How to Check if an Email Is Phishing: A Safe Guide to Links, Attachments, Reporting, and Recovery Steps

Key takeaways
- How to check if an email is phishing begins with a pause. No clicking, replying, downloading, or approving should happen until the message has been verified elsewhere.
- The sender domain after the @ symbol carries the identity signal, while the display name carries none. Lookalike domains remain the most common disguise.
- Links, QR codes, and attachments need inspection before any interaction, because quishing and weaponized documents hide their destination from a quick visual review.
- Email authentication results such as SPF, DKIM, and DMARC confirm delivery authorization only. A compromised legitimate mailbox can still pass every check.
- Reporting through an approved channel protects other recipients, and fast disclosure after a click limits credential, payment, and malware damage.
Knowing how to check if an email is phishing starts with treating every unexpected request as untrusted until it is verified through a separate, known-good channel. Phishing is social engineering designed to steal credentials, payment details, personal information, or account access. A polished message from a familiar contact can still be malicious.
A suspicious email can be assessed without interacting with attacker-controlled links or attachments. This guide explains how to pause, inspect the full sender address and recipient details, evaluate urgency and secrecy, and preview destinations safely.
Later sections cover QR codes and files, technical signals, and the right reporting workflow. They also address spear phishing, whaling, vishing, smishing, and AI-generated messages, where spelling and grammar no longer reveal the cyberthreat.
A safe check protects more than a single inbox. Independent verification stops payment fraud, reporting improves defenses for other recipients, and prompt recovery limits damage after a click or disclosure. The checklist and response steps below support a confident decision that never depends on one warning sign.
Organizations seeking to instruct their employees to recognize phishing emails are encouraged to explore a tour of Adaptive Security’s phishing simulations.

Phishing Email Checklist: How to Check if an Email Is Phishing
Knowing how to check if an email is phishing comes down to a repeatable sequence rather than a single test. Pause, inspect the sender and domain, assess the request, preview links without clicking, and examine attachments. Verification through an independent channel comes next, followed by reporting and then deletion or quarantine.
This phishing email checklist applies before any interaction with a suspicious message. Phishing attempts to steal credentials, payment details, personal information, or system access by impersonating a trusted person or organization. A familiar logo, polished writing, or real-looking address does not make an email safe.
1. Understand What the Message Is Trying to Achieve
Phishing emails move recipients from trust to action before careful judgment begins. The requested action typically gives a cyberattacker something valuable. Examples include a password, multifactor authentication code, bank account change, invoice payment, customer record, or access to an internal system.
The FBI's guidance on spoofing and phishing identifies passwords and bank PINs among the information cyberattackers commonly target.
The request may appear ordinary. An email can ask an employee to review a shared document, confirm payroll information, reset a Microsoft 365 password, approve a vendor invoice, or download a shipping form.
The risk comes from the combination of identity, timing, and consequence. The sender appears familiar, the request arrives when the recipient is busy, and the message suggests that delay will create a financial, operational, or personal problem.
Phishing emails do not need spelling errors. Cyberattackers copy brand layouts, write fluent messages, use compromised accounts, and personalize requests with open-source intelligence (OSINT) gathered from company websites and social media.
A polished message deserves the same controlled inspection as an obviously suspicious one, which is why a structured review of the anatomy of a phishing email works better than instinct.
2. Use This Eight-Point Visual Phishing Email Checklist
A visual review catches many phishing signals, although only when the recipient inspects the message before clicking, replying, downloading, or approving anything. Treat any unresolved concern as a reason to verify the request independently.
- Pause before taking action. Avoid clicking a link, opening an attachment, replying, forwarding the message, or calling a number inside it. Urgency functions as a pressure tactic and never establishes legitimacy. Inspect the message carefully, keeping it open in a separate window if necessary.
- Inspect the sender's full email address. Display the complete address instead of relying on the visible name. A cyberattacker can make Accounts Payable appear in the sender field while using an unrelated mailbox. Look for unexpected domains, extra words, swapped letters, unusual subdomains, and free email services used for business requests. A familiar display name amounts to no sender verification at all.
- Check the domain against the real organization. Compare the domain after the @ symbol with the organization's known website or a previous trusted message. Watch for lookalike domains that replace a letter, add a hyphen, use a different top-level domain, or place a trusted brand inside a longer attacker-controlled domain. A message from vendor.com.attacker-site.example does not come from vendor.com.
- Assess the request and its urgency. Identify what the sender wants, why the request arrived now, and what happens without immediate compliance. Requests to bypass approvals, change payment instructions, reveal a password, share a verification code, or keep a transaction confidential require independent verification. Executives and vendors follow approval procedures too. Pressure should trigger the procedure and never replace it.
- Preview links without clicking. Hover over a link on a desktop or press and hold it carefully on a mobile device to reveal the destination. Compare the displayed URL with the visible text and the organization's real domain. Treat shortened links, unexpected login pages, misspelled domains, and URLs that use a trusted brand only in a path or subdomain as untrusted. When a message asks for a sign-in, open the service through a known bookmark or manually typed address.
- Examine attachments before opening them. Confirm that the file was expected, that the sender is recognized, and that the reason for sending is clear. Treat unexpected invoices, shipping notices, password-protected archives, macro-enabled documents, executable files, and files that ask for content to be enabled as high risk. When a business process requires a document, verify it through an established channel first, never through the phone number or reply address inside the email.
- Look for inconsistencies in the message. Compare the greeting, signature, writing style, branding, dates, footer, and contact details with prior legitimate messages. A generic greeting is a signal, although a personalized greeting proves nothing about safety. Check whether the tone matches the sender's normal behavior and whether the request fits the person's role. Cyberattackers can copy real text, so inconsistencies should prompt verification rather than serve as the only test.
- Verify, report, and remove the message. Contact the supposed sender through a phone number, chat channel, ticketing system, or address already stored in the organization's directory. Confirm whether that person sent the message and what the exact request was. Use the organization's reporting button or email process, preserve the message if the security team needs it, and delete or quarantine it. The Federal Trade Commission's phishing guidance recommends reporting phishing instead of allowing the message to circulate.
This checklist functions as a decision process rather than a contest to count red flags. One strong signal, such as a request for credentials or a payment change, is enough to stop and verify.
Employees who report uncertain messages quickly give security teams time to investigate related emails, warn other recipients, and remove malicious content before it spreads.
3. Separate Visual Signals From Technical Proof
Visual inspection supports a safe first decision, although it cannot prove that an email is legitimate. A real employee account can be compromised, a legitimate vendor mailbox can be abused, and a cyberattacker can reproduce a company's branding. The absence of spelling errors or suspicious formatting is no clean bill of health.
Email headers and authentication results give security teams additional context. They can show whether sending infrastructure aligns with the claimed domain and whether the message passed checks such as SPF, DKIM, or DMARC.
These controls provide useful signals. A passed authentication check still proves nothing about the safety of the request, because a compromised account can send authenticated phishing messages.
When a request involves money, credentials, sensitive data, or privileged access, verification must use a method the email cannot control. Options include calling a known number from the company directory, starting a new chat, or opening a separate internal ticket.
Replying to the suspicious message, using its signature details, or clicking its cancel or secure-account link all fail the same way. Verification collapses when it stays inside the cyberattacker's communication channel.
4. Know When to Stop Investigating and Report Immediately
Stop investigating and report the email immediately when it requests a password, MFA code, payment, gift card purchase, payroll change, confidential file, remote-access installation, or unusual secrecy.
The same rule applies when the message threatens account closure, legal action, missed payroll, service suspension, or a financial penalty unless action follows within minutes. These requests create high-consequence decisions under artificial time pressure.
Report immediately when a message appears to come from an executive, finance leader, customer, supplier, law firm, government agency, or IT administrator and asks for an exception to normal process. Business email compromise (BEC) often relies on a believable identity and familiar workflow rather than a dramatic malware payload.
A plausible request can still redirect money or expose sensitive information. After a click, an opened attachment, entered credentials, an approved MFA prompt, or a reply containing sensitive information, report the incident without waiting to determine whether damage occurred.
Disconnect from the network only when the organization's incident procedure directs it. Contact the security team through its known emergency channel, change exposed credentials from a trusted device, revoke active sessions where instructed, and provide the original message and timeline.
