Step-by-step method
A reproducible path from question to conclusion.
- 1
Keep the message at a distance
Do not open the attachment or use supplied contact details. For an account or payment, use the official app or independently located website.
- 2
Preserve context
Retain the complete message, time, channel, apparent address or number and email headers where available. A screenshot often hides useful data.
- 3
Compare claimed identity
Check the domain after @, lookalike characters, reply address and consistency with previous exchanges. A display name can be chosen freely.
- 4
Inspect the destination without opening it
Reveal or copy the full link in an appropriate environment. Identify shorteners, misleading subdomains, redirects and the registered domain.
- 5
Assess the request
Classify what is sought: secret, login, payment, installation, document, changed bank details or urgent action. Higher consequence requires stronger independent confirmation.
- 6
Confirm and report
Call using an already known number, use the official channel and forward the item only through the approved internal or competent reporting route.
One signal is not a verdict
A typo, unusual phrase or new domain may prompt caution, but none proves fraud alone. A flawlessly written message can still be malicious.
Look for convergence between identity mismatch, sensitive request, manufactured urgency, unexpected destination and failure to confirm independently.
Separate link text from destination
Visible text can show a familiar name while the actual address leads elsewhere. Identify the registered domain first, then read subdomains and paths.
A padlock shows only an encrypted connection to the reached site. It does not verify the business identity or legitimacy of the request.
Return through a trusted channel
Useful verification does not reply within the suspect channel. Restart through an official app, known number, established contact or internal procedure.
At work, record time, targeted account and action taken so other recipients can be identified without spreading the message unnecessarily.
Common pitfalls
Four shortcuts that weaken the result.
Clicking to look
Opening may expose a token, trigger a redirect or install a file.
Replying to the sender
This confirms an active address and remains in the attacker-controlled channel.
Trusting the display name
It is neither the technical address nor proof of identity.
Forwarding widely
Uncontrolled circulation increases click risk and data exposure.
Practical questions
Frequently asked questions.
Is a well-written message reliable?
No. Writing quality proves neither sender identity nor legitimacy.
Can a search engine verify a link?
Search adds context but does not replace identifying the actual domain and using the official channel.
What if I already entered a password?
Change it through the official service, revoke sessions, enable multifactor authentication and alert the appropriate support team.
Editorial scope
Written and reviewed by Internet Intelligence Service on 15 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.
