Phishing emails are designed to create enough urgency or trust that you act before checking. A few deliberate checks can prevent many common mistakes.
1. Check the full sender address
Do not rely on the display name. Expand the sender details and compare the actual domain with the organisation you expect.
2. Treat urgency as a warning sign
Messages that threaten account closure, demand immediate payment or claim a prize often try to suppress careful thinking.
3. Inspect links before opening them
On desktop, hover over a link. On mobile, long-press when safe to preview the destination. A familiar-looking button can point somewhere completely different.
4. Do not sign in through an unexpected email
If a message says there is a problem with an account, open the official app or type the known website address yourself instead of following the email link.
5. Be careful with attachments
Unexpected invoices, HTML files, archives and office documents can be risky. Verify with the sender through another channel before opening suspicious attachments.
6. Look for context, not just spelling mistakes
Modern phishing can be well written. Focus on whether the request itself makes sense and whether the sender can be independently verified.
7. Check official guidance
For US readers, the FTC phishing guidance explains common warning signs. The UK National Cyber Security Centre also publishes practical advice.
8. Use multi-factor authentication
MFA does not make phishing impossible, but it can reduce the damage from a stolen password. Prefer phishing-resistant methods when your services support them.
9. If you clicked, act quickly
Change exposed passwords from a trusted device, revoke suspicious sessions, contact the relevant organisation and monitor important accounts.
10. When unsure, verify separately
Use a phone number, app or website you already trust. Do not use contact details supplied only inside the suspicious message.
Fake emails are increasingly difficult to spot by appearance
Grammar and design are weak signals. Modern phishing messages can copy genuine branding and use polished language. Treat the requested action as the main clue: unexpected login, payment, password reset, document, QR code or urgent change of bank details deserves independent verification.
Ten checks before you click
- Expand the sender address. The display name can say anything; inspect the actual domain.
- Compare the domain carefully. Look for extra words, swapped letters or unfamiliar country/domain endings.
- Inspect links. On desktop, hover before clicking; on mobile, use the safest available preview method.
- Ignore urgency. “Act now” is not evidence that the request is genuine.
- Question unexpected attachments. Especially files asking you to enable content, install software or sign in.
- Be cautious with QR codes. A QR code can hide the destination until you scan it.
- Verify payment changes independently. Call a known number, not one supplied in the suspicious email.
- Open the service directly. Use your bookmark or type the known website address rather than following the message link.
- Check context. Was this message expected? Does the request fit the normal process?
- When unsure, stop. A legitimate organisation can usually tolerate independent verification.
What if the email really is from a known company?
A genuine-looking sender is not enough. Accounts can be compromised and legitimate email services can be abused. If the request changes money, credentials or access, verify the request using contact information you already trust.
QR-code phishing
Security authorities have warned about phishing that uses QR codes to move the victim from a protected email environment to a phone browser. Treat a QR code in an unexpected email like any other unknown link. Do not scan it simply because the message claims it is required for MFA, payroll, a delivery or document access.
If you already clicked
If you clicked but entered nothing, close the page and avoid downloading files. If you entered a password, change it from the genuine service and review MFA/session settings. If you approved a payment, installed software or supplied financial information, contact the relevant provider or bank using trusted contact details and follow their incident guidance.
Use authoritative guidance
For UK readers, the National Cyber Security Centre publishes guidance on spotting and reporting scams. The US Federal Trade Commission also advises verifying suspicious requests through contact information you know is genuine.
Bottom line
The safest habit is simple: important requests should survive independent verification. Do not use the email itself as the only source of truth for the sender, link or contact details.
