Digital Safety & Privacy

How to Spot a Phishing Email or Message Before You Click

Inspect identity, link destinations, requests, urgency, attachments, and account context, then report suspicious messages through a trusted channel.

What this guide helps you do

Evaluate a suspicious email or text without clicking, replying, or exposing more information.

A phishing message tries to make you act before you verify. It may imitate a person, employer, delivery service, bank, government office, or familiar account. One sign is rarely decisive; the safer approach is to inspect the request, verify through a channel you already trust, and avoid interacting with the message.

Pause the requested action

Do not click, reply, download, call a number in the message, scan its QR code, or approve a sign-in prompt. If the message claims an urgent account problem, open the service through your saved app, bookmark, or manually entered official address.

Inspect the real sender

Expand the sender details. Look for misspelled domains, extra words, unexpected free-mail addresses, altered reply-to fields, and a display name that hides a different address. A real-looking address is not proof by itself; accounts can be compromised.

Evaluate the request

RequestWhy it deserves verificationSafer route
Password or verification codeLegitimate support should not need your passwordUse the known account portal
Payment, gift card, or bank changeIrreversible urgency is common in fraudConfirm with a known contact
Unexpected document or invoiceAttachments and sign-in pages can steal accessAsk through a separate channel
Approve MFA promptSomeone may already know the passwordDeny, change password, review sessions

On a computer, hover to view the destination; on mobile, use a safe preview method only if you know how to avoid opening it. Read the registered domain from right to left before the first slash. Shorteners, redirects, and QR codes hide destinations. Even an HTTPS padlock only says the connection is encrypted; it does not prove the site is legitimate.

Treat language as context, not proof

Urgency, secrecy, fear, unusual tone, and an offer that seems too good can raise concern. Perfect grammar does not make a message safe, and mistakes do not make every message malicious. Compare the request with the relationship, normal process, and expected timing.

Apply the same checks beyond email

Phishing also arrives through text messages, social direct messages, collaboration tools, calendar invitations, ads, search results, QR codes, and phone calls. A message can begin in one channel and move you to another. Keep the verification independent: do not trust a phone number, username, or website supplied by the same suspicious conversation.

Verify independently

  • Open the official app or bookmarked account page
  • Call a number already on your statement or official site
  • Contact the person through a saved address or known workplace channel
  • Ask whether the specific request and attachment were sent
  • Check account notifications and recent sessions directly

Report without forwarding the risk

Use the mail provider's phishing control or your organization's security process. Preserve headers when investigators request them. Do not forward a live attachment or link casually to coworkers. Delete the message after reporting according to policy. CISA's Secure Our World guidance emphasizes recognizing and reporting phishing rather than engaging.

If you already interacted

Disconnect only when instructed by your security process or when active malware is suspected; otherwise preserve access to obtain help. Change the affected account password from a trusted device, revoke sessions, enable or reset MFA, contact the service, review payment and recovery settings, scan or reimage as qualified support advises, and notify the organization whose data may be affected.

Use unique credentials from the password-manager guide and strengthen the account with the two-factor authentication checklist.

Sources and further reading

Primary and contextual sources used to verify definitions or give readers a relevant next resource.

  • CISA Secure Our World Official public guidance on recognizing and reporting phishing, strong passwords, multifactor authentication, and updates.
IE

Prepared and reviewed by

Infortified Editorial Team

Research-led guides with explicit scope, source checks where facts require them, and an independence review before publication.

Search Infortified

Find a practical answer

Start typing to search all guides.

Open full search