Email safety
How to check a suspicious or phishing email
Phishing email tries to make a false action feel routine. It may resemble an invoice, shared document, delivery notice, password warning or message from a manager.
Look beyond the sender name
Email apps often emphasize a display name while hiding the full address. Expand the sender details and look for misspellings, unrelated domains or a reply address that differs from the sender.
- Unexpected domain or free mailbox
- Reply-to address does not match
- Lookalike letters or added words
- A colleague's tone or request suddenly changes
Treat links and files separately
A button can hide a different destination. On a computer, preview the real link without opening it. On a phone, use a safe link-check method rather than visiting the page. Unexpected HTML, archive, executable or macro-enabled files deserve particular caution.
- Sign-in page opened from an email
- Attachment you did not request
- Invoice with changed banking details
- QR code used to hide a login link
Verify through a second channel
Open the service from a trusted bookmark or official app. For work requests, contact the person using a known channel. Never approve a login, BankID request or multi-factor prompt simply because an email says it is required.