563 Recognizing Phishing and Suspicious Messages | Recognizing a Suspicious Email or Message, and What to Do After Responding to a Phishing Message


Phishing uses messages that pretend to be trustworthy so that a person will click, open, pay, reveal information, or sign in somewhere unsafe. The message may arrive by email, text, social platform, or another communication service, and it may imitate a business, public service, coworker, friend, or family member.
This section develops a careful way to handle suspicious messages. It covers sender checks, links and attachments, requests for passwords or personal details, independent verification through another channel, and practical steps after someone has already responded.

563.1 Recognizing a Suspicious Email or Message

A suspicious message often contains details that do not fit the relationship or situation. It may arrive unexpectedly, use a slightly altered sender address, ask for an unusual action, or create pressure to click, pay, sign in, or reveal information. Poor spelling can be a warning, but well-written phishing messages are common too, so appearance alone is not enough.
Look at the request rather than only the design. A message that copies a bank logo can still be false if it asks for a password or directs the reader to an unfamiliar web address. A message from a friend’s real account may also be unsafe if that account has been taken over. The safest reaction to doubt is to pause before interacting with the content. Do not reply, open the attachment, or follow the link until the claim can be checked independently. Suspicion is a reason to verify, not proof that the sender is dishonest. Even a genuine message can be handled more safely through a known route when the request involves valuable access or information.

563.2 Checking Who Really Sent a Message

The name shown on a message is not reliable proof of who sent it. Email display names can be copied, phone numbers can be spoofed in some systems, and social accounts can be imitated or taken over. A message may therefore look as if it comes from a known person or organization while the underlying account or address tells a different story.
Check the full sender information where the service makes it available. Compare the address or username with previous genuine contact, and be cautious about small spelling changes, extra characters, or an unfamiliar domain. Context matters as well: a supplier who normally sends invoices one way may deserve verification if payment details suddenly change. When the request is sensitive, contact the person or organization through a trusted number, saved contact, official app, or known website. The check should not rely on contact details supplied inside the doubtful message itself. For a person you know, a brief call can settle the question without further interaction.

563.3 Being Careful With Links and Attachments

Links and attachments can turn a harmless-looking message into a security problem. A link may lead to a fake sign-in page, a fraudulent payment page, or a site that tries to install unwanted software. An attachment may contain harmful code or a document designed to persuade the reader to enable unsafe features. The file name or visible link text can be made to look familiar even when the destination is different.
Before opening anything unexpected, consider whether the sender had a reason to send it and whether the message fits the normal conversation. On devices that show the destination address, inspect it without opening and look for misspellings or unrelated domains. For important services, it is often safer to use a saved official app or enter a web address you already trust. Unexpected files from known contacts should still be confirmed if the account could have been compromised. Curiosity is not a good reason to test a suspicious attachment on a device that holds valuable information.

563.4 Recognizing Requests for Passwords or Personal Details

Requests for passwords, verification codes, banking details, identity numbers, or other sensitive information deserve special caution because these details can give direct access to accounts or support later fraud. A message may claim that the information is needed to confirm identity, prevent account closure, release a payment, or fix a technical problem. The explanation can sound reasonable while the method of asking is unsafe.
Legitimate services have their own procedures, and many do not need a customer to send a password or one-time sign-in code to another person. Instead of answering the message, go to the organization through a known route and check whether any action is actually required. Pay attention to requests that combine secrecy or urgency with sensitive information. Even when a message contains correct personal details, that does not prove it is genuine; such information may have been obtained from public sources, old records, or another breach.

563.5 Checking a Message Through Another Channel

A doubtful message can often be checked without using any link, phone number, or reply option inside it. If a message claims to come from a bank, employer, delivery company, public service, friend, or family member, contact that source through a channel already known to be genuine. This might mean opening the official app, typing the organization’s website address, using a saved phone number, or speaking to the person directly.
The second channel should be independent of the suspicious one. Replying to the same message and asking “Is this really you?” may simply give the attacker another chance to answer. For a changed payment instruction, confirm the details with the usual contact before sending money. For an account warning, check security notices inside the account itself. Independent verification separates the truth of the claim from the appearance of the message. It is especially useful when the message asks for money, credentials, or an urgent change to normal arrangements.

563.6 What to Do After Responding to a Phishing Message

Responding to a phishing message does not always cause the same kind of harm, so the next step depends on what happened. Simply replying may confirm that an address is active, while opening a link, entering a password, sending identity details, downloading a file, or making a payment can create more serious exposure. Write down what was shared or opened while the details are still clear.
If a password was entered, change it through the real service and review active sessions and recovery settings. If the same password was used elsewhere, protect those important accounts too. A downloaded file may require the device to be checked before sensitive use continues. Financial information or payments may require rapid contact with the relevant bank or payment provider. Keep the message and other evidence instead of deleting everything immediately. A calm, specific response is more useful than changing unrelated settings without knowing what was exposed.