Free Guide

Got a suspicious email? Here's what to check before you click anything.

A quick, plain-English walkthrough for spotting a phishing email, built for anyone who isn't sure if that message from their bank, Amazon, or the IRS is actually real.

The Basics

What is phishing, exactly?

Phishing is when someone pretends to be a company or person you trust, in an email, text, or phone call, to trick you into clicking a bad link, downloading malware, or handing over information like passwords, account numbers, or a one-time login code. It works by creating urgency or fear so you act before you stop to think.

Before You Click

Six signs an email might be phishing

The sender address doesn't match

"Amazon Support" might show up as the name, but the actual email address is something like security-amazon@mail-verify.net. Always check the real address, not just the display name.

It creates urgency or fear

"Your account will be suspended in 24 hours" or "unusual sign-in detected." Real companies rarely demand instant action over email.

It wants you to click or open something

Especially a link or attachment to "verify," "confirm," or "update" an account you weren't expecting to hear about.

The greeting is generic

"Dear Customer" instead of your actual name. That said, more sophisticated phishing attempts can personalize this too, so don't rely on this one alone.

It asks for something a real company wouldn't

Your full password, a complete card number, gift cards, or a one-time login code, sent over email or read out loud on a phone call.

Something just looks slightly off

Misspellings, a stretched logo, an odd reply-to address, or formatting that doesn't quite match emails you've gotten from that company before.

What To Do Instead

Four steps, instead of clicking

01

Don't click anything

Not the link, not "unsubscribe," not the attachment. Closing the email costs you nothing. Clicking it might not.

02

Check the real destination

On a computer, hover over the link without clicking to see the actual web address in the corner of your browser. On a phone, press and hold it to preview the link.

03

Verify a different way

If it claims to be your bank, employer, or a company you use, go to their website by typing the address yourself, or call the number on the back of your card, not any number or link in the email.

04

Report it, then delete it

Most email providers have a "Report phishing" option. Use it, then delete the message.

If You Already Clicked

Already clicked a link or entered information? Here's what to do now.

It happens to careful people too, phishing is designed to fool you. Acting quickly matters more than feeling bad about it.

  • If you entered a password: change it immediately, ideally from a different device, and change it anywhere else you reused it.
  • If you entered financial information: call your bank or card issuer right away. Most can freeze or reissue a card within minutes.
  • If you downloaded or opened a file: disconnect the device from Wi-Fi and stop using it until it's been scanned.
  • Either way: turn on multi-factor authentication (MFA) on the affected account if it isn't already on.

Still Not Sure, Or Think Something's Wrong?

I'll take a look, free.

If you're not sure whether something was actually phishing, or you think a device might already be affected, send me what you're seeing. A quick second opinion is free. If it turns out your computer needs cleanup, we'll go from there.

Get a Free Second Opinion

or reach out directly: contact@hearthandfirewall.com · (401) 310-0765