Do not use the link or contact details in the message; open the official service independently and verify the request through a trusted channel.
I received a suspicious message or link
Preserve the message, avoid interacting with it and verify the claimed sender through a trusted route before opening links, files or payment requests.
The safest way to start
Do not use the link or contact details in the message; open the official service independently and verify the request through a trusted channel.
Avoid links, attachments, QR codes, phone numbers and unsubscribe buttons in the suspicious message.
Do not reply, open attachments, call the supplied number or enter credentials after following an unexpected link.
Stop analysis and contact organizational security if the message targets payroll, financial transfers, administrator access, legal deadlines or sensitive customer data.
The request has been independently confirmed or rejected.
Quick checks before changing anything
Use these checks to narrow the problem and avoid applying an unrelated fix.
Check what the message wants
Urgent login, payment, gift card, remote-access, document-signing and secrecy requests deserve extra verification.
Inspect the sender and destination
Compare the full sender address and link destination with the organization’s known domain; display names and shortened links are not proof.
Look for context mismatch
Unexpected invoices, shared documents, delivery notices or password resets can be phishing even when grammar and branding look professional.
Safe first actions
Mark actions as you complete them. Progress is stored only in this browser.
Step-by-step route
Continue only when the result of the current step supports the next one.
- 1
Assess the request
Identify the action, data, money or access the sender wants.
Expected resultThe social-engineering goal becomes clear. - 2
Inspect without opening
Review sender details and link text using safe preview methods or a URL checker without loading unknown content.
Expected resultObvious domain or attachment mismatches are identified. - 3
Verify through a separate channel
Contact the person or company using previously known information.
Expected resultThe request is confirmed or rejected without trusting the original message. - 4
Respond according to exposure
If nothing was opened, report and delete; if credentials or files were submitted, follow compromise response immediately.
Expected resultThe incident is contained at the correct severity.
Stop and escalate when
- Stop analysis and contact organizational security if the message targets payroll, financial transfers, administrator access, legal deadlines or sensitive customer data.
How to know the problem is resolved
- The request has been independently confirmed or rejected.
- No credentials, payment or remote access were provided to the suspicious channel.
- The message was reported and affected users were warned when appropriate.
Recommended learning route
Open these lessons in order when you need more detail or want to prevent the issue from returning.
Spot common phishing signals
Check sender identity, urgency, payment requests, links and unexpected attachments.
Online Security · Recognize Phishing and ScamsInspect links and files safely
Review destinations before opening and avoid executing unfamiliar downloads.
Online Security · Recognize Phishing and ScamsVerify sensitive requests
Contact the person or company using a trusted route rather than replying to the message.
Online Security · Recognize Phishing and ScamsRespond to a suspected compromise
Use a clean device, change credentials, revoke sessions and review account activity.
Online Security · Backup and Incident ResponseTipsMake tools and guides
Continue with a connected problem
FAQ
Can a legitimate-looking HTTPS link still be malicious?
Yes. HTTPS protects the connection to a site; it does not prove the site is trustworthy. Verify the domain and open the service through a known route.
Is it safe to reply and ask whether the message is real?
No. A reply stays inside the attacker-controlled channel and confirms your address is active. Verify using a known phone number, official app or separate conversation.