Do not interact first
What to do
- Leave the email unopened or close it if already opened.
- Do not click links or download attachments.
- Do not reply to the sender.
- Create a support ticket and include the sender, subject line, and why it looks suspicious.
- If you already clicked something, report that immediately in the ticket.
Red flags
- Unexpected login or password reset requests
- Urgent requests for payment or gift cards
- Messages with mismatched sender names and domains
- Links that do not match the organization they claim to be from