BEGINNER-FRIENDLY SECURITY GUIDE

How to Tell If an Email Is Phishing

Phishing emails try to make you act before you have time to think. They may imitate a company, coworker, vendor, bank, or delivery service and ask you to click, pay, sign in, or share sensitive information.

Check who really sent the message

Look beyond the display name and read the full From address. A familiar name can be paired with an unrelated, misspelled, or lookalike domain. Also check whether Reply-To sends your response somewhere different.

A different sending domain is not automatic proof of phishing—legitimate services send mail for other organizations—but it is a reason to verify the message independently.

Pay attention to the request

Be cautious when an unexpected message asks for a password, MFA code, payment, gift card, bank-account change, direct-deposit change, or urgent document signature. A real-looking sender does not make an unusual request trustworthy.

Pressure tactics such as “final notice,” “act today,” or threats of suspension are especially concerning when combined with a sensitive request.

Inspect links and attachments

On a computer, hover over a link without clicking it and compare the destination with the organization you expect. On a phone, press and hold carefully to preview the address. Avoid opening unexpected executable files or password-protected archives.

Use a bookmark, known app, or address you type yourself instead of relying on the message's link.

Authentication helps, but it is not a verdict

SPF, DKIM, and DMARC can show whether a message was authorized for the domain it used. They do not prove that the domain belongs to the organization being claimed, or that a request for money or credentials is legitimate.

When the stakes are high, contact the sender using a phone number or contact method you already trust.

Check a suspicious email

Paste the message or full header into the local Email Analyzer to review technical warning signs.

Check an Email