Phishing emails often look convincing.
They may copy the logo of a bank, delivery company, online store, cloud service, or government agency. Some messages even include your name, order details, or the name of a company you regularly use.
The safest approach is not to judge an email by its appearance. Instead, inspect how the message asks you to act.
1. Check the Full Sender Address
The sender’s display name can be easily changed.
An email may appear to come from:
Microsoft Security Team
But the real address may be:
Expand the sender details and inspect the complete email address.
Look for:
- Misspelled company names
- Extra words or numbers
- Unfamiliar domains
- Free email services used for official business
- Characters that resemble other letters
A company name in the display field does not prove that the message came from that company.
2. Be Suspicious of Urgency
Phishing messages often try to prevent careful thinking.
Common warnings include:
- Your account will be closed today
- A payment failed
- Your password expires immediately
- Suspicious activity was detected
- A package cannot be delivered
- You must verify your identity now
Legitimate companies may send urgent notifications, but you should still verify them independently.
Open the company’s official app or type its website address directly into your browser instead of using the email link.
3. Inspect Links Before Clicking
On a computer, move the cursor over a link without clicking it. The real destination should appear near the bottom of the browser or email window.
On a phone, press and hold the link to preview it.
Check whether:
- The domain belongs to the real company
- The spelling is correct
- Unnecessary words appear before or after the company name
- The address uses an unrelated URL-shortening service
- The link leads to a file rather than a normal webpage
For example:
accounts.google.com may be legitimate.
google-account-security.example.com is controlled by example.com, not Google.
Read domains from right to left. The important registered domain is usually the part directly before .com, .org, .net, or another domain ending.
4. Do Not Trust the Lock Icon Alone
A lock icon means the connection to the website is encrypted.
It does not mean the website is honest.
Phishing websites can also use HTTPS and display a lock icon.
Always confirm the domain name before entering:
- Passwords
- Payment details
- Recovery codes
- Personal identification
- Security answers
Encryption protects the connection, not the intentions of the website owner.
5. Be Careful With Attachments
Unexpected attachments can contain malicious software.
Common risky file types include:
- Executable files
- Compressed archives
- Script files
- Documents requesting macros
- Password-protected archives
- Files with double extensions
A file named:
Invoice.pdf.exe
is not a PDF. It is an executable program.
Even familiar document formats can be dangerous if they ask you to enable editing, activate macros, or install additional software.
Before opening an attachment, confirm with the sender through another communication channel.
6. Look for Unusual Requests
Be suspicious when an email asks you to:
- Share a password
- Send a verification code
- Purchase gift cards
- Transfer money urgently
- Change payment details
- Install remote-access software
- Scan a QR code to log in
- Download a security certificate
- Provide personal documents
Legitimate support staff should not ask for your full password or multi-factor authentication code.
A verification code is intended to prove that you control the account. Anyone asking you to send it may be attempting to log in as you.
7. Notice Changes in Normal Business Procedures
Business phishing often imitates managers, suppliers, or finance departments.
The message may request:
- A new bank account for payments
- An urgent invoice
- Confidential employee information
- A large transfer
- A change to payroll details
Do not approve unusual financial requests based only on email.
Verify the request using:
- A known phone number
- An internal messaging platform
- An existing supplier contact
- A face-to-face conversation
- A formal approval process
Do not use the phone number included in the suspicious email.
8. Review the Language and Formatting
Poor grammar is no longer a reliable way to identify phishing. Modern scam emails may be professionally written.
However, warning signs can still include:
- Unusual greetings
- Inconsistent branding
- Different fonts
- Low-quality logos
- Unexpected tone
- Strange punctuation
- Language that does not match previous messages
- A signature that lacks normal contact details
The strongest signal is often not one mistake but several unusual details appearing together.
9. Be Careful With QR Codes
Some phishing emails use QR codes instead of clickable links.
The code may lead to a fake login page designed for mobile users.
Before scanning:
- Ask why a QR code is necessary
- Verify the sender
- Preview the destination when possible
- Avoid entering credentials on the opened page
- Use the official app instead
QR codes hide the destination more effectively than visible links, which makes them attractive to scammers.
10. Use a Password Manager
A password manager can reduce phishing risk because it normally fills credentials only on the correct domain.
If the password manager does not recognize a login page, stop and inspect the address.
Do not manually copy the password into an unfamiliar page simply because autofill did not work.
Use a unique password for every important account. Password reuse allows one stolen password to compromise several services.
11. Enable Multi-Factor Authentication
Multi-factor authentication adds protection after the password.
Strong options include:
- Authentication apps
- Hardware security keys
- Passkeys
- Device-based confirmations
Text-message codes are generally better than using only a password, although they may be less secure than other methods.
Never approve a login request you did not initiate.
Repeated unexpected authentication prompts may mean someone already knows your password.
12. Verify Through an Independent Channel
When a message seems suspicious, do not reply directly.
Instead:
- Open the official app.
- Visit the website through a saved bookmark.
- Call a verified customer-service number.
- Contact the sender using an existing conversation.
- Ask your company’s security team.
This separates the verification process from the suspicious message.
13. What to Do After Clicking
Clicking a phishing link does not always mean your account has been compromised.
The next steps depend on what happened.
If You Only Opened the Page
Close it and run a security scan if the page downloaded anything.
If You Entered a Password
Change the password immediately from a trusted device.
Also change it anywhere else you reused it.
If You Shared a Verification Code
Sign out of other sessions, change the password, and review account activity.
If You Entered Payment Details
Contact the bank or card provider immediately.
If You Installed Software
Disconnect the device from the internet and seek technical support.
Act quickly. Delaying gives attackers more time to use the information.
14. Report the Message
Reporting phishing helps email providers and organizations block similar attacks.
Use the email service’s:
- Report phishing
- Mark as spam
- Report suspicious message
Employees should also forward suspicious messages to their internal security team using the company’s approved reporting method.
Do not forward dangerous attachments casually to coworkers.
A Simple Phishing Checklist
Before clicking, ask:
- Is the sender address correct?
- Was I expecting this message?
- Is it creating unnecessary urgency?
- Does the link use the official domain?
- Is the attachment expected?
- Is it asking for passwords or codes?
- Is the request different from normal procedure?
- Can I verify it independently?
When several answers raise concern, stop interacting with the message.
Final Thoughts
Phishing succeeds because people are rushed, distracted, or worried.
The most reliable defense is to slow down.
Check the full sender address, inspect links, avoid unexpected attachments, and verify urgent requests through another channel.
A message that is genuinely important will still be important after you spend two minutes confirming that it is real.