An email says your account will be suspended. A text demands a small delivery fee. A supplier sends updated banking instructions inside an existing conversation. Each request could look routine—and each could be phishing.
Phishing uses deceptive messages, websites, or conversations to persuade you to disclose information, grant access, install harmful software, or send money. It reaches people through email, texts, messaging apps, and phone calls.
The safest response is to verify the request somewhere else. Open the organization’s app, use a trusted bookmark, or call a number you already know. Do not let a suspicious message supply both the problem and the supposed solution.
1. Start With the Request, Not the Appearance
Before studying the logo or grammar, ask: What is this message trying to make me do? The FTC’s phishing guidance identifies familiar stories: suspicious account activity, payment problems, unfamiliar invoices, and requests to confirm personal information.
Slow down when a message asks you to:
- Enter a password or disclose a sign-in verification code.
- Send money, buy gift cards, or change banking details.
- Release sensitive employee, customer, or financial records.
- Open an unexpected attachment, install software, or run commands.
- Keep the request secret or bypass normal approvals.
Urgency alone does not prove fraud. But urgency combined with an unusual request deserves independent verification.
Do not rely on spelling mistakes. The FBI warns that criminals use generative AI to create more convincing messages and reduce language errors. Polished writing, accurate job titles, and familiar branding are not authentication.
2. Inspect the Sender and Destination
Check the actual email address
Expand the sender details. A display name such as “Payroll” or a colleague’s name tells you little. Look for misspelled domains, unfamiliar addresses, and unexpected reply-to addresses.
However, a legitimate address is not proof of safety. Attackers can compromise real accounts and insert fraudulent requests into genuine conversations. The FBI’s business email compromise guidance recommends independently verifying payment changes and other sensitive requests.
Read links carefully—without visiting them
On a computer, hovering over a link can reveal its destination. The following illustrative addresses use reserved example domains:
- https://login.example.com/ has “login” as a subdomain of example.com.
- https://example.com.attacker.example/ belongs under attacker.example, not example.com.
- https://attacker.example/example.com/login places the familiar name in the path, not the destination’s domain.
A familiar name somewhere in an address is not enough. Shortened links and legitimate tracking services can also obscure destinations, so unfamiliarity alone does not settle the question.
HTTPS does not mean trustworthy. It encrypts the connection; it does not establish that the operator is honest. Chromium’s security team explains this distinction.
If a destination is difficult to inspect, especially on a phone, stop decoding it. Open the service independently instead.
3. Recognize Traps Beyond Ordinary Links
Unexpected attachments and shared documents
An invoice or shared document may contain harmful software—or simply lead to a fake sign-in page. Confirm that you expected the file before opening it. If a document unexpectedly demands your email password, stop and contact the sender through an established channel.
QR codes
A QR code is another way to deliver a link. The FTC warns that scammers hide harmful destinations in QR codes. For an unexpected delivery or account notice, use the official app rather than scanning the message’s code.
Fake CAPTCHA and repair instructions
Stop if a webpage asks you to paste commands into Windows Run, PowerShell, or a terminal to prove you are human or fix an error. Microsoft documents this technique as ClickFix: attackers persuade the visitor to execute the harmful command themselves.
4. Verify Through a Separate, Trusted Channel
Microsoft recommends contacting the organization independently rather than using suspicious links—even when the apparent sender is someone you know.
- Bank alert: Open your banking app or call the number on your card.
- Account suspension: Navigate to the service using a trusted bookmark and check account notifications.
- Supplier payment change: Call a previously verified contact, not the new number in the email.
- Unusual request from your manager: Confirm through an established number or in person.
Replying to the same email is not independent verification: the attacker may control that conversation. A familiar voice is not conclusive either; AI can imitate voices. Initiate contact through a trusted route.
You do not have to prove a message is malicious before choosing a safer way to handle its request.
Verification adds friction. Reserve the strongest checks for high-consequence actions: payments, account access, sensitive records, and changes to established procedures.
5. Use Security Tools Without Treating Them as Guarantees
Email filtering, browser warnings, and updated software reduce exposure, but no single tool catches everything. Conversely, an “unverified sender” warning does not automatically establish fraud. Evaluate the request as well as the indicators.
Enable multifactor authentication, and prefer passkeys or FIDO2 security keys where supported. NIST explains that manually entered one-time codes are not phishing-resistant: attackers can trick you into providing a code and relay it to the legitimate service.
Passkeys and FIDO2 security keys bind authentication to the legitimate service. They do not prevent every scam, such as a fraudulent payment request. Never disclose a sign-in code to an unexpected caller or approve a login prompt you did not initiate.
For organizations, combine training with filtering, phishing-resistant authentication, clear payment controls, and easy reporting. Employees should not be the only defense.
6. Report Suspicious Messages
For work or school accounts, use the organization’s designated reporting button or contact security. If you interacted with the message, explain exactly what happened. Avoid forwarding it casually to colleagues.
- Gmail on a computer: Open the message without following links or attachments, select More next to Reply, then Report phishing. See Google’s instructions.
- Supported Outlook interfaces: Select the message, then Report and Report phishing. Workplace controls may differ; follow your organization’s procedure.
- U.S. text messages: Forward phishing texts to 7726, which spells SPAM.
- U.S. fraud reports: Use ReportFraud.ftc.gov; report internet crime, including business email compromise, to IC3.gov.
After reporting, delete the message unless your security team asks you to retain it.
7. If You Already Clicked, Respond to What Happened
Stop interacting. Clicking does not automatically mean your account is compromised, but entering information, granting access, or running software changes the response.
You only opened the page
Close it. Do not accept notifications, download files, or continue “verification.” Report the message. On a work device, tell IT about any unexpected downloads or browser behavior.
You entered credentials, shared a code, or approved access
From a trusted device, go directly to the legitimate service. Change the exposed password and any reused passwords. Revoke unfamiliar sessions and connected applications; review recovery details and recent security activity. For email, check forwarding rules and filters. Google’s compromised-account guidance provides a useful recovery model. Notify workplace IT immediately if relevant.
You downloaded or ran something
Do not open a downloaded file. If you ran software or commands, contact IT immediately for a managed device. For a personal device, update security software and run a scan; seek qualified help if compromise is suspected. Avoid changing passwords on a potentially compromised device.
You sent money or disclosed identity information
Contact your bank or payment provider immediately and request fraud assistance, including a recall if available. Recovery is not guaranteed, but speed matters. For exposed identity information in the United States, use IdentityTheft.gov for tailored steps.
Your Practical Phishing Checklist
- Pause: Is pressure pushing me to skip normal checks?
- Question: Was I expecting this request?
- Inspect: Does the actual sender or destination raise concerns?
- Protect: Does this involve money, credentials, sensitive data, or software?
- Verify elsewhere: Can I use a trusted app, bookmark, or established contact?
- Report: Have I used the appropriate reporting channel?
- Respond: Have I explained what I clicked, entered, downloaded, approved, or paid?
Make Independent Verification a Habit
Detecting phishing is not a test of who can spot the most typos. It is a repeatable decision process: examine the request, verify independently, and report concerns promptly.
Take action today: enable phishing-resistant authentication where available, locate your reporting tools, and establish a callback rule for payment changes. The goal is not perfect suspicion. It is making the safer action your default.