An email may look as though it comes from a familiar company while actually trying to steal your information or money. This guide explains three things to inspect before you reply, open an attachment or follow a link: the sender, the request and the destination.
Editorial clarification: the original guide treats a matching sender address as a sign of authenticity. That is not enough to establish trust. The English edition corrects that point and uses fictional .example addresses instead of potentially real domains.
1. Look beyond the sender's display name
A name such as “Customer support” or a recognisable company name can be copied. Inspect the full email address, including the domain after the @ symbol. A small spelling change may be easy to miss.
For an imaginary business using bisa.example, compare no-reply@bisa.example with no-reply@bisaa.example or no-reply@bisa-support.example. These are different domains. The examples are not working addresses and do not identify real companies.
Even an exact match is not proof of authenticity: a sender address can be spoofed. Microsoft explains this in its guidance on phishing and suspicious senders. Do not ignore a warning just because the name or logo looks familiar.
2. Consider what the message asks you to do
Be especially careful with unexpected requests for card details, account information, passwords, verification codes or a bank transfer. Pressure to act immediately, a supposed account problem or an unfamiliar invoice should prompt you to pause.
The issue is not simply whether a company ever discusses payments by email. It is whether this particular request is authentic and expected. Do not reply with sensitive information to prove your identity or resolve a threat made in an unverified message.
3. Check links without opening them
A link's visible text may differ from its destination. For example, https://www.bisa.example and https://www.bisaa.example are not the same address. The same caution applies to extra words or punctuation: looking similar is not the same as being the website you intended to visit.
Rather than testing a suspicious link, open the company's app or a website you already know is genuine. Use contact details obtained independently to ask about the message. Avoid unexpected attachments as well. The FTC's phishing guide explains this independent verification approach.
If you are still unsure
Leave the message alone while you verify it. Use your email provider's phishing-report option where appropriate, and keep your devices and account protections up to date. These checks reduce risk; they are not a test that can certify every email as safe.
For related examples, see our guide to scams affecting Facebook buyers and sellers. If you discuss a suspicious message in the comments, remove private information and do not post active suspicious links.
Comments (0)
Comments are shown in their original language.
No comments have been published yet. Be the first to join the conversation.