Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Phishing emails try to trick you into revealing information, clicking a harmful link, downloading software, sending money, or giving someone access to an account. Don’t judge an email by its logo or polished appearance: examine what it asks you to do, check the sender and link destination, and verify unexpected requests through a contact method you already trust.

What makes an email phishing?

Phishing is an attempt to steal personal information or gain access to online accounts through deceptive messages or websites that imitate services you use. That definition comes from Google’s guidance on avoiding and reporting phishing. A message may appear to come from a bank, workplace, familiar person, or another trusted organization, but a familiar name or convincing logo does not establish that it is genuine.

Look at the action the sender wants you to take. A message deserves extra scrutiny if it asks for a password or payment, urges you to open a link or attachment, or pressures you to act immediately to avoid a consequence. Unexpected prizes and rewards can also be bait. Urgency and emotion are meant to short-circuit careful checking.

How to check a suspicious email

  1. Pause before acting. Do not reply, open an attachment, follow a link, send money, or enter sensitive information while you assess the message.
  2. Check the sender’s full address. Compare it with the displayed name and look for misspellings or a domain that differs from the organization’s genuine address. A recognizable display name alone is not enough.
  3. Preview links without opening them. On a computer, hover over a link to see its destination if your email client supports this. Compare the destination with the link text and the organization you expect. A mismatch is a warning sign; do not click just to investigate.
  4. Read any provider warnings or authentication details. Treat them as clues, not a final verdict. Gmail describes checking message authentication and headers in its sender and message verification guidance.
  5. Verify the request independently. Contact the person or organization using a phone number, app, or website you already know is genuine. Do not use contact details or links supplied in the suspicious message.
  6. Report it if it remains suspicious. Use your email service’s phishing-reporting control rather than replying to the sender.

What sender authentication can—and cannot—tell you

An authentication warning means the mail provider could not confirm the apparent sender; it does not, by itself, prove the message is malicious. Gmail notes that legitimate mailing-list messages can sometimes fail authentication. Conversely, an authenticated message is not necessarily safe: spammers can authenticate mail too. Authentication is one piece of evidence to weigh alongside the request, sender address, link destination, and independent verification. See Gmail’s explanation of authentication and sender details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What to do if you clicked, replied, or shared information

Stop interacting with the message. If you entered a password, payment information, or other sensitive details, go directly to the affected service using its official app or a website address you already trust; follow that provider’s security instructions. Do not return to the email to find a security link.

For a suspicious Google security message, Google recommends visiting your Google Account directly and reviewing recent security activity. If you see unfamiliar activity, secure the account and change its password. If you suspect account settings were changed, Google’s phishing and account-safety guidance also advises checking for unknown delegates, forwarding rules, and filters. These steps are specific to Google; for another provider, use that service’s official security page.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use reporting and account safeguards

Report suspicious messages through your provider’s phishing or spam control. For work email, follow your organization’s reporting process or contact its IT staff. CISA puts the principle simply: “When in doubt, report it out: If it looks suspicious, it’s best to mark it as ‘junk’ and forward to your IT staff.” The guidance appears in the Cybersecurity and Infrastructure Security Agency’s Phishing: Simple Tips (2024).

Safeguards can reduce risk, but they do different jobs. Provider warnings and reporting help flag suspect messages. Multi-factor authentication (MFA) can help limit account harm if a password is stolen, while browser protections may warn about risky sites. Gmail also describes built-in phishing detection and 2-Step Verification in its account-safety guidance. None of these measures makes it wise to trust a suspicious request without checking it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.