How to Recognize Phishing Emails Without Guessing
Learn to examine unexpected email requests, verify them independently, and report suspicious messages through the right channel.
Understand the request, the sender, and the protections around your account. Build a verification habit before you need it.
A recognizable name or a polished design does not settle whether a request is legitimate. Before you sign in, disclose information, install something, or change a payment process, ask whether the request was expected and how you can verify it independently. Our phishing awareness guide explains that decision in practical scenarios.
Use the service’s normal app, a known bookmark, or an established contact route. Do not rely on a phone number or alternate address supplied only by the questionable message. For workplace mail, use your organization’s verification and reporting process.
SPF, DKIM, and DMARC address particular questions about sending domains and message authentication. They do not certify every statement inside a message or guarantee that a request is trustworthy. Our plain-language authentication guide separates these roles and offers planning questions for domain owners.
Technical reference: Google’s sender guidance in our sources library. The guide explains the provider’s scope; do not assume one provider’s requirements apply unchanged everywhere.
Know how you sign in, how you would recover access, and which devices or applications have permission to use the account. Make changes through the provider’s legitimate settings. Keep recovery codes and other secrets out of casual notes or shared documents.
Our account security checklist turns this into a review routine, with the provider reference linked in the article. The checklist is not an account audit and does not produce a verified security grade.
A suspicious request is not just another newsletter to organize. Use your provider’s phishing-reporting tools or your organization’s approved channel. If you already entered credentials, approved an unexpected sign-in, or ran an unfamiliar file, use the legitimate recovery or support process promptly and describe what actually happened.
Do not assume deleting the email reverses an earlier action. Equally, do not claim compromise from an unclear observation alone. The appropriate response depends on the event and the relevant support guidance.
Try this suggested rule: verify unexpected, consequential requests through a route that does not depend on the message itself. Keep the rule available when a request is urgent or convincing. Then connect it to a clear reporting route and a periodic account review.
For provider-specific guidance, visit our phishing reference and account security reference. For the surrounding workflow, continue to Email Management.