The signs that almost never fail
- Artificial urgency: "your account will be suspended in 24 hours", "immediate action required". Legitimate providers don't pressure you with short deadlines by email.
- The sender doesn't match the real domain: hover over the sender's name (without clicking) and look at the full address. "[email protected]" is not Microsoft.
- Links that don't go where they claim: hover over any link (without clicking) and check the actual URL shown. If the text says "Go to my bank" but the link points to an unfamiliar domain, it's phishing.
- Unexpected attachments, especially .zip, .exe, or Office files that ask you to "enable macros".
What to do (in this order)
- Don't click any link or open any attachment.
- Don't reply to the email, not even to say it's phishing — that confirms your address is active.
- If the email pretends to be from a service you use (bank, provider, cloud), go there by typing the address directly into your browser, never from the email's link, to check whether there's a real pending matter.
- Report it to [email protected] by forwarding it as an attachment so the full technical header can be analyzed.
- Delete it after reporting.
If you already clicked or opened an attachment
Don't wait to confirm something bad happened. Disconnect the device from the network (WiFi and cable) and contact support immediately — see I think I've been hacked: first steps.