Why first contact emails carry higher risk
Most legitimate business relationships build over time. A completely new sender — one your mail system has never seen before — has no track record. That is not automatically suspicious, but it does mean there is no basis yet for trust.
No prior relationship
You have no history with this sender, so you cannot verify their identity based on past interaction.
Attackers exploit new contact
Fraudsters deliberately reach out cold, knowing recipients are less likely to have context to judge the message.
Links and attachments are untested
Any link or file from a new sender has not been seen before. It could be entirely safe — or a gateway to malware.
Display names can be faked
An email can say it is from "Microsoft Support" or "Your Bank" while actually originating from a completely different domain.
Three things to do before acting on a first contact email
These three checks take less than two minutes and significantly reduce your risk of being caught out.
Check the real sender address
Do not trust the display name. Hover over or tap the sender name to reveal the actual email address. Does the domain match who they claim to be?
Consider whether it makes sense
Were you expecting to hear from someone like this? Does the message make sense in context? Unexpected requests — especially involving links, files, or information — deserve more scrutiny.
Verify independently if in doubt
If the email asks you to do something — click a link, open a file, make a payment, share information — look up the sender independently before acting. Search their company or contact them through their official website.
Red flags in first contact emails
These are the most common warning signs that a first contact email may not be what it appears to be.
Asks you to click a link or open an attachment immediately High risk
Legitimate first contact rarely requires you to open a file straight away. Malicious attachments and links are among the most common ways attackers gain access to systems.
Creates urgency or pressure to act quickly High risk
"Your account will be closed", "respond within 24 hours", "urgent action required" — these phrases are designed to bypass your judgement. Genuine organisations give you time to verify.
Requests personal, financial, or login information High risk
No legitimate new contact should ask for credentials, bank details, or sensitive information before any relationship has been established.
Display name does not match the actual email domain Check carefully
The email says it is from "HMRC" or "NatWest" but the actual address is a random Gmail or unusual domain. This is a near-certain sign of impersonation.
Vague or generic content with no specific context Check carefully
"Dear Customer", "I found your details online", "We have a business opportunity for you" — mass-sent phishing emails rarely contain specifics because they are not targeted at you personally.
Poor spelling, grammar, or unusual formatting Check carefully
While not always present, deliberate errors or oddly formatted emails can be a sign that the sender is not who they claim to be — or is based outside the country they are impersonating.
What a suspicious first contact email looks like
Here is an example of the kind of first contact message that should prompt extra caution before any action is taken.
Dear Business Owner,
Our records indicate that your company has an outstanding filing requirement. Failure to complete this within 7 days may result in a penalty or your company being struck off the register.
Please click the link below to review the notice and complete the required action immediately.
View your notice and respond →
Companies House Compliance Team
What to do when you receive a first contact email
Follow these steps any time you receive a message from a sender you do not recognise and cannot immediately verify.
Pause before clicking anything
Read the email fully before interacting with any link or attachment. Most harm from phishing happens in the moment of clicking — pausing gives you time to assess.
Check the actual sender domain
Hover over or tap the sender name to reveal the full email address. Search the domain if it is unfamiliar. Impersonators often use domains that look almost right — look for extra words, hyphens, or different TLDs (.net, .org instead of .gov.uk).
If it claims to be from a known organisation, verify independently
Go directly to the organisation's official website (type the address in your browser — do not click the link in the email) and check whether the contact or notification is genuine.
Do not open attachments from unknown senders without caution
If you are not expecting a file from this person and cannot verify who they are, do not open the attachment. Contact your IT team if unsure — they can scan or review it safely.
Report it if it looks suspicious
Forward suspicious emails to your IT team. In the UK, you can also report phishing emails to the National Cyber Security Centre at report@phishing.gov.uk. If you are a managed customer, call us on 0345 450 9666.
Dos and don'ts for unknown senders
- Check the full email address, not just the display name
- Verify the sender independently via their official website or phone number
- Hover over links to check where they lead before clicking
- Ask your IT team before opening unexpected attachments
- Report suspicious emails to IT and to report@phishing.gov.uk
- Trust a display name without checking the actual email address
- Click links or open attachments under time pressure without checking
- Provide personal, financial, or login details to an unverified sender
- Assume an email is safe because it looks professionally written
- Let urgency rush you — take the time to verify first