Organizations can reinforce this process with phishing simulations that rehearse email, voice, SMS, and deepfake scenarios. Employees practice pausing, verifying, and reporting before a real request carries financial or operational consequences.
The goal is to build a repeatable response that makes the safest action easier under pressure, without shaming employees for missing a signal.
5. Make Reporting the Default Safe Action
Reporting phishing should be faster than forwarding a suspicious email to a colleague for informal review. Provide a clear reporting button in the email client, define what happens after a report, and tell employees what information the security team needs.
A useful process captures the original message, sender address, links, attachment names, recipient, and approximate time of interaction.
Security teams should acknowledge reports, classify the message, remove confirmed cyberthreats from other inboxes, and provide targeted follow-up when an employee interacted with the content. That feedback loop turns each suspicious message into a training signal.
Employees learn which decisions protected the organization, while analysts gain visibility into campaigns that bypass automated filters.
The safest response to an uncertain email is a pause, an independent check, and a report. That sequence protects credentials, payment processes, and personal information even when a message looks polished enough to pass a quick visual review.
How to Check if an Email Is Phishing by Verifying the Sender
How to check if an email is phishing starts with the sender rather than the message's branding or urgency. Expand the full sender details, compare the display name with the actual From address, and inspect the domain character by character. Review the Reply-To field before clicking, replying, or opening an attachment.
A familiar name or legitimate third-party sending service does not prove safety. Unusual requests need confirmation through a separate trusted channel, and a full checklist of phishing email warning signs covers the visual signals in more depth.
1. Compare the Display Name With the Full From Address
The display name is a convenience label that performs no identity check. Email applications often show only a name such as Payroll, Microsoft Support, or Brian Long while hiding the address that delivered the message. Select the sender name, open the message details, or use the option that reveals the full From address.
Compare the visible name with the address after the @ symbol. A message labeled Accounts Payable that arrives from accounts-payable@vendor-helpdesk.co deserves scrutiny when the organization normally uses company.com.
The mismatch proves nothing on its own, although it creates a verification checkpoint. A legitimate message should fit the sender's role, organization, and normal communication channel.
Cyberattackers also place trusted names inside addresses to make the first part look official. The address ceo.company.com@gmail.com belongs to Gmail rather than to company.com, and the same applies to company-security@outlook.com. The domain after the @ symbol carries the identity signal, while the words before it carry none.
Review the greeting alongside the sender details. Dear customer, Hello user, or Dear employee can indicate that the sender does not know the recipient, particularly when the message claims to come from an internal department.
A generic greeting remains inconclusive because automated business messages use it legitimately. Treat it as one signal to assess alongside the address, request, recipients, and expected workflow.
2. Inspect the Domain and Reply-To Address Character by Character
The domain is one of the strongest visible identity signals in many phishing emails, although it requires careful reading. Cyberattackers register lookalike domains that imitate trusted organizations through a changed letter, added word, substituted character, or misleading subdomain.
The address company-support.com differs from company.com, and company.com.security-check.net belongs to security-check.net rather than to company.com.
Read from right to left through the domain's main ending. In login.company.com, the organization is generally company.com. In login.company.com.verify-account.net, the controlling domain is verify-account.net. Long subdomains and familiar brand names can push the actual domain out of immediate view.
Check for character substitutions that are easy to miss in a crowded inbox. A lowercase l can resemble an uppercase I, while extra hyphens, doubled letters, or altered country-code endings can create a convincing copy. Internationalized domain names can also use characters from other writing systems that resemble Latin letters.
When a message requests credentials, payment, sensitive data, or an urgent approval, navigate to the organization's known website through a bookmark or a manually entered address instead of the email link.
Open the message details and compare the Reply-To field with the From address. A mismatch can be legitimate when a company uses a ticketing system, marketing platform, customer-service queue, or other third-party sending service.
The domain alone remains inconclusive. A message that appears to come from an executive while directing replies to a free mailbox, unrelated domain, or unfamiliar external address requires independent verification.
Technical headers provide more context when the decision carries financial or legal consequences. Authentication results such as SPF, DKIM, and DMARC can show whether the sending infrastructure was authorized for a domain, although a passing result guarantees nothing about safety.
A criminal can send a malicious message from a compromised legitimate account or abuse a legitimate service. Header results serve as supporting evidence, and they never license ignoring an unusual request.
3. Analyze the Recipients, Greeting, Branding, and Request Together
Recipient details can reveal a cyberattack that the sender line conceals. A message addressed to undisclosed recipients, a large unfamiliar group, or several unrelated employees can indicate bulk targeting. Review the To, Cc, and Bcc fields when they are visible.
When an apparently private executive request includes an unfamiliar group of recipients, pause before responding.
Messages that appear to come from the recipient's own address deserve the same caution. Cyberattackers sometimes place that address in both the From and To fields to suggest that the message originated from the recipient's account.
The technique exploits familiarity while establishing nothing about the true sender. Inspect the full headers and report the email through the organization's approved process.
Branding works as a supporting signal and never as an identity guarantee. Altered logos, stretched images, inconsistent colors, outdated organization names, and unofficial department labels can expose a counterfeit message.
A real logo can appear in a malicious email because cyberattackers copy it from a public website, and a legitimate message can contain a redesign or formatting error. Judge branding against the sender domain and business context rather than treating visual polish as proof.
Pay particular attention to confidentiality and anti-verification language. Phrases such as do not discuss this with anyone or do not call to confirm attempt to isolate the recipient from colleagues who could expose the fraud.
Cyberattackers use secrecy to prevent a second person from challenging the request. A legitimate confidential transaction still has an approved process, an accountable owner, and a safe verification method.
Use a separate channel when the message requests a wire transfer, gift card, password reset, multifactor authentication code, payroll change, sensitive document, or unusual vendor payment. Call a known number from the company directory or an existing contact record.
Never use the phone number in the email, reply to the message, or approve a request merely because the sender appears to know internal details.
The Cybersecurity and Infrastructure Security Agency guidance on recognizing phishing identifies suspicious requests for personal information, harmful links, and unexpected attachments as warning signs. Apply that guidance as a decision sequence: verify the sender, inspect the destination, confirm the request, and report the message when the signals fail to align.
4. Treat Known Contacts as Untrusted Until the Request Is Verified
A known contact can still send a phishing email. The person's account might be compromised, the mailbox might be spoofed, or the legitimate account might have been used through an authorized third-party service.
Familiarity lowers skepticism, which makes a trusted contact an effective cover for fraud. The relevant question is whether the request matches that person's normal behavior and verified process.
Compare the message with previous conversations. Has the writing style changed abruptly? Is the sender requesting a new bank account, secret payment, urgent file transfer, or login action never requested before? Does the email arrive at an unusual time or reference an unrecognized project?
One difference can have an innocent explanation. Multiple changes require separate confirmation.
A reply proves nothing about authenticity. When a cyberattacker controls the mailbox, the reply reaches the cyberattacker. Start a new conversation using a previously trusted address, call the contact through a known number, or ask a colleague to confirm the request independently.
Executive, finance, human resources, and IT requests deserve a documented two-person approval process instead of personal judgment under pressure.
Third-party sending services require the same balanced approach. A legitimate company might send invoices, support tickets, newsletters, calendar notices, or account alerts through a platform whose domain differs from the organization's primary domain.
Verify the service through the organization's public website, existing contract records, or a known internal owner. A third-party domain proves nothing on its own, although an unexplained service combined with urgency, secrecy, or a Reply-To mismatch is a strong reason to stop.
Organizations can reinforce these habits with phishing simulations that rehearse sender verification across realistic email and social engineering scenarios. Employees who report suspicious messages, even when uncertain, give security teams the context to investigate related messages and protect other recipients.
A careful pause is the trained behavior that keeps an unfamiliar sender, lookalike domain, or compromised trusted account from turning one email into a larger incident.
How to Check if an Email Is Phishing by Inspecting Links, QR Codes, and Attachments
Part of knowing how to check if an email is phishing is inspecting every link, QR code, and attachment before interacting with it. Hover over links on a computer, long-press them on a mobile device when supported, and compare the destination with the organization named in the message. Treat unexpected redirects or files as a stop signal.
Previewing a message differs from opening its links or attachments, although no preview feature removes every risk. High-stakes requests still need verification through a trusted channel.
