Simple Ways to Spot a Phish

Not sure about an email?

Scout and phish

👀 Quickly Check…

  • Pause for a moment
    Don't click right away, take a breath.
  • Check the sender’s address
    Open the email details and read the full email address, not just the name.
  • Ask yourself: was I expecting this?
    If the message is unexpected, be extra cautious.
  • Hover over any links
    Preview the web address and make sure it corresponds and matches the sender.
  • Don’t log in from emails
    Go to the website directly instead of using email links.
  • Watch for urgency
    Messages that say “act now” or claim your account is locked are common warning signs.
  • Skip the unexpected attachments
    If you weren’t expecting a file, don’t open it.
  • Look for mistakes
    Spelling errors or unusual wording can signal a phishing attempt.
  • Never share passwords
    No real service will ask for your password by email.
  • Report it if unsure
    Do not guess. Report the message to the Information Security team.

Once you’ve gone through these ten simple steps, you’ll have a better idea of whether the email is suspicious or not. When in doubt, always report it.

To report a suspicious email, click the three dots in the top right corner of the email and select the fishing hook from the dropdown, or forward to phishing@nd.edu. Reporting helps protect the whole campus!