EMAIL VERIFICATION

Pause before you trust an email.

Emails can look professional and convincing while still being fraudulent. Before you click, open an attachment, sign in, pay money or disclose information, work through these checks.

A professional-looking email is not proof of legitimacy.

Attackers can imitate companies, banks, employers, suppliers, delivery services and people you know. They may use familiar names, logos, documents and urgent language to make a request appear trustworthy.

When an email asks you to take an important action, verify the request independently before acting.

What should I never send by email?
Never send passwords, one-time passwords, PINs, recovery phrases, private keys or other authentication secrets in response to an unexpected request.
What if the sender looks familiar?
Check the actual sender address rather than relying only on the display name. For important requests, contact the person or organization through a trusted method you already know.
What if the email contains a link?
Do not rush to click it. If the link asks you to sign in, pay, download something or provide sensitive information, independently locate the legitimate website or contact the organization through a trusted channel.
EMAIL SAFETY CHECKS

Check the email before acting.

Work through the checks below. The greater the possible consequence, the more carefully the request should be verified.

Who sent the email?

Check whether the sender address and identity are what you would reasonably expect.

Why this matters
A familiar display name does not prove that an email came from the real person or organization. Look carefully at the actual sender address and be cautious about small spelling changes or unusual domains.

Is the request unusual?

Be careful when an email suddenly asks you to pay, disclose information, change account details or take an unusual action.

Why this matters
Unexpected requests deserve independent verification, particularly when the requested action could affect money, accounts, identity or sensitive information.

Is there urgency or pressure?

Be cautious when the message demands immediate action, threatens consequences or offers a reward for acting quickly.

Why this matters
Urgency can discourage careful verification. Pause and independently confirm important requests before acting.

Does it contain a link?

Treat unexpected links carefully, especially links asking you to sign in, make a payment or provide information.

Why this matters
Do not assume a link is legitimate because the message contains familiar branding. Check the destination independently before entering credentials or other sensitive information.

Is there an attachment?

Be cautious with unexpected documents, applications, archives or other files attached to an email.

Why this matters
Unexpected attachments can contain harmful content or may be designed to make you act before thinking. Confirm that the sender genuinely intended to send the file before opening it.

Is money or account access involved?

Verify payment instructions, beneficiary changes, invoices and login requests independently.

Why this matters
An email should not be the only evidence supporting a high-impact financial or account decision. Use a trusted contact method that you already know.
Before you act, check three things.

Sender: Is the message really from who it claims to be?

Request: What exactly is the email asking you to do?

Consequence: What could happen if the request is fraudulent?

Do not let an email create the urgency.

If money, credentials, identity, sensitive information or an irreversible action is involved, pause and verify through a trusted channel before acting.

VERIFY BEFORE YOU TRUST.