Security

How to Recognize Phishing Emails, Texts and Fake Websites

Spot phishing pressure tactics, inspect links safely and protect your accounts after clicking or sharing information.

Glowing green security shield protecting connected devices and data
Original concept artwork created for this Circuit Compass guide.

Spot phishing pressure tactics, inspect links safely and protect your accounts after clicking or sharing information. Use this practical checklist as a starting point and confirm model-specific instructions with the service or device maker.

Pause when a message creates urgency

Phishing messages often demand immediate action: a parcel fee, locked account, tax refund, job offer or warning from a manager. Urgency is a reason to slow down. Do not call the number or use the link provided in the same message.

Open the known official app or type the organization’s address yourself. If the alert is real, the account should usually show it there.

Check the sender and destination separately

Display names can be copied. Expand the full email address and compare the domain letter by letter. On a computer, hover over a link without clicking; on mobile, press and hold only if the interface previews the URL without opening it. Watch for misspellings, unexpected subdomains and URL shorteners.

HTTPS encrypts a connection but does not prove the site is honest. A fake site can also have a padlock.

Treat requests for secrets as hostile

Legitimate support should not ask for your password, one-time code, recovery code or remote access through an unexpected conversation. Payment requests involving gift cards, cryptocurrency or a sudden bank-detail change require independent verification.

Call a known number from a statement, card or official website. For workplace payments, confirm through a second communication channel.

Handle attachments and QR codes carefully

Unexpected documents can lead to credential pages or malware. Confirm with the sender through a separate channel before opening. A QR code is simply another way to hide a destination; preview the address and apply the same checks as any link.

Keep the operating system, browser and security tools updated so known malicious files have fewer opportunities.

Respond quickly after a mistake

If you entered a password, change it from a trusted device and change any reused password. Sign out other sessions, enable multifactor authentication and review recovery details and forwarding rules. Contact the bank immediately for payment information.

Report the message through the service’s phishing tool and tell affected contacts. If malware may have run, disconnect the device from sensitive activity and use official support or qualified help.

References and further reading

These primary resources support the guidance and provide current, service-specific instructions.

Found something that needs updating? Send a correction with the page URL and supporting source.