Evergreen FAQ

How to Spot a Fake Invoice or Login Page Before You Click

Jul 12, 2026

A staff member gets an email from what looks like a familiar vendor. The logo is right, the tone is professional, and there is a "Pay Now" button front and center. It feels routine. Then someone flags it, and suddenly the whole team is asking the same question: how did that almost work?

This scenario comes up regularly for the logic-IT team. Phishing emails and fake login pages are not crude anymore. They are built to pass a quick glance, and they often do. The difference between a costly mistake and a near miss usually comes down to knowing exactly where to look.

The Details That Give Fakes Away

Attackers put real effort into making fraudulent emails look legitimate, but they almost always leave traces. The most common tells include:

  • A sender domain with one transposed letter. The display name may say your vendor perfectly, but the actual sending address might read "invoi ces@acm e-supp1ies.com" instead of the real domain. One character off is all it takes.
  • A payment button that routes somewhere unexpected. Hover over any "Pay Now" or "Click Here" link before you touch it. If the URL does not clearly match the vendor's actual domain, treat it as suspicious.
  • A login page without HTTPS. Any page asking for credentials should show a padlock and "https" in the address bar. A page that loads over plain HTTP is a hard stop.
  • Urgency without a paper trail. Real vendors rarely send a first contact as an urgent payment demand. If there is no prior invoice, purchase order, or conversation to match it against, that pressure is a tactic, not a deadline.

The One Habit That Stops Most Attacks

Spotting visual clues helps, but the single most reliable defense is verifying through a separate channel you already trust. That means picking up the phone and calling the vendor using a number from a previous paper statement, your own saved contacts, or the vendor's official website. Do not use any contact information inside the suspicious email itself. An attacker who sent the email also controls whatever phone number or reply address appears in it.

This one step, calling to confirm before acting on any unexpected financial request,

Dealing with something similar at your business? We can help.

Talk to logic-IT
← Back to all posts