Unknown Sender Caution | The Cloud Network
First Contact Alert

You have received a message from an unknown sender

This may be the first time your organisation has received a message from this address. That does not mean it is harmful — but it does mean you should take a moment before clicking, replying, or acting on anything it contains.

Caution: Many cyberattacks begin with a first contact email designed to appear routine — a delivery notification, an invoice, a job enquiry, or a request for information. Read this page before taking any action.

Why first contact emails carry higher risk

Most legitimate business relationships build over time. A completely new sender — one your mail system has never seen before — has no track record. That is not automatically suspicious, but it does mean there is no basis yet for trust.

No prior relationship

You have no history with this sender, so you cannot verify their identity based on past interaction.

Attackers exploit new contact

Fraudsters deliberately reach out cold, knowing recipients are less likely to have context to judge the message.

Links and attachments are untested

Any link or file from a new sender has not been seen before. It could be entirely safe — or a gateway to malware.

Display names can be faked

An email can say it is from "Microsoft Support" or "Your Bank" while actually originating from a completely different domain.

Being cautious is not the same as ignoring the email. Many first contact emails are completely legitimate — new suppliers, potential clients, job applicants. Caution simply means pausing to verify before you act, not deleting everything from an unknown address.

Three things to do before acting on a first contact email

These three checks take less than two minutes and significantly reduce your risk of being caught out.

01

Check the real sender address

Do not trust the display name. Hover over or tap the sender name to reveal the actual email address. Does the domain match who they claim to be?

02

Consider whether it makes sense

Were you expecting to hear from someone like this? Does the message make sense in context? Unexpected requests — especially involving links, files, or information — deserve more scrutiny.

03

Verify independently if in doubt

If the email asks you to do something — click a link, open a file, make a payment, share information — look up the sender independently before acting. Search their company or contact them through their official website.

Red flags in first contact emails

These are the most common warning signs that a first contact email may not be what it appears to be.

Asks you to click a link or open an attachment immediately High risk

Legitimate first contact rarely requires you to open a file straight away. Malicious attachments and links are among the most common ways attackers gain access to systems.

Creates urgency or pressure to act quickly High risk

"Your account will be closed", "respond within 24 hours", "urgent action required" — these phrases are designed to bypass your judgement. Genuine organisations give you time to verify.

Requests personal, financial, or login information High risk

No legitimate new contact should ask for credentials, bank details, or sensitive information before any relationship has been established.

Display name does not match the actual email domain Check carefully

The email says it is from "HMRC" or "NatWest" but the actual address is a random Gmail or unusual domain. This is a near-certain sign of impersonation.

Vague or generic content with no specific context Check carefully

"Dear Customer", "I found your details online", "We have a business opportunity for you" — mass-sent phishing emails rarely contain specifics because they are not targeted at you personally.

Poor spelling, grammar, or unusual formatting Check carefully

While not always present, deliberate errors or oddly formatted emails can be a sign that the sender is not who they claim to be — or is based outside the country they are impersonating.

What a suspicious first contact email looks like

Here is an example of the kind of first contact message that should prompt extra caution before any action is taken.

What to do when you receive a first contact email

Follow these steps any time you receive a message from a sender you do not recognise and cannot immediately verify.

1

Pause before clicking anything

Read the email fully before interacting with any link or attachment. Most harm from phishing happens in the moment of clicking — pausing gives you time to assess.

2

Check the actual sender domain

Hover over or tap the sender name to reveal the full email address. Search the domain if it is unfamiliar. Impersonators often use domains that look almost right — look for extra words, hyphens, or different TLDs (.net, .org instead of .gov.uk).

3

If it claims to be from a known organisation, verify independently

Go directly to the organisation's official website (type the address in your browser — do not click the link in the email) and check whether the contact or notification is genuine.

4

Do not open attachments from unknown senders without caution

If you are not expecting a file from this person and cannot verify who they are, do not open the attachment. Contact your IT team if unsure — they can scan or review it safely.

5

Report it if it looks suspicious

Forward suspicious emails to your IT team. In the UK, you can also report phishing emails to the National Cyber Security Centre at report@phishing.gov.uk. If you are a managed customer, call us on 0345 450 9666.

Most first contact emails are harmless. The goal is not to make you distrust every new email — it is to give you a moment to check before you act. A brief pause is all it takes to avoid the vast majority of attacks that start this way.

Dos and don'ts for unknown senders

✓ Do this
  • Check the full email address, not just the display name
  • Verify the sender independently via their official website or phone number
  • Hover over links to check where they lead before clicking
  • Ask your IT team before opening unexpected attachments
  • Report suspicious emails to IT and to report@phishing.gov.uk
✗ Never do this
  • Trust a display name without checking the actual email address
  • Click links or open attachments under time pressure without checking
  • Provide personal, financial, or login details to an unverified sender
  • Assume an email is safe because it looks professionally written
  • Let urgency rush you — take the time to verify first

Need help or have a concern?

Our team is available to advise on any security concerns, investigate suspicious activity, or help you improve your organisation's security posture.

Please use our contact details below to get in touch