Protecting Your Business Email: Spam, Phishing, and Passwords

spam email illustration

Table of Contents

Your business email is more exposed than most people realise. It’s not just inbox clutter – fraudulent emails, fake login pages, and weak passwords cost UK businesses real money every year. Here’s what you need to know about the three most common threats, and how to deal with them.

Spam — the one everyone knows about

Spam is unsolicited bulk email – messages you didn’t ask for, sent to thousands of addresses at once. Most of it is harmless nuisance: things trying to sell you something you don’t want. Some of it isn’t.

The word “spam” for unwanted email comes from a Monty Python sketch where Vikings repeatedly drown out conversation by singing about tinned meat. The internet adopted it in the 1980s and 90s to describe any repeated, unavoidable noise – and the name stuck.

How to keep spam out of your inbox:

Use your email provider’s spam filters – Gmail and Outlook both have them built in and they’re reasonably good. Make sure they’re switched on and check your spam folder occasionally to confirm nothing legitimate is getting caught.

Don’t publish your email address on your website in plain text. Bots scrape contact details from web pages constantly. Write it as “yourname at yourdomain dot co dot uk” or use a contact form instead.

Use a secondary email address for sign-ups, newsletters, and online purchases. Keep your main address for clients and important correspondence.

Never reply to spam – not even to click “unsubscribe.” If the email is genuine spam, hitting unsubscribe confirms your address is active and you’ll get more, not less.

Report spam to your email provider. It helps their filters get smarter for everyone.

Stopping spam through your website contact form:

If you’re getting flooded with spam through your website’s contact form, there are a few reliable fixes.

A reCAPTCHA (the “I’m not a robot” checkbox, or the image selection version) stops most automated bots from completing forms. It’s the most common solution and works well for the majority of cases.

A honeypot field is a hidden form field that humans can’t see but bots fill in automatically. Your website can be set to reject any form submission where the honeypot field has been filled. Visitors never notice it – it just catches bots quietly in the background.

If you’re on WordPress, there are several anti-spam plugins (Akismet being the most well-known) that handle form spam effectively without adding friction for real visitors.

recaptcha I am not a robot

Phishing - the one that actually costs you money

Phishing is more serious than spam. It’s the attempt to obtain sensitive information – usernames, passwords, bank details – by pretending to be someone you trust.

Here’s a real example. An email arrives claiming to be from BT, warning of a declined direct debit and asking you to log in and update your billing information. On first glance it looks convincing. The fake website it links to looks convincing too. But look closer and the cracks appear:

  • The sender name said “British Telecom” – a name BT dropped in 1991
  • The email referenced a random number starting with a hash, not an actual account number
  • It addressed the recipient as “info” – the start of their email address, not their name
  • The actual sending address was from a funeral home in Utah, which had itself been compromised

Anyone who followed the link and entered their details would have handed over their BT login credentials and bank information to scammers.

bt-phishing-scam

The warning signs to look for:

The sender’s actual email address – not just the display name. Hover over it or tap to expand. If a legitimate company like PayPal or HMRC is sending from a Gmail address or something unrelated, it’s fake.

Your name – legitimate companies you have accounts with will address you by name. “Dear Customer” or “Dear info@yourdomain” is a red flag.

Account details – genuine emails about your account will usually reference your account number or the last four digits of a card. Vague references to “your account” without specifics are suspicious.

Urgency – phishing emails almost always try to create panic. “Your account will be suspended,” “Immediate action required,” “Verify now.” Legitimate companies don’t communicate like this.

Links – hover over any link before clicking. The URL that appears should match the company’s actual domain. Anything that doesn’t match, looks slightly misspelled (paypa1.com, hmrc-refund.co.uk), or uses a completely unrelated domain is fraudulent.

If you receive a phishing email:

Don’t click anything. If you’re genuinely unsure whether an email is real, contact the company directly through their official website or phone number – not through any contact details in the email itself.

Report it. Most major companies have a dedicated phishing reporting address (BT’s is phishing@bt.com, for example). You can also forward suspected phishing emails to report@phishing.gov.uk – the UK’s National Cyber Security Centre.

If you’ve already clicked a link and entered details, change your passwords immediately and contact your bank if any financial information was involved.

Passwords - the one most people get wrong

The problem with passwords is straightforward: if they’re easy to remember, they’re probably easy to crack. Most people know this and do it anyway.

Here’s some context that might change your approach. Modern computers can attempt billions of password guesses per second. The time it takes to crack a password scales dramatically with length and complexity:

  • “12345” — cracked instantly
  • “trapstorm” – cracked in 2 minutes
  • “G7r#8zP!9q” – approximately 5,000 years
  • “cloud-vanish-horizon!82” – approximately a sextillion years

You don’t need to make passwords impossible to remember. You need to make them expensive enough to crack that attackers move on to easier targets.

Rules for passwords that actually hold up:

Make them long – 12 characters minimum, 16 or more for anything important. Length is the single biggest factor in resistance to brute force attacks.

Mix character types – uppercase, lowercase, numbers, and symbols. “Cloudvanish” is weaker than “Cl0ud-V@n!sh” even at the same length.

Avoid anything personal – your name, date of birth, pet’s name, address. This information is often findable online and is where attackers start.

Avoid dictionary words alone – “sunshine” or “football” are cracked in seconds. If you want to use words, combine unrelated ones with symbols between them: “Tr@p*St#rM” takes around 1,000 years.

Never reuse passwords – if one account is compromised and you’ve used the same password elsewhere, all those accounts are now compromised too. Use a different password for every account.

Change important ones regularly – every three to six months for accounts with financial information or sensitive data.

Password managers:

If the idea of remembering dozens of unique passwords sounds impossible, that’s because it is – and you’re not supposed to. Password managers exist specifically for this. They generate strong random passwords, store them securely, and fill them in for you.

If you’re on an iPhone, iCloud Keychain does this automatically – creating strong passwords when you sign up for new accounts, storing them, filling them in, and warning you if any have appeared in known data breaches. Android users have Google Password Manager, which works the same way across your devices.

If you’d rather use something platform-independent, 1Password and Dashlane are both well-regarded options that work across all devices and browsers.

Passkeys - where things are heading:

Passkeys are beginning to replace passwords altogether, and it’s worth knowing about them. Instead of a password, a passkey uses a cryptographic key stored on your device. You authenticate with your face, fingerprint, or PIN – and that’s it. Nothing gets sent over the internet that can be intercepted or stolen.

The practical benefits are significant: passkeys can’t be phished (there’s no password to hand over to a fake site), they can’t be leaked in a database breach, and they’re faster to use. Apple, Google, and Microsoft are all implementing them, and support is growing across major websites and apps.

Both iPhones (iOS 16 and above) and Android phones now support passkeys, stored in iCloud Keychain and Google Password Manager respectively. If a site or app offers the option to switch to a passkey, it’s worth doing.

Passwords aren’t going away overnight, but passkeys are the direction of travel – and for good reason.

Website security is part of what we cover in our website support and maintenance contracts – including regular password audits, plugin updates, and keeping your site protected. Get in touch if you want to know more.

Share the Post:

related posts