Start with the request.

Is the message asking for credentials, a payment, sensitive information, or an unexpected download? Treat the action it asks you to take as the most important clue.

Notice the pressure.

A short deadline, a threat of account closure, or an unusually generous offer can be an attempt to make you act before checking. Urgency alone does not prove a message is malicious, but it is a reason to slow down.

Check the sender in context.

A display name is easy to imitate. Look at the actual address and consider whether it matches the organization and the kind of request. A familiar-looking address is not proof of legitimacy.

Use an independent channel.

Open the official service using a bookmark or an address you already know. Contact the organization through a verified phone number or support page rather than a link or number in the message.

If you already interacted.

Contact your institution’s IT team through a trusted channel. Explain what you clicked or shared. If credentials were exposed, follow the institution’s account recovery guidance promptly.

Practice with a fictional email