Phishing is the most reported type of cybercrime in the US. The FBI’s Internet Crime Complaint Center logged 193,407 phishing and spoofing complaints in 2024, more than any other category.
We know it firsthand: Abusix has been targeted by whaling attacks ourselves. If you run mail for an ISP, hosting provider, telecom, or business, this guide explains how phishing works, how spear phishing differs from mass phishing, and how to stop both before they reach your users.
Phishing vs spear phishing vs whaling
| Phishing | Spear phishing | Whaling | |
|---|---|---|---|
| Target | Anyone, in bulk | A specific person or team | Senior executives |
| Message | Generic, sent to thousands | Personalized with researched details | Highly tailored, often about money or legal issues |
| Typical goal | Passwords, card details, malware | Access to systems or data | Large payments or confidential information |
| Hardest part to filter | Volume and changing infrastructure | Each message is unique | Often no links or attachments at all |
Phishing casts a wide net. Messages impersonate banks, delivery companies or popular services, create urgency (“your account will be suspended in 24 hours”) and push the recipient to a fake login page or a malicious attachment.
Spear phishing targets a specific person. Attackers research their victim on LinkedIn, social media and company websites, then use real names, projects and colleagues to make the message believable. Anyone who controls something valuable is a target: finance staff, account managers and IT administrators as well as executives.
Whaling is spear phishing aimed at the top. A typical whaling email impersonates the CEO or a trusted partner and asks for an urgent payment, or claims a legal problem that needs “clearing up” quietly. Because each message is unique and often contains no link, it can pass straight through filters that look for known bad content.
Advanced Phishing Techniques

Related attacks: smishing, vishing, and pharming
Phishing doesn’t only arrive by email. Smishing uses text messages, vishing uses phone calls, and pharming redirects users to a fake site even when they type the right address, for example, through DNS tampering. Attackers often combine channels, such as an email followed by a “confirmation” call. Learn how phishing and pharming differ here.
How to spot a phishing email
- Mismatched sender: the display name says one thing, the actual address or domain another.
- Lookalike domains: small changes such as a zero for an “o” or an extra word in the domain.
- Urgency or threats: deadlines, account suspensions, legal action or unusual secrecy.
- Unexpected requests: payments, bank detail changes, password resets or gift cards.
- Suspicious links: the visible text doesn’t match the real destination, or the link uses a URL shortener.
- Risky attachments: unexpected invoices, password-protected archives or files that ask you to enable macros.
AI-written phishing now has fewer spelling mistakes, so language errors are no longer a reliable sign. Focus on the request and the sender, not the grammar.
Common Characteristics of Phishing Emails

How phishing gets past filters
- Fresh infrastructure: newly registered domains and new IP addresses with no bad history yet.
- Snowshoe sending: spreading a campaign thinly across many IP addresses and domains so no single source looks suspicious.
- Compromised accounts: sending from real, trusted mailboxes that pass authentication.
- Hidden destinations: links behind shorteners, redirects or trusted file-sharing services.
- No payload at all: whaling and business email compromise messages that only ask for an action.
Phishing Detection Mechanisms

Technical defenses that stop phishing
1. Reject known bad sources at the connection
Real-time blocklists stop phishing from known bots, infected hosts, and abused infrastructure before the message is delivered. Add newly observed domain and IP lists to catch fresh infrastructure early. See how each Abusix blocklist works.
2. Enforce sender authentication
SPF, DKIM and DMARC stop exact-domain spoofing. Publish strict DMARC policies for your own domains, and act on DMARC failures for inbound mail. Read our guide to SPF, DKIM, DMARC and BIMI.
3. Check every link and domain in the message
Compare domains and URLs, including expanded short links and file-sharing links, against domain and URL blocklists. Flag lookalike domains of your own brand and your users’ common contacts.
4. Scan attachments
Scan attachments for malware, block risky file types, and treat password-protected archives with suspicion. Here’s how to layer spam filtering.
5. Encrypt mail in transit
Use TLS between mail servers so messages can’t be read or altered on the way.
6. Protect accounts
Require two-factor authentication, and check login IP addresses against an authentication blocklist. This limits the damage when a user does hand over their password, and stops attackers from sending phishing from your own accounts. See how to detect compromised accounts.
The human layer: training and reporting
Technology stops most phishing, but some will always get through, especially targeted attacks. Prepare users for the rest:
- Train regularly. Short, frequent sessions work better than an annual course. Cover the red flags above and the specific scams your users see.
- Run phishing simulations. Send realistic test emails and use the results to focus training, not to blame people.
- Make reporting one click. A “Report phishing” button turns every user into an early warning system.
- Verify money requests out of band. Any request to pay or change bank details should be confirmed by phone, using a known number.
- Share alerts. When a campaign is spotted, warn everyone quickly.
Measure progress with a few numbers: simulation click rates, the share of users who report suspicious mail, and how quickly reports arrive after a campaign starts.
When someone clicks
Act fast: reset the password, end active sessions, check the account’s mail rules and sent items, scan the device, and look for the same message in other mailboxes. Here’s a step-by-step guide to what to do after clicking a phishing link.
Stop phishing before it reaches the inbox
The best phishing email is the one your users never see. Abusix Mail (formerly known as Abusix Mail Intelligence) gives your mail servers real-time IP, domain, and URL blocklists, including lists of newly observed domains and IP addresses, so you can reject phishing infrastructure as soon as it appears. See how Abusix Mail works.