1. Inspect the Link and URL Before Selecting It
Link inspection starts by revealing the destination without loading the page. On a desktop or laptop, move the pointer over the link without clicking. Most email applications display the full destination in a status bar, tooltip, or lower corner of the window.
Read the address from right to left, and never judge it by the visible wording alone. In https://login.example.com.account-check.net/signin, the controlling domain is account-check.net rather than example.com.
Cyberattackers place familiar company names in subdomains, paths, or query strings to make fraudulent addresses look legitimate.
On a phone or tablet, press and hold the link until the device displays a preview or action menu. Choose an option such as Copy Link or Preview when available, and avoid Open. Paste the copied address into a notes app or other non-browser field, where it can be examined without navigating to the site.
Mobile behavior differs between email applications. Cancel the action when the only available choice opens the link immediately.
A genuine message from a bank, payroll provider, cloud service, or government agency should lead to the organization's established domain. Lookalikes that swap characters, add words, or use an unrelated country-code domain fail that test.
Watch for shortened URLs, redirect chains, misspellings such as micros0ft, extra hyphens, unusual punctuation, and domains that differ by a single character.
A secure https connection encrypts traffic to the site. It proves nothing about whether the site belongs to the claimed organization.
A familiar login page still requires scrutiny. Compare its domain with an already trusted bookmark, or type the organization's known address manually into a new browser window. Never use an email link to reset a password, review an invoice, approve a payment, or resolve an account warning.
For a broader defensive program, phishing simulations that rehearse suspicious links and business email compromise give employees a controlled way to practice inspection before a real request creates pressure.

2. Check QR Codes for Quishing and Unexpected Redirects
QR codes turn link inspection into a mobile problem. A code printed in an email, PDF, invoice, poster, or message can send a phone directly to a phishing page, app download, payment form, or credential prompt. This technique is called quishing, or QR-code phishing, because the code conceals its destination from a quick visual review.
Treat an unexpected QR code as an untrusted link, especially when it asks for a sign-in, payment confirmation, account unlock, or bypass of a security control.
Never scan a code merely because the message uses a company logo or claims that scanning is required. Cyberattackers can copy the branding and layout of a legitimate notice while replacing the destination.
When scanning is necessary, use the phone camera's preview to inspect the URL before opening it. Most current devices display the destination as a notification or preview. Read the domain, compare it with the claimed organization, and cancel when the address is shortened, misspelled, redirected, or unrelated.
A QR code that points to a file download or requests an immediate login deserves the same scrutiny as a suspicious email link. Physical placement also matters.
A sticker placed over a legitimate QR code on a parking meter, restaurant menu, package, or office notice can redirect users without changing the surrounding message.
When money or credentials are involved, confirm the destination through the service's official app or a manually entered web address instead.
3. Examine Attachment Names, Icons, and File Types
Attachment inspection begins with the complete filename rather than the icon. A cyberattacker can name a file Invoice.pdf.exe, use a familiar Microsoft Office icon, or hide the real extension with spacing and long filenames. Configure the operating system to show file extensions before evaluating attachments.
When the email client hides the extension, save the file only if the organization's security process permits it, then inspect it in a controlled location without opening it.
Executable extensions are immediate warning signals in an unsolicited message. Files ending in .exe, .scr, or .pif can run code when opened, while archive files such as .zip, .rar, .7z, and .iso can conceal an executable or script inside another layer.
A message claiming that an archive contains an invoice does not make the archive safe. Ask the sender to provide the information through an established business portal, or confirm the request using a phone number obtained independently.
Document files require caution too. Common formats such as .docx, .xlsx, .pptx, and .pdf serve legitimate work, although cyberattackers can weaponize them with malicious links, embedded content, deceptive forms, or requests to enable macros. A familiar extension lowers suspicion while establishing nothing about trust.
A spreadsheet that asks for content to be enabled, a document that requests a password, or a PDF that directs to a login page should be treated as an active phishing attempt until verified.
File compression creates another visibility problem. An archive can contain a filename that appears harmless until extraction, while password-protected archives prevent some email scanners from inspecting their contents.
Never use a password supplied in the same email to unlock an unexpected file. That pairing signals an attempt to bypass automated inspection.
The filename, icon, sender identity, and message context must agree. A shipping notice with an unexpected executable, a vendor invoice sent from a personal account, or a resume containing a script file gains no credibility from a professional logo on the attachment.
Confirm the document through a known contact or existing service portal before downloading or opening it.
4. Preview the Message Without Interacting With Its Contents
Previewing an email normally displays text and formatting already delivered to the email client. Selecting a message to read it differs from clicking a link, scanning a QR code, downloading an attachment, or enabling active content.
That distinction allows employees to inspect the request, identify pressure tactics, and plan verification without following the cyberattacker's path.
Previewing is no absolute safety guarantee. Some messages contain remote images, tracking elements, malformed content, or links that activate through accidental selection.
Keep the reading pane and automatic image loading configured according to organizational policy, and avoid clicking buttons or embedded media while examining the message.
When the email client begins downloading content, opens a browser, launches an application, or displays a security prompt, stop and report it.
Use the preview to record the request and its claimed purpose, then verify it outside the message. For a payment change, contact the vendor through an existing account record. For a password warning, open the service from a trusted bookmark. For an internal request, confirm it through a known phone number or separate workplace channel.
Inspection identifies warning signals. Independent verification determines whether the request deserves action.
When a link, QR code, or attachment fails any of these checks, never test it out of curiosity. Report the message through the organization's reporting process and preserve the email for analysis.
That action gives security teams a usable signal while protecting the next recipient from the same lure. Trust remains unresolved until the sender's name, email address, and domain align.
How to Verify a Suspicious Email Request Through a Trusted Channel
Anyone learning how to check if an email is phishing should pause before clicking, replying, paying, or sharing information. Verification belongs in a trusted channel found independently: a known-good app, an official website typed into the browser address bar, a saved phone number, or a separate contact route to the supposed sender.
A legitimate request can withstand verification. Secrecy, urgency, upfront fees, unexpected prizes, inheritances, rewards, and demands for financial information require extra scrutiny.
1. Stop the Email From Controlling the Next Step
Separate the request from the message that delivered it. Avoid clicking its links, opening attachments, replying to the sender, calling a number in the email, or using any contact detail supplied in the message.
A phishing email keeps the recipient inside the cyberattacker's version of events, where every link, phone number, payment instruction, and supposed support contact reinforces the deception.
Read the request as an instruction and never as proof of identity. Identify what the sender wants, what information or money it requests, how quickly it demands action, and whether it asks for secrecy.
Phrases such as do this immediately, do not tell anyone, and call this number to prevent a loss are pressure tactics. They establish nothing about legitimacy.
Restate the request in neutral terms. Examples include a request to change a supplier's bank details, a request to approve a password reset, or a claim that a prize is available in exchange for a fee.
That reframing makes the decision testable. The change, reset, payment, award, or notice can then be checked outside the suspicious email.
2. Verify Financial and Payment Requests Independently
Financial requests require strict verification because a convincing message can turn a small mistake into an irreversible transfer.
For an invoice, payment-change request, bank-detail update, payroll instruction, wire transfer, gift-card request, or cryptocurrency payment, stop the transaction. Open a known-good accounting, banking, payroll, or vendor-management application instead of the email's button or attachment.
Compare the request with already trusted records: the supplier's profile, previous invoices, approved purchase order, contract, payment history, and existing bank details.
When a message claims that a vendor changed accounts, contact that vendor using a phone number from a signed contract, previous statement, or official company directory. Require confirmation through the organization's payment-control process before releasing funds.
Use two-person verification for unusual transactions. The second reviewer should assess the request independently rather than approve the first person's conclusion.
High-value payments deserve a callback to a known number, with a record of who confirmed the details, when, and from which source. A request to bypass normal approval, split a payment, use a personal account, buy gift cards, or keep the transaction secret is a stop signal.
Apply the same rule to personal banking. Open the bank's official app or type its web address manually, then review alerts, recent transactions, and account messages there. Assistance should come from the number printed on the card or statement rather than the number in the email.
The FTC guidance on avoiding phishing scams advises contacting an organization through a phone number, email address, or website known to be real instead of using information supplied by a suspicious message.
