Verify the request through a channel you already trust. A familiar logo, correct name or polished message is not enough.
A delivery message asks for a small extra payment. An account alert says your access will be suspended. A colleague appears to need a document immediately. Different stories can lead to the same request: click a link, reveal information or send money before you have time to think.
Phishing works by making an action feel necessary. The strongest response is to verify the action independently.
Start with what the message wants
Ignore the logo for a moment. What are you being asked to do? Sign in, open an attachment, share a code, change bank details or approve an unexpected request?
Those actions deserve more scrutiny than an ordinary informational message. Urgency is not proof of fraud, but it is a reason to slow down.
Correct grammar does not make a message safe. A convincing message can use your real name, copy a familiar style and contain details gathered elsewhere.
Take a separate route
If a message claims to come from a service you use, open its app or navigate through a bookmark you already trust. Check whether the same notice appears in your account.
For an unusual request from a colleague or friend, contact them through an established channel. Use a known number rather than a new number supplied in the suspicious message.
This approach avoids turning the questionable link into your method of verification.
Examine links without depending on them
The visible text of a link can differ from its destination. On a computer, hovering may reveal the address; on a phone, the available preview behavior depends on the app.
Read the domain carefully. A brand name elsewhere in a long address does not establish that the brand controls the website. Shortened links can hide the destination further.
Even a secure HTTPS connection does not establish that the site's owner is honest. Encryption protects the connection, not the truthfulness of the request.
Treat unexpected codes and approvals carefully
Do not share a sign-in code with someone who contacts you unexpectedly. If you receive an approval prompt for a login you did not initiate, deny it and investigate through the service's official settings.
An attacker may claim that the code is needed to cancel a transaction or verify that you are the account owner. The story does not change what the code can authorize.
When a request involves changing payment details, follow the relevant organization's verification process before making the change.
If you already interacted
Your next step depends on what happened. Merely receiving a message is different from entering a password, downloading a file or making a payment.
If you entered credentials, change them through the genuine service and review active sessions and recovery information. Contact the relevant provider promptly if money or sensitive account information was involved. On a work device, follow the organization's incident-reporting process.
Report suspicious messages through the service's built-in tools where available, then remove them. Keep necessary evidence if an incident is being investigated.
You do not need to become a handwriting expert for every scam. A habit of checking important requests through an independent channel is more dependable than judging whether a message looks professional.
Sources & further reading
Original explainers and practical examples, with technical background from the sources below. Source links reviewed 2026-10-03.
More context, fewer assumptions. About our editorial approach.


