A real life example of a phishing email, and what to do if you get one.
Phishing Checklist
- No legitimate company will ask you to verify yourself in an email.
- The domain name of the sender email doesn’t match the site it claims to be from. It might be very similar, such as WELLSFARG0.com (that is a zero in the name)
- Poor grammar and punctuation
- Sloppy formatting
- An image instead of email text
- Instills a sense of urgency
Do
- View the Source and copy the header. If you don’t know how, search the name of your email service with “full email header”. Example: Gmail full email header
- Forward the email, with the source to the bank or the organization impersonated in the email.
- Report it to the FTC. Forward phishing emails with source to [email protected]
- Make sure your email does not load external images
Do Not
- Click on a Link or Image
- Click or download an attachment
- Reply