Treat unexpected financial rewards as unverified claims. A prize, inheritance, refund, grant, tax rebate, bonus, or loyalty reward proves nothing about an email's authenticity.
Never pay an upfront processing, release, tax, shipping, or legal fee to receive money or property. Never supply bank-account details, card numbers, Social Security numbers, tax identifiers, or identity documents to claim an unexpected benefit. The FTC's guidance on fake prize and sweepstakes scams states that legitimate prizes require no payment.
3. Verify Password Resets and Account Alerts in the Real Service
Account-reset emails require a different check, because the safest verification happens inside the account itself rather than inside the message.
When an email claims that a password expired, that multifactor authentication failed, that suspicious activity was detected, or that an account will be locked, ignore the embedded link. Open the service through a saved bookmark, known-good mobile app, or manually typed official address.
Inside the account, inspect the security center, notification history, active sessions, recovery methods, and recent sign-in activity. Look for a password-reset event or security alert that matches the email.
When no corresponding event exists, treat the message as suspicious. When an event does exist, initiate the reset from the account's own controls rather than from the email.
Contact internal IT or the help desk through the number, portal, or chat channel already published by the organization, and never through a number in the alert.
Describe exactly what happened to the support team, and provide the message as an attachment or forwarded report only when the organization's process allows it. Security teams can inspect the message safely and determine whether the request belongs to a legitimate campaign.
After a click or a credential entry, act immediately without waiting for certainty. Change the password from the genuine service, end other active sessions, review multifactor authentication settings, and report the incident to the security team.
Switch to a different trusted device when the message led to a software download or a sensitive data entry. Fast reporting gives defenders time to revoke sessions, block related messages, and warn other employees before the campaign spreads.
4. Confirm Employer, Bank, and Public-Agency Messages With Another Person
Impersonation attacks succeed when familiarity is mistaken for verification. A message that appears to come from a manager, chief executive, human resources team, bank, police department, tax authority, court, delivery company, or government agency still needs independent confirmation.
Display names and logos are easy to copy, and a familiar writing style proves nothing about whether an account is genuine.
For an employer request, contact the manager through a separate channel: an in-person conversation, a known phone number, an existing workplace chat, or a new message started from the organization's directory.
Avoid replying in the same email thread when the request involves money, payroll, credentials, confidential data, gift cards, or an unusual purchase. Ask a colleague or supervisor to confirm it independently, especially when the supposed sender claims to be unavailable or discourages involving anyone else.
For a bank message, open the official banking app or use the number on the card or statement. For a government communication, type the agency's official web address manually and locate its published contact information.
Never trust a link that claims to connect to a public agency, even when the message threatens arrest, account closure, deportation, penalties, or immediate legal action. A legitimate agency can explain the notice through its established channels.
Delivery notices also require independent checks. Open the retailer or carrier app directly and inspect the order or tracking record.
Never pay a small redelivery fee, provide a card number, or enter a password through an unexpected delivery link. Cyberattackers use ordinary transactions as camouflage because recipients expect shipping messages and often act before checking the underlying order.
Verification should end with a clear decision. When the trusted source confirms the request, complete it through that source and follow normal approval controls. When the source cannot confirm it, refuse the request, report the email, and preserve the message for investigation.
A short delay and a second person's review protect both the organization and the employee from pressure designed to make caution feel like failure.
For organizations, simulated phishing exercises can rehearse verification behaviors across email, voice, SMS, and executive impersonation scenarios. Employees become faster and more confident when they practice stopping, switching channels, and reporting before a real request reaches a payment desk or privileged account.
Those habits also make suspicious sender identities, addresses, and domains easier to challenge before trust turns into action.
Report and Remove a Suspected Phishing Email Safely
A complete answer to how to check if an email is phishing ends with reporting the message without interacting with it. Avoid replying, clicking links, opening attachments, forwarding casually, or using phone numbers and email addresses supplied inside the message.
Use Gmail, Outlook, or the organization's reporting mechanism, preserve the original evidence when instructed, and delete or quarantine the message only after reporting is complete. A client-by-client walkthrough of how to report a phishing email covers the exact menu paths.
1. Stop Interacting With the Message
Treat a suspected phishing email as unsafe until the organization or email provider classifies it. Replying confirms that the address is active, clicking a link can open a credential-harvesting page, and opening an attachment can trigger malware.
Even a polite response gives the sender another opportunity to build trust.
Never use contact details included in the email to verify the request. A message that appears to come from a bank, supplier, executive, payroll team, or technology provider can contain an attacker-controlled phone number, reply address, calendar invitation, or support link.
When verification is necessary, open the organization's website by typing its known address manually. An alternative is a phone number already stored in the corporate directory, a bank statement, a contract, or an official account portal.
Never forward the message to coworkers as a warning unless the security team specifically instructs it. Casual forwarding can spread a malicious link, expose an attachment to another recipient, and strip or alter technical details needed for investigation.
Use the built-in phishing report function or the organization's designated reporting button instead. A dedicated reporting workflow routes the message to the people and systems responsible for analysis without asking employees to become threat analysts.
After a click, a reply, a credential entry, a file download, or a payment, report that fact immediately, without waiting for confirmation that the message was malicious.
Fast disclosure gives IT or security teams time to revoke sessions, reset credentials, isolate a device, contact a bank, or warn other recipients while the cyberattack is still active.
2. Report Phishing in Gmail
Gmail provides a built-in reporting path that is safer than forwarding a suspicious message. On a computer, open the message, select the three-dot More menu beside the Reply option, and choose Report phishing. In the Gmail mobile app, use the message's More menu and select the phishing reporting option when available.
Google's official Gmail phishing guidance explains that reporting marks the message for phishing analysis and helps Gmail handle similar cyberthreats.
Reporting differs from deleting. Deleting removes the message from the mailbox view while telling Gmail nothing about an attempt to steal information.
Reporting creates a signal that can support filtering decisions for future messages and related campaigns. Gmail can also move the reported email to Spam, depending on the account and reporting path.
When the message contains evidence the employer needs, leave the Trash and Spam folders intact until the security team confirms that preservation is complete.
Corporate Gmail accounts can carry retention, investigation, or legal-hold requirements that do not apply to personal accounts. A security analyst might need the original message, attachment, delivery time, sender details, and full headers to determine whether other employees received the same campaign.
When Gmail has already placed the email in Spam, avoid moving it back to the Inbox simply to inspect it. Report the message from Spam when the reporting option is available, and follow the organization's process.
A suspicious message that resembles a routine invoice, shared document, password reset, or delivery notice still deserves controlled handling.
3. Report Phishing in Outlook
In Outlook on the web, select the suspicious message from the message list, choose Report, and select Report phishing. In many work or school environments, the organization adds a separate reporting button to the ribbon or message toolbar.
Use that button when available, because it can route the message directly to the internal security queue.
Microsoft's current Outlook phishing instructions describe the Report and Report phishing workflow. Outlook's report action can remove the message from the Inbox, although reporting does not always block the sender.
Blocking an address also has limits, because cyberattackers can rotate domains, spoof display names, or send through compromised accounts.
Report the message first, then allow the organization's mail controls to determine whether the sender, domain, URLs, or campaign indicators should be blocked.
A question mark beside the sender image, an unverified sender warning, or a via address can indicate that the visible identity fails to match the authenticated sending path. These indicators call for caution rather than a casual reply seeking confirmation.
A cyberattacker can use a familiar display name while sending from a different domain, so inspect the actual address through Outlook's sender details without clicking links or attachments. In the Outlook desktop client, menu labels differ by version and company policy.
When Report phishing is missing, use the organization's approved reporting button, report the message through the help desk or security portal, and leave the original message intact until instructions arrive.
Avoid improvising by forwarding the message to a public mailbox or deleting it before the security team decides whether headers are needed.
4. Escalate the Message to the Workplace
Workplace escalation is required when the message involves company accounts, money, customer data, payroll, invoices, executive impersonation, credentials, remote access, or a suspicious attachment.
Report it through the approved channel with a short explanation of what happened. Useful examples include an unexpected vendor invoice that was never opened, or a link that was clicked and a password that was entered. That context determines the response priority.
Send the original message with full headers when the security or IT team requests it. Full headers preserve routing, authentication results, message IDs, timestamps, and other signals that a normal forward can omit or modify.
