Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Analyst safely reviewing a suspicious message, sender details and timeline

Messaging and fraud guide · 11 min

Analyse a suspicious message without clicking, replying or disclosing more information.

A display name, logo or urgent tone proves nothing. Safe review separates the apparent identity, actual destination, requested action and expected context.

Published 15 September 2026Reviewed by IIS editorial team

At a glance

Four rules for a useful review.

  • Do not interact to test it.
  • Compare the sender through a known channel.
  • Read the actual link destination.
  • Assess the request before the wording.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Keep the message at a distance

    Do not open the attachment or use supplied contact details. For an account or payment, use the official app or independently located website.

  2. 2

    Preserve context

    Retain the complete message, time, channel, apparent address or number and email headers where available. A screenshot often hides useful data.

  3. 3

    Compare claimed identity

    Check the domain after @, lookalike characters, reply address and consistency with previous exchanges. A display name can be chosen freely.

  4. 4

    Inspect the destination without opening it

    Reveal or copy the full link in an appropriate environment. Identify shorteners, misleading subdomains, redirects and the registered domain.

  5. 5

    Assess the request

    Classify what is sought: secret, login, payment, installation, document, changed bank details or urgent action. Higher consequence requires stronger independent confirmation.

  6. 6

    Confirm and report

    Call using an already known number, use the official channel and forward the item only through the approved internal or competent reporting route.

One signal is not a verdict

A typo, unusual phrase or new domain may prompt caution, but none proves fraud alone. A flawlessly written message can still be malicious.

Look for convergence between identity mismatch, sensitive request, manufactured urgency, unexpected destination and failure to confirm independently.

Return through a trusted channel

Useful verification does not reply within the suspect channel. Restart through an official app, known number, established contact or internal procedure.

At work, record time, targeted account and action taken so other recipients can be identified without spreading the message unnecessarily.

Common pitfalls

Four shortcuts that weaken the result.

Clicking to look

Opening may expose a token, trigger a redirect or install a file.

Replying to the sender

This confirms an active address and remains in the attacker-controlled channel.

Trusting the display name

It is neither the technical address nor proof of identity.

Forwarding widely

Uncontrolled circulation increases click risk and data exposure.

Practical questions

Frequently asked questions.

Is a well-written message reliable?

No. Writing quality proves neither sender identity nor legitimacy.

Can a search engine verify a link?

Search adds context but does not replace identifying the actual domain and using the official channel.

What if I already entered a password?

Change it through the official service, revoke sessions, enable multifactor authentication and alert the appropriate support team.

Editorial scope

Written and reviewed by Internet Intelligence Service on 15 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.