Email safety

How to check a suspicious or phishing email

Phishing email tries to make a false action feel routine. It may resemble an invoice, shared document, delivery notice, password warning or message from a manager.

Look beyond the sender name

Email apps often emphasize a display name while hiding the full address. Expand the sender details and look for misspellings, unrelated domains or a reply address that differs from the sender.

  • Unexpected domain or free mailbox
  • Reply-to address does not match
  • Lookalike letters or added words
  • A colleague's tone or request suddenly changes

Treat links and files separately

A button can hide a different destination. On a computer, preview the real link without opening it. On a phone, use a safe link-check method rather than visiting the page. Unexpected HTML, archive, executable or macro-enabled files deserve particular caution.

  • Sign-in page opened from an email
  • Attachment you did not request
  • Invoice with changed banking details
  • QR code used to hide a login link

Verify through a second channel

Open the service from a trusted bookmark or official app. For work requests, contact the person using a known channel. Never approve a login, BankID request or multi-factor prompt simply because an email says it is required.