Editorial technology illustration for "How to Spot a Phishing Email Before You Click Anything"

How to Spot a Phishing Email Before You Click Anything

Technology advice gets complicated fast when every answer starts with a product, a warning, or fifteen settings you do not understand. This guide takes the practical route: identify the real risk or bottleneck, make the safest useful change, and leave yourself a way back.

Start with the request, not the logo

A polished logo proves almost nothing. Ask what the message wants you to do: sign in, pay an invoice, buy gift cards, open a document, reset a password, or share a code. Urgency plus a request involving money, credentials, or secrecy deserves a separate verification step.

Check the actual sender

Expand the sender details and read the full address. Look for misspellings, extra words, unfamiliar domains, and free email accounts pretending to represent a business. A familiar display name can be forged. Even a real coworker’s account can be compromised, so an unusual request still needs verification.

Inspect links without opening them

On a computer, hover over the link and read the destination. On a phone, press and hold only if your mail app safely previews the address. Do not trust a link merely because it contains a company name somewhere in a long address. When the message claims to be from a service you use, open your browser or official app yourself and navigate there independently.

Treat attachments as a separate decision

Unexpected invoices, shared documents, voicemail files, and shipping notices are common bait. Do not enable macros or security-bypass prompts. Confirm the attachment with the sender through a known phone number or a fresh message—not by replying to the suspicious email.

Verify through a second channel

Call the person using a number you already have, open the company’s official app, or start a new message to a known address. Never use the phone number or verification link supplied inside the suspicious message. If the request is legitimate, a short delay will not ruin it.

If you already clicked

Stop entering information. Close the page, disconnect only if a download started, run your normal security scan, and change any password you entered from a clean device. If that password was reused, change those accounts too. Contact your bank immediately for payment information and tell your workplace security team if a work account or device was involved.

Donna’s bottom line

Use the simplest process that solves the real problem, document the important choices, and verify the result. More software is not automatically more security, more speed, or more control. A small repeatable habit usually beats a complicated setup that nobody maintains.

For a deeper look at locking down your site, see 5 Signs Your WordPress Site Needs a Security Audit.

Sources

CISA phishing guidance

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.