MALWARE AND PHISHING CyberArtical Editorial Team

Three checks that settle whether an email is real

Three padlocks of different sizes on a surface lit from one side in red and the other in green

You do not need a taxonomy of attack types to deal with a suspicious email. You need three checks you can run in under a minute, in the same order every time, that do not depend on how convincing the message looks. This is that routine, drawn from what CISA, the FTC and the FBI actually publish.

The routine

  • Check one — the ask. Urgency, dire consequences, or a request for personal or financial information. CISA lists all three as indicators.
  • Check two — the address. Misspellings, wrong domains (a .gov that ends in .com), near-misses like amazan.com, and untrusted shortened URLs.
  • Check three — the channel. “Look up another way to contact the company or person directly.” Never the number or link in the message.
  • Not a check: grammar and spelling. CISA says AI-written lures now have both correct.
  • Not a check: the padlock. The FBI says do not trust a site just because it shows a lock icon or “https”.
  • Finish with resist, report, delete — and do not reply.

For people who want a procedure, not a feeling

Anyone who receives email at work or at home and wants a decision procedure rather than a general sense of caution. It works for texts too, with one substitution: report those to SPAM (7726) rather than by email.

It is deliberately short. A ten-point checklist gets abandoned at point three on a busy morning, which is precisely when the messages that matter arrive.

Check one: what is being asked of you

Before looking at anything technical, read what the message wants. CISA’s indicators are urgent or emotionally appealing language claiming dire consequences, and requests to send personal and financial information.

The FTC’s pretext list is the same idea in specifics: they say there has been suspicious activity or log-in attempts on your account and there hasn’t; they say there is a problem with your account or payment information and there isn’t; they ask you to confirm personal or financial information you don’t need to confirm; they send an invoice you don’t recognise, a link to make a payment where the link has malware, an offer of a government refund, or a coupon for free stuff.

If the answer to “what does this want” is money, credentials or personal data, and it wants them soon, you are already at check three. Check two is optional at that point.

Check two: where it actually points

  1. Read the sender address in full, not the display name.
  2. