Start with what the message asks you to do
A phishing email tries to move you from reading to acting: signing in, opening a file, sharing a code or sending money. A familiar logo is easy to copy. Even an authentic-looking conversation can contain a message from a compromised account. Judge the action before judging the branding.
Imagine an invoice saying a supplier has changed its bank account. The important question is whether that change is genuine. A correct invoice number does not answer it.
Check the message in four steps
- Expand the sender details. Compare the actual address with earlier messages from the organisation. A display name such as Microsoft Support is not proof of identity.
- Read the request. Urgency, secrecy and pressure to bypass the usual approval process deserve an independent check. Perfect spelling does not make an email safe.
- Inspect the destination without opening it. Hover on a desktop or use your app's link-preview feature carefully. In https://bank.example.attacker.test, the address belongs to attacker.test, not bank.example. Shortened links conceal the destination.
- Open the organisation's app or a saved bookmark instead. For payment changes, telephone a contact using an independently known number, not the number in the suspicious email.
A safe practice exercise
Compare one expected receipt with one suspicious message. Write down the real sender, the requested action and the destination domain. Do not open attachments to complete the exercise. The aim is to practise verification, not to collect malware samples.
Verify your decision
A payment or account alert should be independently explainable through the genuine service. If you cannot confirm it, stop the requested action and report the message using your email provider's phishing option. At work, follow the IT reporting process so other recipients can be protected.
Common mistakes
HTTPS protects the connection; it does not prove that the operator is honest. A message appearing in an existing thread is not automatically trustworthy. Forwarding the attachment to colleagues can expose them too: use the approved reporting route instead.
If you already interacted
Record whether you only opened the page, entered credentials, approved an MFA prompt or ran a download. Those events need different responses. Use the related phishing-response guide; if money was involved, contact your bank promptly through its official app or published number.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.