The email is not the authority
Never use an email to prove that same email is real.
Do not trust its link, reply address, attachment, or phone number. Open the official app, type the known website yourself, or call a number you already trust.
Six red flags that matter
- Unexpected ask: You did not request the reset, invoice, delivery, or refund.
- Pressure: It threatens loss, arrest, suspension, or a missed deadline.
- Wrong sender: The domain is misspelled, unrelated, or hidden behind a familiar name.
- Wrong destination: The link leads somewhere different from the company it claims to represent.
- Unwanted file: It includes an invoice, document, or attachment you did not expect.
- Money or secrets: It asks for a password, security code, payment, gift card, or crypto.
A real logo proves nothing. It can be copied in seconds.

Verify without touching the email
- Close or minimize the message.
- Open the official app or type the company's known address yourself.
- Check the account for the alert, charge, delivery, or request.
- For a person you know, start a new call or message using saved contact details.
If the claim does not appear through a trusted channel, treat the email as hostile.
If you already clicked
- Stop. Do not enter more information.
- Change any exposed password from the official site, make it unique, and enable multi-factor authentication.
- Call your bank or payment provider immediately if you shared payment details or sent money.
- Update your security software and run a scan if you opened a file or downloaded anything.
- Mark the email as phishing and report the fraud.
Use a screenshot before you act
isReal checks suspicious messages and explains the pressure tactics, impersonation clues, risky destinations, and safer next step in plain language.
See how the isReal screenshot checker works