How to Spot a Phishing Email or Message Before You Click
Inspect identity, link destinations, requests, urgency, attachments, and account context, then report suspicious messages through a trusted channel.
INFORMATION FIELD OFFICEIF / D-07
Research dossier · open collection
Digital safety is easier when actions follow the systems that control identity: devices, email, phone, passwords, authentication, money, networks, and recovery. These guides prioritize prevention, independent verification, containment, official reporting, and documented recovery.
FIELD NOTES / D-07
Begin with the lead note, then follow the question closest to your next step.
Inspect identity, link destinations, requests, urgency, attachments, and account context, then report suspicious messages through a trusted channel.
Evaluate storage model, devices, sharing, recovery, and export, then migrate accounts to unique credentials without creating a lockout.
Compare security keys, authenticator apps, push prompts, biometrics, and codes, then protect important accounts without creating a lockout.
Harden the router that connects household computers, phones, work devices, guests, and smart products to one shared network.
Focus on the accounts, data, people, and harms that matter most instead of trying to disappear from the internet in one afternoon.
Reduce unnecessary site access and tracking while preserving the logins and services you intentionally use.
Assume other people control the local network and reduce what your device exposes, what tasks you perform, and how long the connection persists.
Harden the phone that holds communications, photos, payment access, passwords, authentication codes, location history, and account recovery.
Control who can find, contact, tag, profile, and reuse your information across current posts, old content, apps, and account recovery.
Protect the inbox that receives resets, financial notices, identity documents, private conversations, and security alerts for other accounts.
Assess a QR code’s context and destination, verify requests through an independent route, and respond appropriately if you already shared information.
Check website sessions, browser profiles, downloads, and saved access before leaving a shared computer, with a recovery route if you already walked away.