Email Safety & Phishing

Most account takeovers start with a single deceptive email. Learn to verify before you click and keep your credentials yours.

AD SLOT [BANNER]

Check the real sender

A friendly display name means nothing — look at the actual email address behind it. Phishers use lookalike domains with swapped or extra characters. If an email claims to be from a service you use, compare the domain against one you know is genuine.

Never enter credentials from a link

Legitimate verification or password requests should be completed by navigating to the official website yourself, not by clicking a link in an email. If a message pushes urgency — "your account will be closed in 24 hours" — treat that pressure as a red flag, not a reason to rush.

Verify codes and requests directly

If you receive a verification code you did not request, do not share it with anyone — no real support team will ask for it. When in doubt, log in through the official app or site and check your security activity there.

Layer your defenses

Enable two-factor authentication so a stolen password alone is useless, use a password manager so you are not typing credentials into fake forms, and use a VPN on public networks to keep your traffic private. Together these make phishing far less likely to succeed.