Mark it once you can do it without this page open.

How to do it

  1. Pause whenever a message asks you to act quickly, pay, log in or open a file.
  2. Look at the full sender address, not just the display name, for misspellings and odd domains.
  3. Press and hold or hover over each link to see where it really goes before tapping.
  4. Check the greeting and the details: a real bank knows your name and never asks for your password.
  5. Open the company's app, or type its address yourself, to check whether anything is actually wrong.
  6. Report the message with the phishing or junk button, then delete it.
  7. Change the password at once and turn on two-step login if you already typed it on a linked page.

Stop and call a professional if

  • You entered bank or card details on a linked page: call the bank's number from the back of your card straight away.
  • You opened an attachment and the computer is acting strangely: disconnect it from the internet and have a trusted repair shop check it.

Common mistakes

  • Trusting a message because it shows a real logo.
  • Replying to ask if it is genuine, which confirms your address is live.
  • Opening an unexpected invoice or shipping attachment.

Quick self-check

Three questions. Your last score is kept in this browser.

1. A text says a package is held and links to a payment page. What should you do?
2. What does the display name on an email prove?
3. You typed your password on a page from an email link. What first?

Teach this to someone

A one-page sheet for showing a friend, a roommate or a kid: what to say, what to show, and one question to check it landed.

Words on this page

Sources

  • Federal consumer guidance on phishing and online fraud, 2026. Checked September 28, 2026.

Last reviewed . First published .