A few months ago, one of our clients forwarded me an email they had received. It looked like it came from their bank. The logo was right, the formatting was clean, and it said there was "unusual activity" on their account. There was a big blue button that said "Verify Your Identity."
They almost clicked it. The only reason they didn't was because something felt slightly off about the sender's email address. That gut feeling saved them from handing their banking credentials to a scammer.
Here's the thing: you shouldn't have to rely on gut feelings to catch phishing emails. You need a system. And the best one I've found in over 17 years of IT services work in Lawrenceville, GA is the SLAM method.
It's simple, it's fast, and it works. Let me walk you through it.
What Is the SLAM Method?
SLAM is an acronym that stands for Sender, Links, Attachments, and Message. It's a four-step mental checklist you run through every time you get an email that asks you to do something -- click a link, open a file, send money, share login credentials, or take urgent action.
The idea is straightforward: before you react to any email, you check these four things. If any one of them looks wrong, you stop and verify through a different channel (like calling the person who supposedly sent it).
According to CISA (the Cybersecurity and Infrastructure Security Agency), over 90% of successful cyberattacks start with a phishing email. That stat has held steady for years. Phishing works because it targets people, not technology. And SLAM gives your people a quick, repeatable way to fight back.
Let's break down each letter.
S -- Check the Sender
This is your first line of defense. Before you read the body of the email, look at who sent it.
And I don't mean glance at the display name. I mean actually look at the full email address. Phishing emails almost always use addresses that look close to legitimate ones but aren't quite right. Here's what to watch for:
- Misspelled domains:
support@micros0ft.cominstead ofsupport@microsoft.com(that's a zero, not the letter O) - Extra words in the domain:
billing@paypal-secure-login.cominstead ofbilling@paypal.com - Completely wrong domains: An email claiming to be from your bank but sent from
alerts@random-domain.xyz - Free email services: A "vendor" emailing you from a Gmail or Yahoo address instead of their company domain
On your phone, the full email address is often hidden behind the display name. Tap on the sender's name to reveal the actual address. That extra second can save you a lot of trouble.
One more thing: just because an email address looks legitimate doesn't guarantee it's safe. Attackers can spoof sender addresses or compromise real accounts. That's why SLAM has three more steps.
L -- Hover Over the Links
Phishing emails almost always include a link they want you to click. It might say "Reset Your Password" or "View Invoice" or "Confirm Your Account." The text on the button looks normal, but the actual URL it points to is something completely different.
The rule is simple: hover before you click. On a computer, move your mouse over the link without clicking. A small preview will pop up (usually in the bottom-left corner of your browser or email client) showing you the real URL. On a phone, press and hold the link to see where it actually goes.
Here's what to look for:
- Mismatched URLs: The button says "Login to Microsoft 365" but the link goes to
http://m1crosoft-login.sketchy-site.com/auth - HTTP instead of HTTPS: Legitimate login pages use HTTPS. If the link starts with plain HTTP, that's a red flag
- Weird domain structures: The real domain is what comes right before the first slash.
microsoft.com.evil-site.com/loginis NOT a Microsoft site -- the actual domain there isevil-site.com - Shortened URLs: Links using bit.ly, tinyurl, or other shorteners in a business email are suspicious. Legitimate companies link directly to their own domains
If you're not sure about a link, don't click it. Open your browser and go directly to the company's website by typing the address yourself. If there's really an issue with your account, you'll see it when you log in the normal way.
A -- Question the Attachments
Attachments are one of the most common ways malware gets delivered. An email shows up with a "invoice," "shipping label," or "contract" attached, and the moment you open it, malicious code runs on your computer.
Ask yourself these questions before opening any attachment:
- Was I expecting this? If you didn't ask for a document, be suspicious. Even if it appears to come from someone you know, their account may have been compromised
- Does the file type make sense? An invoice should be a PDF, not a
.exe,.zip, or.jsfile. Be especially wary of files ending in.exe,.scr,.bat,.js, or.vbs - Is it a macro-enabled Office file? Files like
.xlsmor.docmcontain macros that can execute code. If a "vendor" sends you a spreadsheet that asks you to "Enable Content" or "Enable Macros," that's a major warning sign - Is it password-protected? Attackers sometimes send password-protected ZIP files specifically to bypass your email security filters. The password is conveniently included in the email body. Legitimate businesses rarely do this
When in doubt, don't open the attachment. Call or message the sender using contact information you already have (not the phone number in the suspicious email) and ask if they actually sent it.
M -- Read the Message Carefully
This is where you evaluate the actual content of the email. Phishing messages rely on emotion -- urgency, fear, curiosity, or greed -- to get you to act before you think.
Watch for these common tactics:
- Urgency and threats: "Your account will be suspended in 24 hours" or "Immediate action required." Legitimate companies don't threaten you into clicking links within minutes
- Too-good-to-be-true offers: "You've been selected for a $500 gift card" or "Claim your tax refund now." If it sounds too good to be true, it is
- Vague greetings: "Dear Customer" or "Dear User" instead of your actual name. Your bank knows your name
- Grammar and spelling issues: While phishing emails have gotten much better, many still have awkward phrasing, odd formatting, or small spelling mistakes
- Requests for sensitive information: No legitimate company will ask you to email your password, Social Security number, or credit card details. Ever
- Mismatched context: You get a "shipping notification" from UPS but you haven't ordered anything. You get a "password reset" email but you didn't request one
The key question to ask yourself: Does this email make sense in the context of my normal business? If the answer is no, or even "I'm not sure," verify it before you do anything.
