REFERENCE / PRINTABLE
Phishing Identification Checklist
Print this one-page reference and post it at every workstation. Use the 10-second scan before you click.
The 10-Second Phishing Scan
Before you click any link, open any attachment, or act on any request, scan the email for these red flags. If you see even one, stop and verify.
Urgency or fear: Does the email pressure you to act immediately? Phrases like your account will be closed, payment overdue, or final notice are designed to make you panic.
Mismatched sender: Does the display name match the email address? Hover over the sender name to see the actual address. Look for look-alike domains like @paypa1.com instead of @paypal.com.
Unexpected links: Were you expecting this link? Hover over it to see the real destination URL before clicking. If the URL does not match the organization, do not click.
Unexpected attachments: Were you expecting this attachment? Even from someone you know, their account may be compromised. Verify by phone or text before opening.
Generic greeting: Does it say Dear Customer or Dear User instead of your name? Legitimate organizations usually know who you are.
Credential or payment requests: Does it ask for passwords, MFA codes, wire transfers, or gift cards? No legitimate organization will ever ask for these by email.
Spelling or grammar errors: While AI has made phishing more polished, errors still happen. Any mistake in a professional email is a red flag.
Reply-to address: Does the reply-to address differ from the sender address? This is a common tactic to redirect responses to the attacker.
If You See a Red Flag
Do This Immediately
- Do not click. Do not open attachments. Do not reply.
- Report it. Use the Report Phishing button or forward to your IT team.
- Delete it after reporting.
- Verify by phone if the request involves money or data. Call the person at a known number, not from the email.
- When in doubt, do not click. It is always better to verify than to click and regret.
Common Phishing Types
- Email phishing: Mass emails pretending to be from banks, vendors, or IT departments.
- Spear phishing: Targeted emails that reference real projects, colleagues, or vendors.
- BEC (Business Email Compromise): Emails impersonating executives asking for wire transfers, gift cards, or sensitive data.
- Smishing: Phishing by text message, often fake package delivery or bank alerts.
- Vishing: Phishing by phone, often tech support scams or government impersonation.
This checklist is a supplement to Module 01: Phishing and Business Email Compromise. Complete the full module for interactive training and knowledge checks.