A suspicious email does not always look suspicious at first glance. Modern phishing messages can copy the branding, writing style, and layout of legitimate companies, making it difficult to tell whether a message is genuine or designed to steal your information.
Phishing emails are commonly used to trick people into revealing passwords, financial information, verification codes, or other personal details. They may also attempt to persuade you to click a dangerous link or download a malicious file. Google recommends checking the sender, paying attention to warnings, avoiding suspicious links, and never entering sensitive information after following an unexpected link.
This guide explains practical ways to examine an email before interacting with it, including what to look for in the sender address, links, attachments, urgency, and message content.
Practical example: The examples in this guide are fictional. Never enter your password, verification code, banking details, or other sensitive information into a page simply because an email tells you to do so.
What Is a Phishing Email?
Phishing is an attempt to steal personal information or gain unauthorized access to online accounts through deceptive emails, messages, advertisements, or websites.
A phishing message may pretend to come from:
- Your bank
- A social media platform
- An online store
- Your workplace
- A delivery company
- A family member or friend
- A service you regularly use
Google explains that phishing messages can ask for personal or financial information, encourage you to click links or download software, or imitate a trusted organization or person.
The important thing to remember is that a professional-looking email is not automatically a legitimate one.
Step 1: Check the Sender’s Email Address
One of the first things to examine is the actual email address of the sender.
The display name alone is not enough.
For example, an email might display:
Google Security
but the actual address could belong to an unrelated domain.
Look carefully at the complete address rather than judging the message by the name shown beside it.
Google specifically recommends checking whether the sender’s email address matches the sender name and whether the message is authenticated.
A mismatch does not always prove that an email is malicious, but it is an important warning sign that deserves investigation.
Step 2: Look for Gmail Security Warnings
Gmail uses automated systems to identify potentially dangerous messages.
Depending on the message, Gmail may display warnings about suspicious emails or attachments.
Do not ignore these warnings simply because the email appears to come from a company you recognize.
Google recommends paying attention to its security warnings and avoiding links, attachments, or requests for personal information when a message appears suspicious.
A warning does not mean you should investigate the message by clicking its links.
When Gmail identifies a potential phishing message, the safer approach is to avoid interacting with it until you can independently verify the request.
Step 3: Read the Message Without Clicking Anything
Before clicking a link, read the entire email.
Look for inconsistencies in:
- The reason for contacting you
- The company mentioned
- The requested action
- The deadline
- The sender
- The language used
A message that asks you to make an important decision immediately deserves extra attention.
You can read the content without opening links or attachments.
This allows you to examine the request before taking an action that could expose information.
Step 4: Be Suspicious of Urgent Requests
Phishing messages frequently create a sense of urgency.
Examples include messages claiming:
Your account will be closed today
Your payment failed
Your package cannot be delivered
Your account has been compromised
You must verify your identity immediately
Urgency is not proof of fraud by itself. Legitimate companies sometimes send time-sensitive notices.
However, Google recommends stopping and thinking before clicking links or responding to unexpected requests.
Ask yourself:
Did I expect this message?
Was I actually waiting for this service?
Can I verify the request independently?
If the answer is no, do not rush.
Step 5: Do Not Trust the Logo
A convincing logo does not prove that an email is authentic.
A scammer can copy:
- Company logos
- Colors
- Fonts
- Email layouts
- Images
- Legal disclaimers
- Signature styles
Treat visual design as secondary evidence.
The actual sender address, destination of links, and circumstances surrounding the message are more useful when evaluating a suspicious email.
Step 6: Check Links Before Opening Them
Links deserve particular attention because phishing emails often use them to direct victims to fake login pages.
On a computer, Google recommends placing the mouse pointer over a link without clicking it and checking the URL that appears. If the URL does not match the description of the link, it may lead to a phishing site.
On a phone, the interface may behave differently. Instead of assuming that a button is safe, consider whether you actually need to use the link at all.
For sensitive accounts, the safest approach is often to open the official app or type the known website address yourself rather than following an unexpected email link.
Step 7: Look Beyond the Visible Link Text
A link may say:
“Verify your account”
while sending you somewhere completely different.
The words displayed in an email are not necessarily the same as the website address behind the link.
This is why visually recognizing a familiar brand name is not enough.
If the message asks you to sign in, make a payment, or provide sensitive information, opening the service directly through its official app or website is generally safer than following an unexpected email link.
Step 8: Check the Domain Carefully
Even when you inspect a URL, pay attention to the actual domain.
Scammers may use domains that contain familiar words but belong to unrelated websites.
