Phishing Email ID
14 items · Technical · Easy difficulty · 15 min
Quick, actionable steps to spot and report phishing emails.
-
Inspect sender address
Compare the display name with the actual email address and watch for misspelled domains.
-
Check reply-to address and headers
View full headers to see the true sending server if the address looks odd.
-
Look for generic greetings and unexpected tone
Be suspicious of vague salutations or messages you weren't expecting.
-
Examine links and domains
Do not click links; inspect the full domain and path for subtle typos or extra words.
-
Hover links to reveal the URL
On desktop, hover; on mobile, long-press to preview. Never tap if the preview looks suspicious.
-
Copy link and paste into a text editor or safe browser tab
Check for extra characters, subdomains, or misleading paths before visiting.
-
Handle attachments cautiously
Treat unexpected attachments as unsafe, especially .exe, .zip, .scr, or Office files with macros.
-
Scan attachments with antivirus or upload to an online scanner
Use your security tools or services like VirusTotal before opening files.
-
Avoid enabling macros or running executables
Never enable macros or run downloaded programs from unverified emails.
-
Verify requests for credentials or money through known channels
Contact the sender using official phone numbers or website contact forms, not reply.
-
Watch for urgency and fear-based language
Phishers pressure you to act now; treat time-sensitive threats as suspicious.
-
Confirm unexpected or unusual messages with the sender
Use a separate trusted contact method to validate the request.
-
Report the phishing email to IT, security team, or provider
Include full headers and the original message when possible.
-
Mark the message as phishing, block sender, and delete the email
Quarantine the message to prevent further exposure and remove it from your inbox.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.