000+ Businesses Served