# How to avoid phishing emails: recognition and safer habits

> Learn how to avoid phishing emails by checking requests outside the message, reporting suspicious mail, protecting accounts, and recovering after mistakes.

To avoid phishing emails, do not let the message control how you verify it. Pause on unexpected requests, inspect the full sender and destination, then open the claimed service through a bookmark, app, typed address, or known contact route. Keep passwords and one-time codes out of email-driven conversations. Report suspicious messages through your provider or organization, and switch to recovery steps immediately if you already clicked, signed in, opened a file, or paid.

## Quick takeaways

- Verify the request outside the message before acting.
- Treat urgency as a reason to pause, not proof of fraud by itself.
- Check the full address and real destination, not the display name or logo.
- Never share a password or one-time code because an email asks.
- Use the normal reporting route instead of replying or testing a suspicious link.
- If you interacted, contain the account, device, or payment risk first.

## Why recognition starts with the requested action

Phishing is defined by deception and the action the sender wants, not by bad grammar or one visual clue. The National Institute of Standards and Technology describes phishing as deceptive communication intended to obtain sensitive information or induce an unsafe action ([NIST phishing guidance](https://www.nist.gov/itl/smallbusinesscyber/guidance-topic/phishing)).

Read the message as a request. Is it asking you to sign in, send money, change payment details, open a file, scan a QR code, call a number, approve a prompt, share personal information, or bypass a normal process? That request tells you what needs independent verification.

A polished message can be malicious. A clumsy message can be legitimate. Logos, signatures, conversation history, and familiar writing are context, not proof. A compromised real account may have authentic history and a valid sender address. A lookalike domain may be one character away from the real one.

The useful question is not "Does this look professional?" It is "Can I confirm this request without using the path the message supplied?"

## Verify the claim outside the email

The Federal Trade Commission advises people to contact the supposed organization using a website or phone number they know is real, rather than contact details in an unexpected message ([FTC phishing guidance](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams)). Apply that rule literally.

If the message claims there is an account problem, open the provider's app or type its address yourself. If it claims a purchase, compare the claim with independently opened order or transaction history. If a colleague requests a payment change, call them on a known number or use an established business process. If a bank appears to contact you, use the number on your card or statement.

Do not return to the email after finding a real issue. A genuine account alert can coexist with a fake email that guessed or reused public information. Continue inside the trusted app, site, or conversation you opened yourself.

Use this compact decision record when the request matters:

```text
Claim in the message: account, payment, file, login, or business change
Requested action: what the sender wants you to do
Independent route: app, typed site, known phone, or existing conversation
Verified event: found, not found, or still uncertain
Next action: continue in trusted route, report, or escalate
```

## Inspect addresses and destinations without trusting them alone

Expand the full sender address. Compare the domain with one you already know belongs to the organization. Watch for extra words, substituted letters, unexpected subdomains, and reply addresses that differ from the visible From address.

Inspect the actual link destination without visiting it when the mail client exposes that information. The visible text can name a trusted site while the destination belongs elsewhere. A padlock or `https` only describes the connection to the destination; it does not establish that the destination is the organization named in the email.

These checks find contradictions. They do not prove safety. A real account can be compromised, and an attacker can register a plausible domain with a valid encrypted connection. Independent verification remains the decision point.

![Decision flow moving from a suspicious request to an independent route, verified event, and safe next action](/images/editorial/how-to-avoid-phishing-emails/how-to-avoid-phishing-emails-verification-flow.svg "1200x676")

*Source: Palisade deterministic workflow based on [FTC phishing guidance](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams) and [NIST phishing guidance](https://www.nist.gov/itl/smallbusinesscyber/guidance-topic/phishing).*

## Protect the accounts a phish is trying to reach

Use a unique password for each important account and store it in a reputable password manager. A password manager also adds friction on a lookalike site because it should not offer the saved credential for a different domain. Do not override that mismatch simply because the page looks familiar.

Turn on multi-factor authentication. Prefer a phishing-resistant method such as a passkey or hardware security key when the service offers it. Codes and approval prompts are still sensitive. Never read a code to someone who contacted you or approve a sign-in you did not start.

Keep recovery email addresses, phone numbers, backup codes, and trusted devices current. Protect the email account especially carefully because password resets for other services often arrive there. Review unexpected recovery or sign-in alerts through the account's security area, not the alert link.