In Gmail, the headers are available through the More menu under Show original. In Outlook, the option is commonly available through message properties or View source, depending on the client. Copy the headers exactly rather than retyping them.
Security teams should receive the message with full headers in several situations. These include a message that targets multiple employees, appears to come from an executive or supplier, requests a payment or password reset, includes a suspicious attachment, or could support an incident investigation.
Analysts also need the original when the message belongs to a suspected business email compromise (BEC) campaign, or when the sender appears to be a compromised legitimate account.
Use the organization's secure reporting channel for confidential material. Never paste sensitive customer records, credentials, payroll data, or regulated information into a public abuse form.
When the message belongs to a wider campaign, the security team can search mailboxes, quarantine matching copies, block indicators, and notify employees who received it.
Reporting also improves the organization's defensive signal. A single employee report can reveal that a message bypassed existing filtering, identify new sender infrastructure, or show that a cyberattacker is targeting a particular department.
Employees provide valuable context that automated filters cannot always see, including whether the request matches a real project, supplier relationship, or executive communication pattern. Reporting is a protective action and never an admission of failure.
Organizations that want a consistent workflow can connect reporting, analysis, and remediation through phishing response and phish triage controls. The objective is to classify the message quickly, remove related copies when necessary, and give employees clear feedback so suspicious messages receive faster reports.
5. Report Consumer and Financial Scams Through Official Channels
Personal email scams should go to the email provider's phishing-reporting function. When the message impersonates a bank, card issuer, payment service, government agency, retailer, or delivery company, contact that organization directly. Use its official website or the number printed on a card or statement, never contact details from the suspicious email.
Escalate immediately when the message requested money, account credentials, tax information, identity documents, gift cards, cryptocurrency, or banking details.
Contact the financial institution's fraud department, ask whether a transfer or payment can be stopped, and change exposed passwords through the legitimate account website. Use a different device or trusted network when the suspicious message led to a download or credential submission.
For consumer fraud, submit the message through the relevant government or law-enforcement reporting portal when appropriate. Retain the original email, headers, screenshots, payment records, and related phone numbers.
Reporting guarantees no recovery, although it creates an account of the campaign and gives investigators information that can connect reports from multiple victims.
6. Delete or Quarantine the Message After Reporting
Delete the message only after the provider or security team has received the report and confirmed that preservation is unnecessary. When the email client offers quarantine, leave the message there rather than moving it between folders or forwarding it.
Emptying Trash or Spam too early can destroy evidence and make it harder to determine who else received the message.
When the message was harmless, reporting it as phishing can create unnecessary filtering noise. Use the correct category, such as spam, phishing, or a false positive, and follow the organization's instructions.
Accurate classification removes the immediate cyberthreat while giving filtering systems reliable signals for future decisions. Sender details, the full email address, and the domain remain the critical evidence for deciding whether a message deserves trust.
How to Check if an Email Is Phishing With Authentication and Full Headers
Learning how to check if an email is phishing requires more than inspecting the display name or hovering over a link. Open the message details, review its authentication results, and compare the visible sender with the technical path the message took.
Treat authentication as evidence about delivery. It establishes nothing about whether the sender, account, or request is trustworthy.
1. Open Gmail Authentication Details and Full Headers
Gmail provides a quick authentication view ahead of the complete header. Open the message, select the three-dot menu beside the Reply button, and choose Show original.
The page displays the sender's authentication status and the full raw header, including Authentication-Results, Return-Path, Received, From, Reply-To, and Message-ID fields.
Start with Authentication-Results and look for entries such as spf=pass, dkim=pass, and dmarc=pass.
SPF checks whether the sending server is authorized to send mail for the envelope domain, usually reflected in the Return-Path. DKIM checks whether the message carries a valid cryptographic signature associated with a domain. DMARC checks whether SPF or DKIM passed and aligned with the domain shown in the visible From address.
Google's 2025 email sender guidelines explain that DMARC alignment requires the authenticating domain to match the domain in the message's From header. A fuller explanation of how DMARC prevents domain spoofing covers policy modes and aggregate reporting.
Use these fields as separate signals rather than treating a passing result as a green light:
- From shows the identity presented to the recipient. Compare its domain with the organization named in the message, and inspect lookalike spelling, added subdomains, and unexpected free-mail domains.
- Return-Path identifies the envelope sender used for delivery. A different domain is not automatically malicious, because newsletters and third-party services often send on another organization's behalf, although the mismatch requires context.
- Received lines record the servers that handled the message. Read them from the bottom upward to identify the earliest visible sending server, then check whether the route fits the claimed sender and normal mail flow.
- SPF, DKIM, and DMARC results describe technical authorization only. They establish nothing about content safety, account compromise, or abuse of an approved domain.
- Reply-To can redirect responses to a different address. Treat an unexpected change as a warning, especially when the message requests payment, credentials, confidential data, or a new bank account.
A passing result means the message was authorized or signed according to the relevant domain controls. A cyberattacker using a compromised legitimate mailbox can still pass authentication, while forwarding services or mailing lists can cause legitimate messages to fail.
A failure should trigger verification through a trusted channel rather than an instant conclusion.
2. Read Outlook Sender-Verification Warnings as Risk Signals
Outlook can display a sender-verification warning when message headers appear suspicious. Treat the warning as a prompt to investigate rather than a complete verdict. Avoid replying, opening attachments, or following links while the warning remains unresolved.
For a deeper review in Outlook, open the message properties or view its internet headers, depending on the version. Search for Authentication-Results, Received-SPF, DKIM-Signature, DMARC, Return-Path, and Reply-To.
An external-sender label provides useful context while proving nothing about malice. A legitimate supplier can be external, and a compromised internal account can send a dangerous message without any external warning.
When a request involves money, credentials, payroll, legal documents, or sensitive data, verify it using a known phone number, an established chat thread, or a new message addressed to the person's saved contact. Never use contact details supplied in the suspicious email.
3. Confirm Organizational SPF, DKIM, and DMARC Controls
Organizations should publish SPF records containing every approved sending service, enable DKIM signing for each sending domain, and publish a DMARC policy that gives security teams visibility into alignment failures.
Review DMARC aggregate reports for unknown senders, lookalike infrastructure, and legitimate services sending without authorization.
Authentication controls work best when paired with clear procedures. Define which domains and vendors can send invoices, password resets, and executive communications.
Require out-of-band verification for high-impact requests, and train employees to report suspicious messages with the original headers attached. A phishing response process built around reporting and triage gives analysts the evidence needed to investigate quickly.
Header analysis is most valuable when it changes behavior. When authentication passes and the request still looks unusual, pause and verify.
When authentication fails, preserve the message, report it, and let the security team determine whether forwarding, a vendor configuration, or impersonation caused the failure. The sender's address and domain provide another critical signal, because many phishing messages reveal their real intent there.
How to Check a Suspicious Email on an iPhone or Android Device
Knowing how to check if an email is phishing on a mobile device starts the same way: stop interacting with the message, inspect the sender and destination without opening anything, and report it through the official mail app.
Open known-good websites separately instead of following email links, avoid downloading attachments, and contact IT before acting on requests involving payments, passwords, or sensitive data. Mobile screens hide technical details, so uncertainty is a reason to escalate rather than guess.
1. Pause Before Tapping Links, Attachments, or QR Codes
Mobile phishing succeeds when a small screen turns a risky decision into a reflex. Avoid replying, tapping a button, downloading a file, or calling a phone number in the message until the request has been verified through a trusted channel.
A message that creates urgency, threatens account closure, or asks for secrecy deserves the same pause whether it appears in Apple Mail, Gmail, Outlook, or a text-message app.
When the mail app supports a link preview, press and hold the link without opening it. Read the previewed destination carefully, including the domain and any unusual spelling.
A shortened URL, a long string of random characters, or a domain that merely resembles the organization's name is a warning signal. Never copy the link into a browser to investigate it, and use a known-good website or official app instead.
Use the same restraint with attachments. Avoid downloading invoices, login forms, ZIP files, documents, or mobile configuration profiles from an unexpected message.
When the email appears to come from a colleague, vendor, or executive, verify the request through an already trusted phone number or chat thread.

2. Check the Sender in the iPhone Mail App
On an iPhone, expand the sender details by tapping the name or address at the top of the message. Review the complete email address rather than the display name alone. Cyberattackers can label a message Payroll, Apple Support, or an executive's name while sending it from an unrelated domain.
