An email arrives while you are busy: your booking will expire unless you pay now. The logo looks familiar, and the wording sounds professional. Before touching the button, ask one question: what is this message trying to make me do? That is a more useful starting point than judging its design.
Start with the request, not the appearance
Phishing means trying to obtain information or access through a deceptive message. Look for the requested action: a payment, a login, a verification code or an unexpected file. Compare it with what you were already doing. An invoice for a purchase you never made deserves a pause, even if the amount seems small.
Pressure and polished wording can coexist. Good spelling is not proof of safety; see the NCSC guidance on recognizing scams.
Check the full sender address
Expand the sender details rather than trusting a display name such as “Reservations” or “Finance.” Read the domain after the @ sign and compare it with an address you already know. Watch for an extra word or a substituted character. A familiar name, logo or previous conversation is a clue to context, not permission to skip verification.
Email authentication is useful, but scammers can authenticate messages too. Google explains the limits of authentication; a pass is not a safety certificate.
Read the destination, not the button
On a desktop, hovering over a link can reveal its destination without clicking. If your phone cannot show the complete address safely, leave the link alone. A label saying “View booking” tells you nothing about who operates the destination.
Consider this fictional address: https://booking.example.com.verify.example.net/payment. The host is under example.net, not example.com. The familiar-looking part sits before the actual domain. Both domains are reserved for examples; this is text to examine, not a link to visit. If an address is shortened, cut off or confusing, you do not need to decode it to decline the shortcut.
HTTPS protects the connection; it does not establish an honest business. The Chrome connection-security guidance still advises checking the site name.
Verify through a separate route
Return to the imaginary booking email. Open the travel service's app or your saved official bookmark and find the booking there. If the payment request is absent or unclear, contact the provider through details you already trust. Do not use the message's phone number or reply address to verify that same message. Keep an unexpected “receipt” attachment closed during the check; a PDF label is not a reason to bypass it.
The FTC phishing guide recommends contacting a known company through a genuine website or number, independently of the suspicious message.
A checklist before you act
- Was I expecting this request, and does it match my records?
- Have I read the complete sender address and destination?
- Am I being rushed into payment, login or sharing a code?
- Can I verify through my saved app, bookmark or known contact?
- Have I left unexpected attachments and suspicious unsubscribe links alone?
Use your mail service's reporting control rather than replying. Gmail's phishing-report instructions show its own process; at work, follow your team's reporting route.
Already clicked? Describe what happened
Stop interacting with the page. Write down whether you only viewed it, entered details, downloaded a file or ran something. These are different situations; “I clicked” is not the whole incident.
If you shared a password, change it through the genuine service, including reused-password accounts, and enable available multi-factor authentication (MFA). See Microsoft's recovery advice.
Review unfamiliar devices, sessions and forwarding rules; sign out unknown sessions where supported. Google's account-recovery guide explains these checks for Google accounts.
Shared banking details need prompt bank contact. For downloads or work devices, seek security or IT help. The NCSC response guide distinguishes these situations from merely visiting; stay alert afterward.
Make the safer route easy to find
Keep important service bookmarks and verified contact details together. In a small team, agree who checks unexpected payment requests and where suspicious messages go. A clear route makes it easier to ask “can you confirm this?” before someone clicks, without turning every ordinary email into an investigation.