A domain such as:
example-security.com
is not automatically connected to:
example.com
Similarly, a familiar brand name appearing somewhere inside a longer domain does not automatically mean the website belongs to that company.
The part of the address that identifies the actual domain is what matters.
Step 9: Never Enter Your Password After an Unexpected Link
This is one of the most important rules.
Google specifically recommends not entering your password after clicking a link in a suspicious or unexpected message. Instead, go directly to the website or service you intended to use.
For example, imagine receiving an email saying:
Your Google Account requires immediate verification.
Instead of clicking the button in the email, open the Google app or manually navigate to the official Google Account page.
That removes the email link from the process.
Step 10: Be Careful With Attachments
Phishing emails can also use attachments instead of links.
A message might tell you that an attachment contains:
- An invoice
- A delivery document
- A payment notice
- A tax document
- An account statement
- A job offer
Do not open unexpected attachments simply because the file name looks professional.
Google recommends avoiding downloads from untrusted or unknown sources and paying attention to warnings about potentially harmful attachments.
Step 11: Check Whether You Were Expecting the Message
Context is one of the strongest clues.
Suppose you receive an email about an order.
Ask:
Did I actually place an order?
If you receive a delivery notification:
Am I expecting a package?
If you receive a password-reset request:
Did I request a password reset?
An unexpected message is not automatically a scam, but the lack of context should make you more cautious.
Step 12: Be Careful With Messages From Known Contacts
A familiar sender does not guarantee safety.
Google warns that phishing messages can appear to come from people you know, such as friends, relatives, or coworkers.
An account belonging to someone you know could have been compromised.
If a friend suddenly sends an unusual request for money, passwords, codes, or another sensitive action, verify it through a different communication method.
For example, call the person using a number you already have rather than replying to the suspicious email.
Step 13: Be Careful With Requests for Personal Information
Do not provide sensitive information simply because an email asks for it.
Google recommends never responding to suspicious requests for personal or financial information.
Sensitive information can include:
- Passwords
- Verification codes
- Credit card details
- Bank account information
- Identification numbers
- PINs
A legitimate service should provide an appropriate secure process for sensitive account actions.
Step 14: Watch for Unusual Payment Requests
Financial requests deserve additional scrutiny.
Be especially careful if an email asks you to:
- Send money urgently
- Change payment information
- Pay an unexpected invoice
- Purchase gift cards
- Transfer funds
- Provide bank details
If you are unsure, contact the organization using a phone number or website you already know to be legitimate.
Do not use contact information provided only inside a suspicious email.
Step 15: Check the Language and Writing Style
Grammar mistakes used to be one of the most obvious phishing clues.
Today, that is no longer enough.
A fraudulent email can be professionally written.
At the same time, strange wording, unusual formatting, or inconsistent terminology can still provide useful clues.
Do not decide whether a message is legitimate based solely on spelling or grammar.
Look at the entire message.
Step 16: Look for Requests That Feel Out of Character
Imagine receiving a message from your manager asking you to purchase gift cards immediately.
The sender may be genuine, but the request is unusual.
That unusual behavior is more important than the fact that the sender address looks familiar.
The same principle applies to friends, relatives, companies, and other organizations.
When a request is out of character, verify it independently.
Step 17: Do Not Let a Countdown Pressure You
Some scams use language designed to make you feel that you have only seconds or minutes to act.
For example:
“Click within 30 minutes.”
“Your account will be permanently closed.”
“Payment must be completed immediately.”
This type of pressure is intended to reduce the amount of time you spend examining the request.
Take your time.
A legitimate urgent request can generally be verified through an official channel.
Step 18: Open the Official Website Yourself
When an email asks you to perform an account action, consider bypassing the message entirely.
Open the official app or website directly.
For example, instead of clicking a password-reset link in an email, open the service’s official website and navigate to account settings.
This approach removes the suspicious email link from the process.
Google specifically recommends going directly to the website you want to use rather than entering your password after following an unexpected link.
Step 19: Check Recent Account Activity When Necessary
If an email claims that someone accessed your account, do not automatically trust the message.
Open the account’s official security section independently.
For Google Accounts, you can check recent security activity through the account security settings.
Google also recommends reviewing account activity when you suspect someone else may have accessed your account.
This lets you investigate the claim without relying on the links contained in the email.
Step 20: Use Gmail’s Built-In Protection
Gmail automatically identifies many suspicious messages and can display warnings or move messages to Spam.
Google recommends paying attention to these warnings and using Gmail’s reporting tools when appropriate.
No automated system catches every malicious email, however.
