Phishing messages try to make you act before you verify. The most useful defense is a short verification routine that you follow even when a message looks familiar.

Pause when a message creates urgency

Warnings about immediate account closure, surprise invoices, failed deliveries, or urgent payment requests are common pressure tactics. Urgency is not proof of fraud, but it is a reason to verify independently.

Check the actual sender

Display names are easy to imitate. Inspect the full sender address and watch for misspellings, unrelated domains, or unusual reply-to addresses.

Do not trust a link because the text looks right

On a computer, you can often hover over a link to preview its destination. On mobile, use caution with long-press previews. If the message concerns an important account, a safer approach is to open the official app or type the known website address yourself.

Be suspicious of unexpected attachments

Invoices, document shares, compressed files, and office documents can be used as lures. Confirm unexpected attachments with the sender through a trusted channel before opening them.

Watch for requests that bypass normal process

A message asking you to buy gift cards, change payment details, reveal a verification code, or move a conversation to an unusual channel deserves independent confirmation.

If you already clicked

Do not panic. If you entered a password on a suspicious page, change that account password using the legitimate site, end unfamiliar sessions if the service allows it, and review multi-factor authentication. If the same password was reused elsewhere, replace those passwords too.

The goal is not to become suspicious of every email. It is to make verification a normal step whenever a message asks you to log in, pay, download, or disclose sensitive information.

Editorial note: Technology changes quickly. Check current product interfaces and official documentation before making important account or security changes.