A practical way to spot phishing emails before you act
Check unexpected messages, verify requests through a separate route and respond safely if you already clicked a link or shared a password.
An email can have a familiar logo, polished writing and your real name, yet still send you to the wrong place. The most useful question is not whether it looks professional. It is whether the action it asks you to take makes sense and can be verified somewhere other than the message itself.
A delivery fee, an expired password, a university document request and a shared file can all be legitimate. They can also create just enough urgency to make someone stop checking. Build a small pause into those moments.
This guide is for messages in accounts you own or manage. For work or school email, follow your organization's reporting process before deleting evidence or investigating the message yourself.
Read the requested action before inspecting the design
Identify what the sender wants: a payment, a password, a code, an attachment opened, a new app installed or a document uploaded. Write the request in one plain sentence if the message is confusing.
Then compare it with what you were already doing. Were you expecting a parcel from this company? Did you start a password reset? Has the university previously used this portal? Context does not prove legitimacy, but a request disconnected from your activity deserves extra care.
The FTC's phishing guide describes messages that impersonate organizations and push people to disclose information. The practical response is to step outside the email and contact the organization through a route you already trust.
Do not use the phone number printed inside the suspicious message as your independent check. That number is part of the same unverified claim.
Verify the destination, not just the display name
Expand the sender details. A display name such as “Account Support” can be chosen separately from the address behind it. Look for unexpected domains and a reply address that differs from the apparent sender.
On a computer, hovering over a link may show the destination. On a phone, a long press may offer a preview or copy option, but avoid opening the link simply to investigate it. Interface behavior varies, so use the safer route of navigating independently when uncertain.
Read the actual hostname rather than searching the whole address for a brand name. In accounts.example.com, the example domain is the relevant base. In example.com.unrelated.test, the apparent brand is only part of a different hostname.
A secure connection symbol does not establish that the business is genuine. It answers a connection question, not an identity or honesty question. Microsoft's phishing guidance explains common warning signs, including urgent requests and mismatched links.
Use a separate route for important requests
Open your saved bookmark, type the known service address or use its official app. Check the account's notification area, order list or document portal for the same request.
For a person you know, call a number already in your contacts. Ask about the specific request without supplying the answer you expect. “Did you send me a file today?” is more useful than “This urgent invoice is yours, right?”
For admissions, employment or travel paperwork, use the contact route published on the institution's own website. The application-document guide explains how to check a document request before sending identity scans.
If no independent route confirms the request, leave it unresolved rather than acting merely to clear the inbox. A genuine organization should have a way to explain what it needs.
Keep one-time codes out of conversations
A verification code belongs in the sign-in or recovery process you intentionally started. Do not read it to someone who contacted you, paste it into a support chat or send a screenshot containing it.
The same principle applies to approval prompts. Denying an unexpected prompt is safer than approving it because a caller claims the approval will cancel a problem.
A password manager can help you notice an unfamiliar login destination when it does not offer the expected entry. Treat that as a reason to verify, not as a reason to manually paste the password into any page that asks. See setting up a password manager for a workable approach.
No single warning sign catches every phishing message. Your independent route is more dependable than a mental checklist of spelling mistakes.
Handle attachments without turning the check into an experiment
Do not open an unexpected attachment just to see whether it is harmless. Ask the sender through a known channel and request a clear description of what they sent.
Be particularly cautious when a document asks you to enable extra content, install a viewer or disable a security feature. A routine invoice or application form should have an understandable delivery process.
Avoid uploading private attachments to random scanning services. An attachment can contain real confidential information even when you are suspicious of its source. A work security team may have an approved analysis route; use that rather than creating a new public copy.
For a legitimate sensitive document, the safer file-sharing workflow is the better next step.
Respond according to what actually happened
If you only opened the message, stop interacting and report it through your mail app. Do not assume that opening a message automatically means every account is compromised.
If you followed a link but entered nothing, close it and review whether anything downloaded or any permissions were granted. If you entered a password, visit the real service independently, change that password and replace it anywhere else it was reused.
If you approved a sign-in or disclosed a code, review active account sessions and recovery settings. If you installed software or opened suspicious active content, use your device's security tools or your organization's support team rather than continuing sensitive work on the device.
For payment information or an actual transfer, contact the relevant provider through its verified fraud channel promptly. Preserve the details needed for its investigation, but do not forward passwords or codes as evidence.
Keep a simple reporting habit
Use the mail provider's phishing or spam reporting option. For workplace messages, use the approved reporting button or address. A screenshot may omit technical details, so follow the team's instructions about forwarding the original message.
Do not reply to the suspicious sender to announce that you caught the scam. Do not publish the complete message with private names, addresses or access links visible.
After reporting, make one useful improvement if needed: update a reused password, remove an unfamiliar session or bookmark the real service. The Privacy / Security directory contains further resources, but the everyday habit is simpler: pause, leave the message, verify the request, then act.
Sources and further reading
- FTC: How to recognize and avoid phishing scams Consulted 28 September 2026.
- Microsoft Support: Protect yourself from phishing Consulted 28 September 2026.
Consult the linked documentation for current details. Settings, availability and interface labels may change.
Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.