cyber&
Back to Resources

How to verify a suspicious message before acting

Pause, inspect the request, and verify it through a trusted channel before you act.

Start with the situation

A convincing message can use a real logo, a familiar name, or accurate work details. Those signals do not prove that the request is genuine.

The decision to make

Pause the request and verify its sender, destination, and purpose through a channel you already trust.

A practical sequence

  1. Do not click, reply, open an attachment, scan a QR code, or approve a request while you check it.
  2. Expand the real sender address and preview the destination without opening it. Look for subtle domain changes and unexpected file types.
  3. Open the known official site or contact the person using a saved number or directory entry—not details supplied by the message.
  4. Use your organization’s reporting route. If you already acted, say exactly what happened.

Real-world examples

  • A supplier asks for new bank details: call the established finance contact.
  • A password-expiry message arrives: open the service from a trusted bookmark.
  • An unexpected MFA prompt appears: deny it and report it rather than approving it to stop the notifications.

Common mistakes

  • Trusting a display name, logo, or HTTPS padlock as proof.
  • Calling a number or using a link contained in the suspicious request.
  • Forwarding the message widely instead of using the approved reporting route.

What to do next

If you clicked, entered information, or approved something, stop treating this as message verification and follow the security-mistake response guide.

Urgency is a reason to verify, not a reason to skip verification.

Trusted official references

  • CISA

    Recognize and Report Phishing

    Practical guidance for recognizing suspicious messages and reporting them safely.

    View official source
  • UK NCSC

    Phishing scams: how to spot and report them

    Public guidance on checking and reporting suspicious emails, texts, calls, websites, and adverts.

    View official source