You still need to examine unexpected requests carefully.
Step 21: Report a Phishing Email
If an email appears to be phishing, do not respond to it.
Google provides a Report phishing option in Gmail.
On the web version of Gmail, open the suspicious message, select More, and choose Report phishing.
Reporting suspicious messages helps Gmail improve its ability to identify similar attempts.
The exact menu appearance can vary between Gmail versions and devices.
COLOQUE A IMAGEM 4 AQUI
Gmail’s reporting options for identifying a suspicious message as phishing.
Step 22: What If You Already Clicked the Link?
Do not panic.
The appropriate response depends on what happened next.
If you clicked the link but did not enter information or download anything, close the page and avoid interacting with it further.
If you entered your password, change it through the legitimate website immediately.
If you entered financial information, contact the relevant financial institution using an official contact method.
If you downloaded a suspicious file, do not open it.
Google recommends taking steps to secure your account when suspicious activity occurs, including changing passwords when appropriate and reviewing account security.
Step 23: What If You Entered a Password on a Fake Website?
Act quickly.
Go directly to the legitimate website or app and change the compromised password.
Do not use the suspicious link to change it.
If you reused that password on other websites, change those passwords too.
Google recommends using different passwords for important accounts and changing a password when you believe it has been compromised.
Enable additional account protection such as two-step verification when it is available.
Step 24: Review Other Account Security Settings
After a suspected phishing incident, do more than change the password.
Check:
Recent security activity
Signed-in devices
Recovery information
Two-step verification
Third-party applications with account access
Google provides account-security tools that allow you to review these areas and take action when something looks unfamiliar.
Step 25: Remember That Phishing Is Not Limited to Email
The same warning signs can appear through:
- Text messages
- Social media messages
- Advertisements
- Pop-ups
- Search results
- Messaging applications
Google explains that phishing can use emails, messages, advertisements, and deceptive websites.
The same basic habit applies everywhere:
Stop → verify → act
Do not allow an unexpected request to determine what you do next.
A Five-Question Check Before Clicking
When an unexpected email arrives, ask:
Do I know the sender?
Was I expecting this message?
Is the requested action reasonable?
Where does the link actually lead?
Can I perform this task directly through the official app or website instead?
If several answers raise concerns, do not click.
Frequently Asked Questions
How can I tell if an email is phishing?
Check the sender’s actual email address, look for unexpected requests, inspect links carefully, pay attention to Gmail warnings, and consider whether you were expecting the message. Google recommends avoiding suspicious links and requests for personal information.
Can a phishing email look exactly like a real company email?
Yes. Google explains that phishing messages can impersonate reputable organizations and can look like messages from people or organizations you trust.
Should I click an email link to verify whether it is real?
It is safer not to. If the message asks you to sign in or perform a sensitive action, open the official app or website directly instead.
What should I do if Gmail warns me about a suspicious message?
Do not click its links or attachments. Review the message carefully and report it as phishing if appropriate. Google recommends avoiding interaction with suspicious messages.
Can an email from someone I know be phishing?
Yes. A known person’s account may have been compromised, or the sender address may have been impersonated. Google specifically notes that phishing messages can appear to come from people you know.
What if I accidentally clicked a phishing link?
Close the page and avoid entering information. If you entered a password, change it through the legitimate website immediately and review your account security.
What if I entered my password on a fake website?
Change the password immediately through the legitimate service. If the same password was used elsewhere, change those passwords as well. Then review account activity and security settings.
Should I report phishing emails?
Yes. Gmail provides a Report phishing function for suspicious messages.
Does Gmail automatically detect every phishing email?
No security system should be treated as perfect. Gmail has automated protections and warnings, but users should still be cautious with unexpected requests and links.
Is a long or complicated email address a sign of phishing?
Not necessarily. The important thing is whether the sender address and domain match the organization or person the message claims to represent.
Is HTTPS enough to prove a website is legitimate?
No. HTTPS helps protect the connection between your browser and a website, but it does not by itself prove that the site belongs to the company you intended to visit.
The Safest Response to a Suspicious Email
You do not need to become an expert in cybersecurity to identify many suspicious emails.
Start by slowing down.
Check who sent the message, think about whether you were expecting it, inspect the request, and avoid clicking links simply because the email tells you to.
For account-related messages, one of the safest habits is to open the official app or website yourself rather than following an unexpected link.
If the message still looks suspicious, do not reply, do not provide personal information, and report it through the appropriate tools.
Phishing works best when it convinces someone to act before thinking. Taking a few seconds to verify the request can make a significant difference.