Who sent the email?
Check whether the sender address and identity are what you would reasonably expect.
Emails can look professional and convincing while still being fraudulent. Before you click, open an attachment, sign in, pay money or disclose information, work through these checks.
Attackers can imitate companies, banks, employers, suppliers, delivery services and people you know. They may use familiar names, logos, documents and urgent language to make a request appear trustworthy.
When an email asks you to take an important action, verify the request independently before acting.
Work through the checks below. The greater the possible consequence, the more carefully the request should be verified.
Check whether the sender address and identity are what you would reasonably expect.
Be careful when an email suddenly asks you to pay, disclose information, change account details or take an unusual action.
Be cautious when the message demands immediate action, threatens consequences or offers a reward for acting quickly.
Treat unexpected links carefully, especially links asking you to sign in, make a payment or provide information.
Be cautious with unexpected documents, applications, archives or other files attached to an email.
Verify payment instructions, beneficiary changes, invoices and login requests independently.
Sender: Is the message really from who it claims to be?
Request: What exactly is the email asking you to do?
Consequence: What could happen if the request is fraudulent?
If money, credentials, identity, sensitive information or an irreversible action is involved, pause and verify through a trusted channel before acting.
VERIFY BEFORE YOU TRUST.