Spotting a Phishing Email

The checks worth running on any email asking for a password, a payment, or an urgent click. Print this and keep it near the desk.

Check the Sender

  • Hover or tap the sender's name to see the real address underneath the display name. A display name can say anything; the address next to it can't hide as easily.
  • Look for near-misses in the domain, like amaz0n-verify.ru instead of amazon.com. One swapped letter or an odd extra word is the giveaway.

Watch for Urgency

  • Be suspicious of deadlines and threats ("your account will be closed in 24 hours"). Real companies rarely create this kind of panic in an email.
  • Slow down on purpose. Panic is the tactic being used on you, not a sign of a real emergency.

Hover Before You Click

  • On a computer, hover over any link without clicking to see where it actually leads, shown in the corner of the browser.
  • On a phone, press and hold instead of tapping, to preview the link the same way.

Be Careful With Attachments

  • Don't open unexpected invoices or documents, even ones that look routine. This is one of the most common ways malware actually gets onto a computer.
  • Confirm through a different channel (a phone call, a separate message) before opening anything you weren't expecting.

Protect Yourself Either Way

  • Use a password manager. If a password does get phished, it stays unique to one site and can't be reused to break into your other accounts.
  • Turn on two-factor authentication wherever it's offered, so a phished password alone isn't enough.

Read the full article for more detail →