How to Spot a Phishing Email Before It's Too Late

Urgency, unusual payment instructions, requests for passwords and unexpected attachments deserve caution.

How to Spot a Phishing Email Before It's Too Late

Look at the requested action

Urgency, unusual payment instructions, requests for passwords and unexpected attachments deserve caution. Polished language or a familiar logo does not establish that a message is genuine.

Verify through a separate route

Open the organisation's known app or website yourself, or use independently verified contact details. Do not use the message's phone number or button as the only verification of its own claim.

If you already interacted

Describe whether you opened a page, downloaded a file or entered information. From a trusted device, contact the affected provider and follow recovery guidance. Account or payment exposure can need action beyond deleting the email.

Report and keep useful details

Use the mail service's phishing-reporting tools where available. Keep relevant evidence without forwarding dangerous attachments unnecessarily. No single spelling check or sender-name rule reliably identifies every deceptive message.

Questions about this guide

Does a familiar sender name mean an email is safe?

No. Verify unexpected requests through contact details you already trust, especially requests for payment, sign-in or verification codes.

What should I do if I entered a password on a suspicious page?

Change it through the real service using a trusted device and review account access. If money or sensitive information is involved, contact the relevant provider promptly.

Further reading

Tell us about your own situation.

Start a focused inquiry →