Start with the request.
Is the message asking for credentials, a payment, sensitive information, or an unexpected download? Treat the action it asks you to take as the most important clue.
Notice the pressure.
A short deadline, a threat of account closure, or an unusually generous offer can be an attempt to make you act before checking. Urgency alone does not prove a message is malicious, but it is a reason to slow down.
Check the sender in context.
A display name is easy to imitate. Look at the actual address and consider whether it matches the organization and the kind of request. A familiar-looking address is not proof of legitimacy.
Use an independent channel.
Open the official service using a bookmark or an address you already know. Contact the organization through a verified phone number or support page rather than a link or number in the message.
If you already interacted.
Contact your institution’s IT team through a trusted channel. Explain what you clicked or shared. If credentials were exposed, follow the institution’s account recovery guidance promptly.
Verify the request, not just the appearance of the message.