Start with what the message wants
Ask what action the sender is requesting and whether it fits the relationship. An unexpected login, payment, or document-sharing request deserves a closer look.
Read the identity and destination
A display name is only a label. Consider the actual sender address and the destination of any link. Different signals can matter together; a polished design does not establish authenticity.
Verify through an established channel
If uncertain, avoid the message’s links and contact the organization through a route you already know. Report suspicious messages using your organization’s process.
Further reading: NCSC: phishing guidance. This external reference does not imply a partnership or integration.
Browse all resources