Is This a Phishing Message? How to Check Safely
A practical guide to safely inspecting suspicious emails and messages without risking malware, plus immediate containment steps if you clicked a link or entered information.
Start Here: 30-Second Immediate Triage
Immediate action before changing complex settings
If you received an unexpected message claiming your account is suspended, a delivery is held, or payment is overdue, DO NOT click any links to test or verify them.
Quick Diagnostic Checks
Most Likely Causes
Understanding the mechanism prevents guessing and avoids creating new system issues.
Deceptive Sender Display Names
Scammers set display names to "Geek Squad", "Netflix Support", or "Bank of America", but the actual sending email is a random Gmail address or unrelated domain.
Artificial Urgency & Fear Tactics
Messages demand immediate action within 24 hours to prevent account closure, legal action, or unauthorized charges, designed to bypass rational evaluation.
Misleading URLs & Domain Spoofing
Links use slight misspellings (e.g., netfIix-verify.com), excessive subdomains (paypal.com.account-update.xyz), or URL shorteners to mask fake destinations.
Unsolicited Invoices & Attachments
Emails include PDF or ZIP attachments claiming you owe hundreds of dollars for a subscription you never purchased, prompting you to call a fake call center.
Requests for Passwords or 2FA Codes
Any message asking you to reply with your password, PIN, or one-time two-factor authentication code is guaranteed to be a fraudulent attempt.
Phishing Red Flags & Triage Matrix
Assess suspicious message elements safely without interacting with links.
Step-by-Step Resolution Protocol
Work through these steps in order. Click to check off items as you complete them.
Safely Inspect Sender and Target Domain (Without Clicking)
- On desktop, hover your mouse over the link without clicking. Check the destination URL preview in the bottom-left corner of your browser.
- Look at the root domain: `support.apple.com` is legitimate, but `apple-support-verify.com` is not.
- On mobile, do NOT tap links. Instead, view the sender details by tapping the contact name at the top of the message.
Immediate Containment: Stop Interacting and Close the Tab
- If you clicked a suspicious link, immediately close the browser window or tab.
- Do NOT download any proposed "software updates", "security plugins", or executable files.
- Do NOT fill out forms asking for your name, address, password, or Social Security number.
Do Not Enter or Transmit Credentials
- Simply loading a webpage in a modern, updated browser rarely infects a device due to robust browser security sandboxes.
- The primary risk in phishing is user-submitted data. If you did not press "Submit" or type passwords, your account credentials remain secure.
Change Compromised Passwords from a Known Safe Device
- If you entered credentials on a suspicious page, open a clean browser tab and go directly to the service's official website.
- Change your password immediately to a strong, unique passphrase.
- If you reused that password on other websites, update those accounts as well.
Terminate All Active Sessions & Enable 2FA
- Visit the account's Security dashboard and click "Sign Out of All Devices".
- Turn on Two-Factor Authentication using an authenticator app (e.g., Google Authenticator, Microsoft Authenticator) or security key.
- Verify that your recovery email and phone number remain unaltered.
Report and Delete the Phishing Message
- In Gmail, Outlook, or Apple Mail, select "Report Phishing" or "Report Spam" to train mail filters.
- For SMS text scams, forward the message to 7726 (SPAM) to notify cellular carrier fraud teams.
- Report significant scams to the FTC at ReportFraud.ftc.gov or the FBI Internet Crime Complaint Center (IC3).
What Your Inspection Result Tells You
If You Suspect Ongoing Compromise
Safe escalation pathways
If you shared sensitive information or downloaded an unknown file:
- 1Call your financial institutions immediately to freeze compromised cards or accounts.
- 2Place a free credit freeze on your credit files at Equifax, Experian, and TransUnion.
- 3Run a full security scan using built-in Windows Security / Defender or macOS security protections.
- 4File an official report at IdentityTheft.gov if your Social Security number or government ID was shared.
When to Stop & Critical Safety Boundaries
Use the Interactive 10-Step Tech Fixer
Prefer an interactive checklist with real-time step trackers? Launch the full FixTheDay Tech Fixer for this issue.
Authoritative & Official Sources
Verified, non-commercial documentation and government safety guidance
Federal Trade Commission comprehensive consumer guide to identifying phishing scams.
Cybersecurity and Infrastructure Security Agency official anti-phishing guidance.
Official US government portal for reporting fraudulent messages and scams.
Global industry and law enforcement coalition dedicated to tracking phishing attacks.