Never use the message's links to verify the account. Open Safari and type the organization's known website manually, use a saved bookmark, or launch the official app, then check for account alerts there.
When the request concerns a wire transfer, invoice, password reset, or multifactor authentication, call the known contact or follow the organization's verification procedure.
Use Mail's reporting option when available, such as Report Junk or Move to Junk. When the organization provides a dedicated reporting button in the mobile mail app, use that workflow rather than forwarding the message manually.
A phishing-reporting and triage workflow gives IT the original message context needed to classify the email and remove related messages.
3. Check the Sender and Report It on Android
Android mail apps use different menus, although the core inspection stays the same. Tap the sender name, expand the details menu, and view the full address.
Look beyond the name before the @ symbol. The domain after it identifies the sender's email service, and a lookalike domain can expose an impersonation attempt.
In Gmail, Outlook, or another approved app, use the message menu to choose the phishing or junk-reporting option. Avoid deleting the message first when the IT team needs headers, attachments, or the original sender information.
When the app offers no reporting function, leave the message untouched and contact IT through the organization's established help desk or security channel.
4. Treat Mobile QR Codes as Links
QR codes make no destination safer. A printed code, an image attachment, or a code displayed on another screen can open a phishing website without showing the full address first.
Never scan an unexpected QR code that requests a login, payment, package fee, or account verification.
After an accidental scan, close the page without entering information, and never approve a login prompt or provide a password. Open the organization's official app or type its verified website separately, then change the affected credentials and notify IT if any data was entered.
5. Escalate When the App Hides Technical Details
Mobile apps often conceal full headers, authentication results, and other technical evidence. That limitation makes the message no safer, and it puts the inspection in the security team's hands.
Capture a screenshot only when policy allows it, preserve the original email, and report the message before interacting with it.
Employees provide the strongest early-warning signal when they report uncertainty quickly. IT can inspect the message, warn other recipients, and confirm the request through a trusted channel before a single tap becomes credential theft or a payment incident.
A clear reporting habit turns a hidden mobile warning into an actionable security signal.
Recognize Spear Phishing, Whaling, Quishing, and AI-Generated Messages
Knowing how to check if an email is phishing means comparing the request, context, identity, and destination instead of relying on visible mistakes.
Ordinary phishing sends a broadly distributed lure, while spear phishing targets a specific person, role, or organization with details designed to build credibility. Whaling applies the same impersonation pressure to executives or employees who control money, credentials, or sensitive information.
QR-code phishing, vishing, and smishing extend the deception through QR codes, voice calls, and text messages. The safest test therefore depends on the request and channel rather than the format alone.
How Does Targeted Impersonation Differ From Ordinary Phishing?
Targeted impersonation starts with context. Cyberattackers use open-source intelligence (OSINT) such as company announcements, job titles, conference appearances, social profiles, and public vendor relationships to make a message fit the recipient's work.
An email that references a real project, familiar supplier, or current executive absence earns more scrutiny rather than more trust.
Spear phishing usually targets a department or individual with a plausible operational request. A finance employee might receive revised banking instructions from a supposed supplier, while an IT administrator might receive a password-reset request that mentions a real software rollout.
Whaling aims higher. It often imitates a CEO, CFO, board member, or outside counsel while requesting a wire transfer, payroll change, confidential file, or urgent approval. A closer look at the main spear phishing variants, including BEC and whaling maps how each one is built.
Personalization proves nothing about identity. A known name, accurate job title, or legitimate project reference can come from public information or stolen correspondence.
CISA's phishing guidance recommends treating unexpected requests for information, links, attachments, or urgent action as signals to stop and verify. Use a trusted channel already on file, such as a known phone number or a new message started from the company directory, before complying.
QR-code phishing, or quishing, hides the destination inside an image that can appear in an email, PDF, poster, or shared document. The code can send a user to a counterfeit sign-in page or a malicious download.
Vishing uses a phone or voice message to create pressure, while smishing uses SMS or another messaging service. The inspection method changes by channel, although the control stays the same: never use the contact details or link supplied by a suspicious message to verify the request.
How Can AI-Generated Phishing Emails Be Recognized?
AI-generated phishing emails remove many traditional warning signs. Clean grammar, polished formatting, and fluent wording no longer establish legitimacy, because generative tools can produce professional messages in seconds.
Spelling mistakes remain useful evidence when they appear, although their absence makes no email safe. A detailed breakdown of the red flags that still expose AI phishing emails covers the signals that survive.
Focus on whether the message makes sense in context. Warning signs include a robotic or unusually formal tone, vague transaction details, invented policy names, contradictory deadlines, an unusual approval path, or a request that conflicts with established procedure.
An unusually personalized message can also be suspicious when its details feel assembled rather than naturally connected to the recipient's work.
The strongest test is behavioral. Identify what the sender wants, why the request arrived now, what identity evidence supports it, and where the link or attachment leads.
Preview the destination without opening it, inspect the actual domain, and navigate independently to the known service instead of using the message's button. Requests involving money, credentials, sensitive data, or payment instructions need independent confirmation even when the email looks flawless.
AI-generated social engineering also reaches beyond text. In 2024, an employee at the Hong Kong office of Arup, a British multinational engineering firm headquartered in London, approved transfers totaling roughly 25 million dollars after cyberattackers used deepfake video personas during a conference call, according to The Guardian's 2024 report.
That same year, a person appearing and sounding like Ukraine's former foreign minister contacted U.S. Sen. Ben Cardin on Zoom. Cardin recognized that the questions were out of character and ended the call, according to The Guardian's report on the incident. Familiar appearance and voice cannot replace independent verification.
Why Do Cross-Channel Attacks Require a Different Check?
Cross-channel attacks combine email, phone, SMS, collaboration tools, or video to make one fraudulent request appear independently confirmed. A cyberattacker might send an invoice by email, follow with a text claiming the matter is urgent, and then call while impersonating a manager.
Each contact reinforces the previous one, although all of them can originate from the same operation.
Treat a channel change as a reason to pause. Compare the request against a known workflow, contact the supposed sender through an independently sourced method, and report the original message alongside related calls or texts.
Phishing simulations covering email, voice, SMS, and deepfake video give employees practice recognizing the same manipulation across channels before a real request demands a fast decision.
Employees do not need to identify the cyberattacker's technology perfectly. The safer response is to recognize an unusual request, slow the transaction, verify the identity, and report the signal so the security team can investigate before trust becomes financial or operational damage.
Apply the Checklist to Common Phishing Email Scenarios
Applying how to check if an email is phishing in practice means comparing an email's visible signals with the action it demands. A legitimate message supports verification, while a phishing email creates pressure and steers the recipient toward an untrusted link, attachment, reply, or payment.
Password-reset emails usually target credentials, while invoice changes and executive requests target money or authority. Every scenario requires the same response pattern: stop, verify through a trusted route, report the message, and avoid interacting with the original content.
Credential Theft: Password-Reset Requests
A password-reset request deserves immediate scrutiny, because cyberattackers use familiar account brands and urgent language to capture usernames, passwords, and MFA codes.
Signals include an unexpected reset, a deadline threatening account lockout, a link whose destination fails to match the organization's known login domain, or a request to enter credentials after clicking from email.
Never use the message's link or phone number. Open a saved bookmark, type the service's address manually, or contact the help desk through its published directory listing.
When no reset was requested, change the password through the legitimate portal, review active sessions, and notify the security team. A phishing simulation and response program can rehearse this decision before employees face a real credential lure.
Payment Fraud: Invoices, Bank Changes, and Secret Executive Requests
Payment fraud emails exploit routine business workflows, although the strongest signal often appears in the requested change rather than the writing style. An invoice with new bank details, an unfamiliar supplier account, a request to bypass procurement, or an executive asking for secrecy should be treated as a high-risk transaction.
Verify the change using a known phone number, an established vendor contact, or a separate internal channel, and never reply to confirm account details through the suspicious thread.
Require a second approver for unusual transfers, preserve the original message, and report it to security and finance. After money has already moved, contact the bank's fraud team immediately and follow the organization's incident-response procedure.
Malware Delivery: Delivery Notices, Government Alerts, and Repeated Messages
Malware delivery often disguises itself as a missed package, tax notice, court document, benefits update, or security warning.
