READ: The ‘GAUGES’ Method of Spotting a Phish
Employees play a crucial role in protecting sensitive company and customer data from potential cyber threats. Use the OrbitalFire ‘GAUGES’ method to detect phishing and social engineering scams:
GRAMMAR
- Is the grammar, spelling, or punctuation suspicious?
- Does the email contain errors?
- Is it formatted normally?
ATTACHMENTS AND LINKS
- Is there an attachment or link?
- Do you recognize the attachment file type?
- Do you regularly use these types of documents?
- Is the link hidden behind a text label?
- Does the domain in the link look familiar?
- Does the link label match the domain?
URGENCY
- Is the sender demanding that you respond or provide information immediately?
- Does the email feel threatening?
- Are these types of urgent requests normal for your role?
GENERIC
- Is the email addressed to “Sir”, or “User” or another generic label?
- Does it feel like it’s a mass email?
EXTERNAL SENDER
- Is the sender someone outside your organization?
- Do you recognize the sender and their organization?
SENDER’S EMAIL ADDRESS
- Does the sender look legitimate?
- Does the sender’s email contain odd characters?
- Does it match the displayed name?
For more information on training your team to help protect against cyber crime, watch our webinar ‘Beyond Awareness Training: Advanced Tips for Securing Your Humans’, and more on our YouTube Channel.
Want a shareable copy of this tip to use in your organization? Or need help creating a ‘Culture of Security’ in your organization through a strong cybersecurity strategy? We’re Here for You.
Frequently Asked Questions About Phishing Detection
What is the GAUGES method for detecting phishing?
GAUGES is OrbitalFire’s framework for spotting phishing emails and social engineering scams. Each letter stands for a key signal to check: Grammar (errors, unusual formatting), Attachments and Links (suspicious file types, hidden links), Urgency (pressure to respond immediately), Generic (mass-email feel, non-personalized greeting), External Sender (unfamiliar sender or organization), and Sender’s Email Address (mismatched or odd characters). Checking all six before acting on an email significantly reduces the chance of falling for a phish.
What is the most common sign of a phishing email?
Urgency is one of the most reliable red flags. Phishing emails are designed to make you act before you think: threats of account suspension, payment deadlines, or requests that “require immediate action” are all pressure tactics. When something feels urgent, that’s exactly when to slow down and check the other GAUGES signals before clicking or responding.
Can phishing emails have perfect grammar now?
Yes. AI tools have made it easy for attackers to write phishing emails with flawless spelling and grammar. That’s why Grammar is one signal in GAUGES, not the only one. A well-written email can still fail the other checks: the sender’s address may not match, the link domain may look off, or the urgency level may be unusual for that sender. Always run through all six signals, not just the ones that seem obvious.
How do I check if a link in an email is safe?
Hover over the link (without clicking) to see the actual destination URL. Check whether the domain looks familiar and matches the organization sending the email. Be especially cautious of links where the visible label doesn’t match the destination, shortened URLs, and domains with subtle misspellings (e.g., “paypa1.com” instead of “paypal.com”). When in doubt, navigate to the site directly in your browser instead of using the link.
What should I do if I think I received a phishing email?
Don’t click any links or open attachments. Report it to your IT or security contact using your organization’s established process. If you’re not sure whether to report, report anyway: a false alarm is always better than a missed threat. If you accidentally clicked a link or entered credentials, notify your IT or security team immediately so they can assess and contain any damage.



