Clear, practical technology insights
Act promptly15 minute route

I received a suspicious message or link

Preserve the message, avoid interacting with it and verify the claimed sender through a trusted route before opening links, files or payment requests.

Quick answer

The safest way to start

Do not use the link or contact details in the message; open the official service independently and verify the request through a trusted channel.

Quick answer

Do not use the link or contact details in the message; open the official service independently and verify the request through a trusted channel.

Best first action

Avoid links, attachments, QR codes, phone numbers and unsubscribe buttons in the suspicious message.

What not to do

Do not reply, open attachments, call the supplied number or enter credentials after following an unexpected link.

When to stop

Stop analysis and contact organizational security if the message targets payroll, financial transfers, administrator access, legal deadlines or sensitive customer data.

Expected result

The request has been independently confirmed or rejected.

1 · Triage

Quick checks before changing anything

Use these checks to narrow the problem and avoid applying an unrelated fix.

Check what the message wants

Urgent login, payment, gift card, remote-access, document-signing and secrecy requests deserve extra verification.

Inspect the sender and destination

Compare the full sender address and link destination with the organization’s known domain; display names and shortened links are not proof.

Look for context mismatch

Unexpected invoices, shared documents, delivery notices or password resets can be phishing even when grammar and branding look professional.

2 · Stabilize

Safe first actions

Mark actions as you complete them. Progress is stored only in this browser.

3 · Diagnose and resolve

Step-by-step route

Continue only when the result of the current step supports the next one.

  1. 1

    Assess the request

    Identify the action, data, money or access the sender wants.

    Expected resultThe social-engineering goal becomes clear.
  2. 2

    Inspect without opening

    Review sender details and link text using safe preview methods or a URL checker without loading unknown content.

    Expected resultObvious domain or attachment mismatches are identified.
  3. 3

    Verify through a separate channel

    Contact the person or company using previously known information.

    Expected resultThe request is confirmed or rejected without trusting the original message.
  4. 4

    Respond according to exposure

    If nothing was opened, report and delete; if credentials or files were submitted, follow compromise response immediately.

    Expected resultThe incident is contained at the correct severity.

Stop and escalate when

  • Stop analysis and contact organizational security if the message targets payroll, financial transfers, administrator access, legal deadlines or sensitive customer data.
4 · Verify

How to know the problem is resolved

  • The request has been independently confirmed or rejected.
  • No credentials, payment or remote access were provided to the suspicious channel.
  • The message was reported and affected users were warned when appropriate.
5 · Build the skill

Recommended learning route

Open these lessons in order when you need more detail or want to prevent the issue from returning.

Lesson 1

Spot common phishing signals

Check sender identity, urgency, payment requests, links and unexpected attachments.

Online Security · Recognize Phishing and Scams
Lesson 2

Inspect links and files safely

Review destinations before opening and avoid executing unfamiliar downloads.

Online Security · Recognize Phishing and Scams
Lesson 3

Verify sensitive requests

Contact the person or company using a trusted route rather than replying to the message.

Online Security · Recognize Phishing and Scams
Lesson 4

Respond to a suspected compromise

Use a clean device, change credentials, revoke sessions and review account activity.

Online Security · Backup and Incident Response
6 · Practice and reference

TipsMake tools and guides

Related routes

Continue with a connected problem

Common questions

FAQ

Can a legitimate-looking HTTPS link still be malicious?

Yes. HTTPS protects the connection to a site; it does not prove the site is trustworthy. Verify the domain and open the service through a known route.

Is it safe to reply and ask whether the message is real?

No. A reply stays inside the attacker-controlled channel and confirms your address is active. Verify using a known phone number, official app or separate conversation.