Signals include an unexpected attachment, a request to enable macros or browser notifications, a compressed file, a QR code, or a demand to install software to view a document. A government agency or carrier gains no trustworthiness from a logo in the message.
Check the notice through the agency's or carrier's official website, using an address entered manually. Avoid opening the attachment, scanning the QR code, or calling the number in the email.
Report the message through the organization's approved reporting channel. After an accidental interaction, disconnect from the network if policy directs it and contact IT without deleting evidence.
Report multiple identical unexpected messages together, because they can reveal a coordinated campaign. Avoid forwarding them widely or warning colleagues by replying to the sender.
| Scenario | Evidence to Check | Risk | Next Action |
|---|---|---|---|
| Password reset | Unexpected request, urgent deadline, mismatched login domain | Credential theft and MFA capture | Use a saved bookmark, verify with IT, and report |
| Invoice or bank change | New payment details, unusual supplier request, altered approval path | Wire fraud and business email compromise (BEC) | Confirm through a known channel, involve finance, and report |
| Executive secrecy request | Pressure, confidentiality demand, unusual payment or data request | Authority-based fraud | Call the executive using a known number, require approval, and report |
| Delivery or government notice | Unexpected attachment, QR code, install request, threat of penalty | Malware or credential theft | Visit the official website manually, avoid opening the message, and report |
| Repeated identical messages | Same wording, sender pattern, sudden volume | Coordinated phishing campaign | Report samples through the approved channel and avoid forwarding |
Reporting is the correct action even when a message turns out to be legitimate. Analysts need the sender, original headers where available, the timestamp, and any action already taken to determine whether other inboxes require review.
The safest response is fast escalation before a suspicious message becomes a credential, payment, or malware incident. Perfect judgment on the first pass is never the standard.
Use Email and Link Checker Tools Carefully When Checking if an Email Is Phishing
When applying how to check if an email is phishing, automated checkers and independent verification serve different purposes. Automated tools compare messages, links, files, and login pages against known cyberthreat signals, while independent verification tests whether the request makes sense in context.
Browser warnings, email filters, malware protection, and reputation services can identify technical danger faster than a person working alone. A clean technical result still proves nothing about the sender's intent.
How to Use Email and Link Checkers Safely
Built-in defenses provide useful signals and never final verdicts. Email filtering can quarantine known malicious messages, browser warnings can block suspicious destinations, malware protection can inspect attachments, and reputation services can flag domains or URLs associated with abuse.
Treat a warning as a stop sign, and treat the absence of a warning as permission to investigate further rather than proof of safety.
Online phishing-checker tools create a separate privacy risk. Uploading a complete email can expose customer names, invoice details, internal addresses, authentication links, contract terms, or confidential attachments to a third party.
Never submit sensitive messages to a public checker unless the organization has approved the service and confirmed how it stores, processes, and deletes submitted data. Where possible, inspect the sender domain, link destination, headers, and message structure locally or through an approved security workflow.
Checkers also produce false positives and false negatives. A newly registered domain can lack enough reputation history to trigger a warning, while a compromised legitimate website can appear trustworthy until a cyberattacker adds a malicious page.
Reputation services often evaluate age, prevalence, and prior abuse rather than the intent behind the current message.
Authentication results such as SPF, DKIM, and DMARC show whether infrastructure authorized the message, although they establish nothing about honesty. A criminal using an authenticated lookalike domain can still send a convincing phishing email.
What Signals Do Password Managers and SSO Provide?
Password managers provide a practical behavioral signal, because they typically recognize the saved domain before filling credentials. When a manager refuses to autofill on a page that resembles a familiar service, stop and inspect the address.
That mismatch often indicates a lookalike domain, a redirected page, or a login page hosted somewhere unexpected. It remains inconclusive, because the account may never have been saved, the service may use multiple legitimate domains, or the manager may not support the site's login flow.
Single sign-on adds another useful control by directing employees to an established identity provider instead of an email-linked credential page. Use the organization's normal application portal or a known bookmark rather than clicking the message.
NIST's 2025 digital identity guidance distinguishes phishing-resistant authentication from methods that still depend on a person recognizing the cyberattack, so SSO alone makes no login prompt automatically safe. Unexpected MFA prompts, unfamiliar consent screens, or requests to approve a sign-in should still be reported.
Why No Single Checker Replaces Independent Verification
Independent verification answers the question automated tools cannot: was this request actually expected and authorized? A message can pass technical checks and still request an urgent wire transfer, payroll change, password reset, sensitive file, or gift-card purchase.
Verify high-impact requests through a separate trusted channel, such as a known number from the company directory or the service opened from a saved bookmark. Never use the phone number, reply address, or link supplied in the suspicious message.
The safest workflow combines signals without allowing any single one to make the decision. Review the warning status, inspect the true destination, consider whether the request fits normal business behavior, and confirm unusual actions independently.
When uncertainty remains, report the message through the organization's approved phishing response workflow instead of testing the link. That habit turns employees into an active detection layer and keeps the sender, email address, and domain as the critical evidence to inspect before trust is extended.
What to Do After a Phishing Email Is Clicked, Opened, or Used to Submit Information
Knowing how to check if an email is phishing matters less once a click has already happened. After a phishing email is clicked, opened, answered, or used to submit information, act quickly and record exactly what happened.
Stop communicating with the sender, notify the employer or IT team, and secure accounts from a known-clean device. Contact the bank immediately when payment data or money was involved.
The response depends on whether content was merely opened or whether credentials, personal information, or payment details were exposed.
1. Stop the Interaction and Notify the Right People
Stop interacting with the suspected phishing email. Avoid replying, clicking additional links, opening more attachments, or calling a phone number in the message.
Preserve the original email, sender address, timestamps, links, attachment names, screenshots, and confirmation pages. Investigators use those details to identify the cyberattack and contain related messages.
When the message reached a work account, report it through the organization's approved process and contact IT or security directly. State clearly whether a link was clicked, data was entered, a file was downloaded, a reply was sent, or a payment was approved.
CISA guidance on recognizing and reporting phishing advises reporting suspected phishing and changing passwords when account information may have been exposed. Leave the message in place until the security team confirms that the evidence is no longer needed.
2. Treat Clicked-but-No-Data Cases as Reduced Risk
Clicking a link without entering information is generally less serious than submitting a password or payment number, although it still requires a check. Close the fraudulent page, avoid downloading anything else, and tell IT exactly what was opened.
When the device displays unusual pop-ups, redirects, new extensions, security warnings, or unexpected login prompts, stop using it and contact IT immediately.
On a managed work device, disconnect from Wi-Fi or the network only when IT or the incident-response procedure directs it. Disconnecting can limit an active infection, although doing so without coordination can remove useful forensic evidence or interrupt containment steps.
IT should check browser downloads, extensions, endpoint alerts, and authentication logs, then run an approved security scan.
On a personal device, update the operating system and security software, run a full scan, and remove identified malicious software before resuming sensitive activity. Previewing an image or email proves nothing about device safety.
Continue monitoring for account alerts, unfamiliar browser sessions, password-reset messages, and follow-up calls that reuse details from the original interaction.
3. Secure Exposed Credentials or Payment Data
Credential exposure requires immediate account protection. From a known-clean device, change the compromised password and every other password that reused it. Start with email, because inbox access can enable password resets for banking, payroll, cloud storage, and social accounts.
Sign out of all sessions, revoke unfamiliar sessions and connected applications, verify recovery email addresses and phone numbers, and enable MFA with an authenticator app or security key where available.
Review the FTC account-recovery guidance for steps that include updating security software, scanning the device, and checking account settings after suspected compromise.
After entering payment-card, bank, payroll, or cryptocurrency information, contact the financial institution using the number on its official website, card, or statement rather than anything in the phishing message.
Ask the bank or card issuer to block or replace the exposed instrument, review pending transactions, and document the fraud report. When money was transferred, request a recall or reversal immediately.
A reply containing personal or company information should go to the employer even when no password was disclosed. The reply confirms that the address is active and can trigger targeted spear phishing, vishing, smishing, or business email compromise (BEC) attempts.
Security teams can use a phish triage process to classify reports and remove related messages before additional employees interact with them.
