How-To
Duration: 2m
6 steps
Spot phishing in 30 seconds – 6-point checklist
Six quick checks that expose suspicious emails as phishing in under 30 seconds.
This 6-point quick check usually identifies phishing emails in under a minute. If even one point applies, treat the message with extreme caution.
Steps
- 1 Read the sender address carefully Does the domain match exactly? "support@postfìnance.ch" (with accent) instead of "support@postfinance.ch" is a classic phishing trick. Expand the sender field in your mail client; don't rely on the display name alone.
- 2 Check the link preview Hover over every link (do not click). Does the URL shown in the status bar match the alleged sender's domain?
- 3 Spot pressure tactics Phrases like "Your account will be locked in 24 hours" exist to push you into hasty action. Legitimate providers always give you enough time.
- 4 Check the salutation Is it a personal greeting with your correct name? Banks and insurers never use "Dear Sir or Madam" for existing customers.
- 5 Watch the attachments Invoices as .zip, .exe, .scr, .iso, or Office files demanding macros? Never open. PDFs from unexpected sources: think twice.
- 6 When in doubt: call back If genuinely unsure, call the provider directly – using the number from their official website, NEVER the number in the suspicious email.