Real-World Phishing Examples (Broken Down With SLAM)
Let me walk you through three phishing emails we've seen in the wild and show you how SLAM catches each one.
Example 1: The Fake Microsoft 365 Alert
The email says your Microsoft 365 password expires today and you need to click a link to keep your account active. It has the Microsoft logo, clean formatting, and a blue "Update Password" button.
- S (Sender): The from address is
no-reply@microsoft-365-security.net. Microsoft's real emails come from@microsoft.comor@accountprotection.microsoft.com. Fail. - L (Links): Hovering over the button reveals
http://ms365-pw-update.ru/login. That's a Russian domain, not Microsoft. Fail. - A (Attachments): No attachments. Pass (but irrelevant since it already failed two checks).
- M (Message): "Your password expires TODAY. Update immediately or lose access." Classic urgency tactic. Microsoft doesn't email you with same-day deadlines like this. Fail.
Verdict: Phishing. Delete it.
Example 2: The Vendor Invoice Scam
An email arrives from what looks like one of your regular vendors. It says "Please find attached Invoice #4892 for services rendered" and has a ZIP file attached.
- S (Sender): The address is
accounting@vendors-billing.cominstead of the vendor's actual domain. Close, but not right. Fail. - L (Links): No links in the body, just the attachment. Pass.
- A (Attachments): A
.zipfile namedInvoice-4892.zip. Your vendor normally sends PDFs. A ZIP file for an invoice is unusual and suspicious. Fail. - M (Message): The email is short and generic. It doesn't reference your company name, a specific project, or any details your real vendor would know. Fail.
Verdict: Phishing. Call your vendor directly (using the number you have on file, not any number in this email) to confirm.
Example 3: The CEO Wire Transfer Request
You get an email that appears to come from your company's owner or CEO. It says they need you to process an urgent wire transfer for a "confidential acquisition" and to keep it quiet until the deal closes.
- S (Sender): The display name shows your CEO's name, but the actual email address is
ceo.firstname.lastname@gmail.cominstead of their company email. Fail. - L (Links): No links. Pass.
- A (Attachments): No attachments. Pass.
- M (Message): The message asks for an urgent wire transfer and specifically says to keep it confidential. This is textbook Business Email Compromise (BEC). The FBI's Internet Crime Complaint Center (IC3) reports that BEC is consistently one of the costliest forms of cybercrime, with billions in losses annually. Fail.
Verdict: Phishing (BEC attack). Walk over to your CEO's office or call their direct line to verify. Never process urgent financial requests based solely on an email.
Think Your Business Email Is Safe?
Credential stuffing attacks use stolen emails from past breaches. Our free dark web scan tells you in seconds if yours has been compromised.
Run a Free Dark Web ScanWant to Phishing-Proof Your Business?
We help small businesses set up email security, train their teams, and build a layered defense against phishing attacks. Our discovery call is free and no-pressure.
Book a Discovery CallSLAM Quick-Reference Checklist
Print this out and keep it near your workstation. Share it with your team. Run through it every time an email asks you to click, open, or respond to something.
S -- Sender
- Did I check the full email address (not just the display name)?
- Does the domain match the company this email claims to be from?
- Are there misspellings, extra words, or unusual characters in the domain?
L -- Links
- Did I hover over every link before clicking?
- Does the URL match the company's real website?
- Is it HTTPS (not plain HTTP)?
- Are there shortened URLs or suspicious redirects?
A -- Attachments
- Was I expecting this attachment?
- Does the file type make sense (PDF for invoices, not .exe or .zip)?
- Is it asking me to enable macros or content?
M -- Message
- Is the email creating urgency or fear?
- Does it use a generic greeting instead of my name?
- Is it asking me to share sensitive information or make a payment?
- Does this request make sense in the context of my normal work?
If any answer raises a red flag: STOP. Don't click, don't open, don't reply. Verify the email through a separate channel -- call the sender, visit the website directly, or ask your IT team.
SLAM Is Step One, Not the Whole Plan
Teaching your team the SLAM method is one of the best things you can do for your business's cybersecurity. It's especially effective against the 8 most common types of phishing attacks targeting businesses today. But it's one layer of defense. Even the most careful person can have a bad day, get distracted, and click something they shouldn't. And remember, phishing often starts offline -- attackers use dumpster diving to gather intel that makes their phishing emails more convincing.
That's why you need technical safeguards backing up your human defenses:
- Multi-factor authentication (MFA) on every account, so a stolen password alone isn't enough to get in
- Email filtering and anti-phishing tools that catch malicious messages before they reach inboxes
- Endpoint protection on every device to block malware if someone does click the wrong thing
- Regular security awareness training to keep SLAM top of mind (not just a one-time thing)
- Phishing simulations to test your team's readiness in a safe environment
- DNS filtering to block known malicious websites even if someone clicks a bad link
According to KnowBe4, organizations that run regular security awareness training and phishing simulations see phishing click rates drop from around 30% to under 5% within a year. That's a massive improvement.
At NGT Technology, we handle all of this as part of our managed cybersecurity services. We set up the email filtering, deploy the endpoint protection, run the phishing simulations, and train your team -- so you can focus on running your business instead of worrying about the next phishing email.
If you want to see where your business stands right now, give us a call at (404) 990-4540 or book a free discovery call. We'll take a look at your current setup and give you a clear, honest picture of what's working and what needs attention. No sales pitch, no pressure.
In the meantime, share the SLAM method with your team today. It takes five minutes to explain and it could prevent the next phishing attack from landing.