Account protection limits damage when a message gets through, but it does not make a request legitimate. A second factor is strongest when you refuse to approve an event you did not initiate.

## Handle attachments, QR codes, and phone numbers carefully

An attachment can be harmful even when its filename resembles an invoice, scan, voicemail, or shared document. Do not open an unexpected file to determine whether it is safe. Verify with the sender through a separate route first, and use the organization's approved analysis process for work messages.

A QR code is a link that hides its destination from the normal hover check. Do not scan one from an unexpected message merely to inspect it. A phone number can also keep you inside the attacker's channel. Search results and caller ID can be manipulated, so use contact information from a statement, card, official app, or known directory.

CISA advises recipients not to click links or open attachments in suspicious messages and to report them through a trusted process ([CISA phishing guidance](https://www.cisa.gov/secure-our-world/recognize-and-report-phishing)). That same restraint applies to unsubscribe links in a message you believe is deceptive.

## Build habits that work when the message feels urgent

Phishing often creates a deadline because speed reduces verification. Use a personal rule that high-impact requests slow down. Payment changes, password resets, payroll updates, gift-card purchases, recovery-code requests, and requests to install software should always move to a second channel.

For work, learn the organization's exact reporting and urgent-escalation routes before an incident. Know who owns suspicious payment requests, account access, endpoint security, and mail investigation. A reporting button helps only when people know what happens after they use it.

Do not shame someone who reports after clicking. Fast disclosure gives the response team a better chance to revoke a session, stop a payment, isolate a device, or remove related messages. A culture that punishes mistakes teaches people to hide the evidence.

Mailbox controls reduce exposure but belong to a separate task. Use [how to block phishing emails](/learning/how-to-block-phishing-emails) when you need filters and rules. For one Microsoft client workflow, see [how to report phishing in Outlook](/learning/how-to-report-a-phishing-email-in-outlook). If the destination is unclear, use [where to send a phishing email](/learning/report-email-phishing-scams) or the broader [phishing-reporting decision guide](/learning/report-email-phishing-scams).

## What to do if you already interacted

Stop interacting and record what happened. The response depends on the action, not on whether you have proven the message was malicious.

If you entered a password, change it through the real service and review sessions, recovery details, and security events. If you shared a one-time code or approved a prompt, treat the account as exposed even if the password was not typed. If you opened a file or installed software on a work device, contact the security team and avoid destroying evidence. If you sent money or changed bank details, contact the financial institution through a trusted route immediately.

Report the message after starting containment. The FTC points people who disclosed personal information to IdentityTheft.gov and accepts fraud reports at ReportFraud.ftc.gov ([FTC phishing guidance](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams)). Your employer, bank, service provider, insurer, or local authority may have a separate process for the specific loss.

## Sources and further reading

- [NIST: Phishing guidance for small businesses](https://www.nist.gov/itl/smallbusinesscyber/guidance-topic/phishing)
- [FTC: How to recognize and avoid phishing scams](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams)
- [CISA: Recognize and report phishing](https://www.cisa.gov/secure-our-world/recognize-and-report-phishing)

## Frequently asked questions

### What is the safest first response to a suspicious email?

Stop and verify the claim outside the message. Open the service through a bookmark, app, or typed address, or contact the person through a known channel. Do not use the email's link, attachment, phone number, reply address, or QR code for that verification.

### Can good spelling mean an email is legitimate?

No. Writing quality is not an identity check. Treat spelling and layout as weak context, then inspect the request, full address, real destination, and independently verified event. A professional message can still be deceptive.

### Should I reply to ask whether the email is real?

No. A reply keeps you in a channel the sender may control. Contact the person or organization through an address, account, phone number, or conversation you already trust.

### Does multi-factor authentication stop every phishing attempt?

No. It can reduce account takeover, especially when the method is phishing resistant, but people can still be tricked into sharing codes, approving prompts, opening files, or sending money. Verify the request before using any authentication factor.

### What if I clicked but did not enter information?

Close the page and do not download or approve anything. Review the relevant account and device through trusted surfaces. For a work device, report the event because security staff may need the URL, time, browser evidence, or endpoint logs even when no credential was entered.
