Evaluate a suspicious email or text without clicking, replying, or exposing more information.
A phishing message tries to make you act before you verify. It may imitate a person, employer, delivery service, bank, government office, or familiar account. One sign is rarely decisive; the safer approach is to inspect the request, verify through a channel you already trust, and avoid interacting with the message.
Pause the requested action
Do not click, reply, download, call a number in the message, scan its QR code, or approve a sign-in prompt. If the message claims an urgent account problem, open the service through your saved app, bookmark, or manually entered official address.
Inspect the real sender
Expand the sender details. Look for misspelled domains, extra words, unexpected free-mail addresses, altered reply-to fields, and a display name that hides a different address. A real-looking address is not proof by itself; accounts can be compromised.
Evaluate the request
| Request | Why it deserves verification | Safer route |
|---|---|---|
| Password or verification code | Legitimate support should not need your password | Use the known account portal |
| Payment, gift card, or bank change | Irreversible urgency is common in fraud | Confirm with a known contact |
| Unexpected document or invoice | Attachments and sign-in pages can steal access | Ask through a separate channel |
| Approve MFA prompt | Someone may already know the password | Deny, change password, review sessions |
Check links without visiting them
On a computer, hover to view the destination; on mobile, use a safe preview method only if you know how to avoid opening it. Read the registered domain from right to left before the first slash. Shorteners, redirects, and QR codes hide destinations. Even an HTTPS padlock only says the connection is encrypted; it does not prove the site is legitimate.
Treat language as context, not proof
Urgency, secrecy, fear, unusual tone, and an offer that seems too good can raise concern. Perfect grammar does not make a message safe, and mistakes do not make every message malicious. Compare the request with the relationship, normal process, and expected timing.
Apply the same checks beyond email
Phishing also arrives through text messages, social direct messages, collaboration tools, calendar invitations, ads, search results, QR codes, and phone calls. A message can begin in one channel and move you to another. Keep the verification independent: do not trust a phone number, username, or website supplied by the same suspicious conversation.
Verify independently
- Open the official app or bookmarked account page
- Call a number already on your statement or official site
- Contact the person through a saved address or known workplace channel
- Ask whether the specific request and attachment were sent
- Check account notifications and recent sessions directly
Report without forwarding the risk
Use the mail provider's phishing control or your organization's security process. Preserve headers when investigators request them. Do not forward a live attachment or link casually to coworkers. Delete the message after reporting according to policy. CISA's Secure Our World guidance emphasizes recognizing and reporting phishing rather than engaging.
If you already interacted
Disconnect only when instructed by your security process or when active malware is suspected; otherwise preserve access to obtain help. Change the affected account password from a trusted device, revoke sessions, enable or reset MFA, contact the service, review payment and recovery settings, scan or reimage as qualified support advises, and notify the organization whose data may be affected.
Use unique credentials from the password-manager guide and strengthen the account with the two-factor authentication checklist.
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- CISA Secure Our World Official public guidance on recognizing and reporting phishing, strong passwords, multifactor authentication, and updates.