What you will learn
- Identify high-risk request patterns without relying on grammar.
- Separate display names from actual sender addresses.
- Recognize urgency, secrecy and payment manipulation.
- Verify a request without replying to the suspicious message.
What you need
- A suspicious example or a harmless training message.
- Access to a known contact method for the claimed sender.
Start with context, not appearance
The FTC warns that phishing messages commonly invent an urgent story and ask the recipient to click a link, open an attachment or provide personal or financial information.
CISA lists recognizing and reporting phishing as one of the core actions that reduce common online risk.
Ask whether you expected the message, whether you normally communicate this way and whether the requested action matches an established process. A real logo and familiar signature can be copied in seconds.
Inspect identity beyond the display name
Expand the full sender address and reply-to address. In collaboration tools, open the user profile and organization information. For phone calls, remember that caller ID can be spoofed. A compromised real mailbox can also send malicious requests, so a correct address is evidence—not proof.
- 1
Read the complete sender address, including the domain after @.
- 2
Compare the domain with a known previous message or official website.
- 3
Check whether Reply-To differs from From.
- 4
Look for a newly created conversation that imitates an old thread.
- 5
Treat requests from a real account as suspicious if the action is unusual.
Classify the requested action
High-risk requests often seek credentials, MFA codes, gift cards, urgent bank changes, cryptocurrency, confidential files, remote-access software or secrecy. Some phishing messages contain no link; they begin a conversation and introduce the harmful request later.
- 1
Write down exactly what the sender wants.
- 2
Mark whether the request changes payment, payroll, recovery or account access.
- 3
Do not open the link or attachment during triage.
- 4
Do not call a number supplied only in the message.
- 5
Preserve the message if your workplace has a reporting process.
Verify through a trusted route
Use an address, app, phone number or conversation you already trust. Contact the person directly, begin a new message thread or open the organization account independently. Verification is not an accusation; it is a normal control for unusual requests.
- 1
Open the official app or type the known website.
- 2
Use a saved contact or published phone number.
- 3
Ask the claimed sender to restate the request through that channel.
- 4
Report the suspicious message using the platform or workplace tool.
- 5
Delete it only after any required evidence is preserved.
- The verification route did not come from the suspicious message.
- No credentials, codes or payments were shared.
- The message was reported when appropriate.
Triage three sample messages
Use one email, one text and one phone scenario.
- 1
Describe the context and whether the message was expected.
- 2
Record sender identity evidence.
- 3
Classify the requested action and possible impact.
- 4
Choose an independent verification channel.
- 5
Write the safe response without clicking or replying.
Common mistakes to avoid
- Trusting a message because the grammar is good.
- Treating a familiar display name as identity proof.
- Using the phone number or link supplied in the request.
- Assuming a real compromised mailbox cannot send phishing.
Key takeaways
- Context and requested action matter more than visual polish.
- Correct sender details reduce uncertainty but do not eliminate risk.
- Independent verification breaks the attacker-controlled path.
Frequently asked questions
Can a message from a real colleague still be phishing?
Yes. Their account may be compromised, or the request may be an impersonation in a new channel. Verify unusual actions independently.
Should I reply asking whether the message is real?
Use a separate trusted channel. Replying keeps you inside the path controlled by the suspicious message or compromised account.
Sources and further reading
- Phishing scams can be hard to spotFederal Trade Commission
- Use Strong PasswordsCISA
Ready to continue?
Mark the lesson complete so your Learning Path progress stays current on this device.