4. Monitor Accounts and Devices on a Defined Timeline
Monitoring turns a one-time reaction into containment. Review email forwarding rules, sent messages, deleted items, login history, MFA changes, payment activity, new payees, shipping addresses, and password-reset notices immediately.
Check again daily for at least two weeks, followed by weekly reviews for the next month, or longer when IT, the bank, or an identity-theft specialist advises it.
Keep the phishing email and related alerts in a dedicated evidence folder. Ask IT to monitor the account and device for several weeks, especially after an attachment was opened or credentials were submitted.
Watch for follow-on abuse, including fake help-desk calls, invoice changes, password-reset prompts, executive impersonation, and messages that reference the original incident.
Fast reporting gives employees and security teams the signal needed to contain the next attempt before it becomes a larger compromise. Persistent monitoring matters because cyberattackers often return through a different channel after the original message is reported.
Build Phishing Awareness Training Into Organizational Resilience
Knowing how to check if an email is phishing protects one inbox. Organizational resilience determines whether a single mistake becomes credential theft, a fraudulent payment, or a broader incident.
Phishing awareness training works when reporting is simple and layered controls support employee judgment. Teams then surface suspicious messages faster, contain them sooner, and turn training into measurable behavioral change.
How Does a Reporting Culture Reduce Phishing Risk?
A strong reporting culture turns employees into an early-warning network. Every employee needs one obvious reporting route, clear instructions for suspicious messages, and immediate reassurance that reporting a mistake is the correct action.
When someone clicks a link, enters credentials, or opens an attachment, the response should begin with containment and coaching rather than blame.
Organizations also need a defined process after every report. Security teams should acknowledge submissions, remove confirmed malicious messages from other inboxes, reset exposed credentials, and explain the outcome when appropriate.
That feedback loop shows employees which signals mattered and makes the next report more likely. CISA's guidance directs organizations to explain both how and to whom employees should report suspicious messages, because unclear procedures delay response.
Leadership should make the standard explicit: reporting a suspicious email is a successful security action, even when the message proves safe. That expectation removes the fear that causes employees to delete evidence, stay silent, or investigate alone.
It also gives analysts better data about the lures, departments, and business processes cyberattackers are targeting.

How Should Organizations Design and Measure Phishing Simulations?
Phishing simulations work when they rehearse decisions employees actually face rather than functioning as gotcha exercises.
Finance employees should practice vendor invoice and business email compromise (BEC) requests, while executive assistants should rehearse calendar changes, payment requests, and executive impersonation. Role-based scenarios build recognition skills without treating employees as interchangeable recipients of generic content.
Simulation design should reflect the channels cyberattackers use. Email tests can be paired with vishing, smishing, QR code phishing, and deepfake scenarios when those channels match the organization's exposure.
The goal is to measure whether employees pause, verify unusual requests, report suspicious activity, and recover quickly after an error. Maximizing click rates serves no purpose.
Completion alone cannot show resilience. Track the signals that connect employee behavior to operational response:
- Reporting rate: Whether employees recognize and escalate suspicious messages.
- Time to report: How quickly a signal reaches the security team.
- Repeat susceptibility: Which scenarios require additional coaching, without shaming the employee.
- Remediation time: How quickly the organization removes malicious messages or resets exposed access.
- Risk reduction: Whether targeted training changes behavior across successive simulations.
A modern security awareness training program should use these outcomes to adjust training paths. An employee who reports quickly but repeatedly struggles with invoice fraud needs a different intervention from an employee who never reports suspicious messages.
Short, targeted follow-up training after a failed simulation creates a more useful learning moment than waiting for an annual course.
Which Technical Controls Should Support Employee Judgment?
Technical controls reduce the number of dangerous messages employees must evaluate, although they never replace judgment. Configure email filtering to identify known malicious senders, suspicious URLs, malware, spoofed domains, and abnormal attachment behavior before messages reach inboxes.
Use attachment and link scanning alongside domain authentication controls such as SPF, DKIM, and DMARC to make unauthorized use of a company domain harder to trust.
These controls have limits. A message from a compromised legitimate account, a newly registered domain, or a trusted supplier can pass basic technical checks.
Employees therefore need a visible reporting mechanism, and analysts need a workflow that connects reports to message analysis, credential protection, and organization-wide remediation.
A phish triage workflow can classify reported messages, guide analysts toward consistent decisions, and remove confirmed cyberthreats from other inboxes. The operational value comes from connecting the report to action rather than leaving it as an isolated alert.
Resilience emerges when each layer covers another layer's blind spots. Filtering blocks familiar cyberthreats, authentication reduces domain spoofing, malware protection inspects payloads, simulations rehearse decisions, and supportive response converts mistakes into faster recovery.
Review these signals together each quarter so leadership can measure whether employees detect, report, and recover from phishing more effectively as cyberattacker tactics continue to change.
Frequently Asked Questions About Phishing Emails
Can Opening or Previewing an Email Alone Cause a Phishing Compromise?
Opening or previewing an email usually causes no compromise on its own. Risk arrives with clicking links, opening attachments, loading remote content, or following a request. CISA advises avoiding links and attachments in suspicious messages.
Previewing is safest when nothing embedded is touched: no replies, no downloads, no QR-code scans, and no phone numbers taken from the message. When the email appears suspicious, report it through the mail app or workplace process, preserve it if security staff request evidence, and delete or quarantine it.
A known sender remains unverified whenever the request is unexpected, which is why checking whether an email is phishing starts with the request rather than the name on it.
What Should Someone Do After Clicking a Phishing Link Without Entering Information?
After a click with no information entered, close the page, report the message, and check the device for signs of compromise. Never return to the page or download anything it offers.
On a work device, notify IT or security immediately so they can review browser, endpoint, and account activity. Run the approved security scan, install pending updates, and change any password that was entered.
CISA recommends reporting and deleting phishing messages and changing passwords immediately when an account may be exposed. Record the time, device, message, and destination before removing evidence.
What Should Someone Do After Entering a Password or Payment Details Into a Phishing Site?
After a password or payment details reach a phishing site, act immediately from a known-clean device: change the exposed password, revoke active sessions, enable MFA, and contact the bank or card issuer using an official number.
Change every account that reused the password, beginning with email, banking, work, and password-manager accounts. Ask the financial institution to block or replace the card and investigate unauthorized activity.
Notify the employer when a work account or device was involved, and preserve the message and URL for responders. NCSC guidance specifically directs people to change reused passwords after sharing sensitive information.
How Can Someone Check Whether Accounts Were Accessed After a Phishing Response?
Check each account's security or login-activity page, active sessions, password-reset notices, MFA changes, recovery details, forwarding rules, and sent, deleted, or archived messages. Look for unfamiliar devices, locations, times, applications, or email rules, and review financial transactions for unauthorized activity.
Sign out of every unrecognized session, change the password from a clean device, and contact the provider through its official support channel. NCSC recommends changing passwords on accounts that used the same exposed credential.
Workplace security teams should search centralized logs when a business account was involved, because a clean inbox establishes nothing about whether a session occurred.
How Long Should Accounts and Devices Be Monitored After a Suspected Phishing Incident?
Monitor affected accounts daily and review financial statements through the next full billing cycle. Device monitoring should stay active until security checks and any employer investigation are complete.
Continue reviewing high-value accounts periodically for several months when credentials, identity information, or payment data were exposed. Set transaction alerts, login notifications, and MFA prompts so unusual activity becomes an immediate action signal.
Retain the original message, timestamps, account alerts, and support case numbers. NCSC incident guidance calls for prompt password changes after sensitive information is shared.
Measure and Improve Phishing Resilience Across Every Attack Channel
Phishing now reaches employees through email, voice, SMS, and deepfake impersonation, which makes isolated email checks insufficient. Knowing how to check if an email is phishing covers one channel, while measurable resilience covers all of them.
Adaptive Security gives organizations visibility into risky behavior and targeted reinforcement across those channels. Take a self-guided tour of Adaptive Security's human-risk platform.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Get started with Adaptive Security
Related articles

Lookalike Domain Phishing: How to Detect Impersonating Domains and Reduce Credential Theft and Fraud

Spear Phishing Incident Response: A Complete Playbook for Containing Targeted Attacks Before They Spread

Interactive Phishing Simulation Tools: The Complete Guide for Testing Email, Voice, and Deepfake Threats
Get started