16 September 2026
How to Spot a Scam Email Now That They Look Real
By Jack Wetson-Catt
Image by Mohamed_hassan on Pixabay
Ask most people how to spot a scam email and they'll tell you to check for typos. Bad spelling, clumsy grammar, a sentence that reads slightly wrong. That advice worked for years, and it's stopped working.
Scammers write with AI now, and AI doesn't make those mistakes. A message that used to arrive full of odd phrasing now reads as cleanly as anything from a real supplier, a real client, or a colleague two desks away. Here at Atema, the suspicious emails our clients across Gloucestershire and the wider South West flag to us have shifted the same way. Where a scam used to stand out on sight, more of what gets forwarded to us now reads as a completely ordinary email that just happens to be asking for something it shouldn't.
Why "check the spelling" stopped working
The old tell worked because a lot of phishing was written by someone working in their second language, and the mistakes gave it away. AI removed that.
The National Cyber Security Centre's own assessment of AI and the cyber threat puts it plainly: generative AI can already be used to create convincing messages "without the translation, spelling and grammatical mistakes that often reveal phishing." That's the one thing most staff were trained to watch for, and it no longer tells you much of anything.
What makes an AI-written scam so convincing
Three things have changed, and none of them are about the writing quality alone:
- It's personal. An attacker can feed your website, your team's LinkedIn profiles or a press release into an AI tool and get back a message with the right names, the right job titles and a plausible reason to be in touch.
- It's fast to produce. What used to take a scammer real time to draft now takes seconds, in whatever tone they ask for, which means more attempts land, more often.
- It's arriving at real scale. Phishing is already the most common attack UK businesses report: 38% identified a phishing attempt in the past year, more than any other kind of attack, according to the government's latest Cyber Security Breaches Survey. The NCSC's own Takedown Service removed 1.2 million phishing campaigns last year alone, over half of them within an hour of being spotted, and that's still only the ones caught.
Instead of an obvious "your account is suspended" message, someone in finance now gets an email that looks like it's from a supplier they actually deal with, mentions a real project, and asks for the bank details on the next invoice to be updated. It reads exactly like the real thing. The only thing wrong with it is who actually sent it.
When it goes beyond email
The same trick works on phone and video calls, and the most striking example so far isn't a small business. In 2024, the engineering firm Arup lost HK$200 million (about $25.6 million) after a finance employee in its Hong Kong office joined a video call to authorise a series of transfers. Every other person on that call, including someone who looked and sounded exactly like the firm's CFO, was an AI-generated deepfake.
Few businesses will ever face an attack that sophisticated. The lesson underneath it applies at any size: if a request to move money or change payment details arrives out of the ordinary channel, however convincing it looks or sounds, verify it a different way before acting on it.
Your spam filter is still doing its job, and it still isn't the whole answer
Keep your email security switched on. It genuinely blocks a lot. But a well-written, personalised email that asks a normal-sounding question and carries no obvious bad link or attachment doesn't always trip a filter's alarms. The signs that matter most now are about the request, not the writing, which is exactly why a trained person still has to be the last line of defence.
The signs that still work
None of these depend on how well the email is written:
- It asks for money, gift cards or a payment to a new account.
- It asks for a password, a verification code or other login details.
- It creates pressure: a deadline, a threat, or "act now."
- It asks to change the bank details on an invoice or a supplier record.
- It comes with a link or attachment nobody was expecting.
- The display name looks right, but the address behind it doesn't match. Checking the full address rather than the display name is the same habit that catches a spoofed sender address, and it still works whether the email was written by a person or a machine.
Every one of those is about what the email is asking for, not how it's phrased. That's the rule worth teaching a team: when a message touches money, logins, or how you pay someone, slow down before acting on it.
Building this into how your team works
- Verify money and login requests a different way. If an email asks for a payment to a new account or a change to bank details, call the person on a number you already have. Don't reply to the email, and don't use a number the email itself provides.
- Retire the spelling check as the main lesson. Replace it with "what is this asking me to do?" as the question staff actually check for.
- Set one firm rule for payment changes. Every change to bank details gets confirmed by phone, no exceptions, even when it's marked urgent.
- Turn on phishing-resistant multi-factor authentication or passkeys, so a password caught by a scam is far harder to actually use.
- Make reporting easy and blame-free. A suspicious email can be forwarded straight to the NCSC's Suspicious Email Reporting Service at report@phishing.gov.uk, and a suspicious text to 7726, both free. Nobody should feel silly for checking.
- Revisit it now and then. A five-minute reminder that scam emails look perfect these days beats a poster nobody reads.
This is exactly the kind of everyday threat our cyber security & compliance work is built to catch, the technical filtering and the staff-awareness side together, rather than something left until someone almost pays the wrong invoice. It's also worth reading what happens when a convincing phishing email is the one that gets through, since that's still the way most serious incidents start. If you'd like us to look at where your business currently stands, book a call with our team and we'll take it from there.
Frequently Asked Questions
Can you still spot a phishing email by bad spelling and grammar?
Not reliably. Attackers use AI to write clean, correctly spelled emails now, so a message with perfect grammar can still be a scam. Judge it by what it's asking you to do instead.
What are the warning signs that still work?
The request itself: a payment, a change to bank details, a login or code, or pressure to act immediately. Those signs don't depend on how well the email reads.
Is AI-generated phishing actually a bigger problem, or just more talked about?
It's a real shift, not just a talking point. The NCSC has directly warned that generative AI removes the spelling and grammar mistakes that used to reveal phishing, and phishing is already the single most common attack UK businesses report, at 38% in the government's latest Cyber Security Breaches Survey.
Will my spam filter stop AI-written phishing?
It will catch a lot, and it's worth keeping switched on. A well-written, personalised email with no obvious bad link can still slip past a filter, though, so don't rely on it as your only defence. A trained, alert person is still the backstop.
What should staff do if they're not sure about a message?
Slow down and check through a channel they already trust, such as calling a known number or asking the person directly, rather than replying to the email or using contact details it provides. Report it too, even if it turns out to be genuine.
How do I report a phishing email in the UK?
Forward it to the NCSC's Suspicious Email Reporting Service at report@phishing.gov.uk, and forward a suspicious text to 7726, both free. If money has already been sent, report it to Report Fraud, the UK's national fraud and cybercrime reporting service, as well.
Written by
Jack Wetson-CattJack co-founded Atema in 2017 and leads the team day to day, bringing years of IT experience across telecoms, finance and legal to how Atema supports its own clients.
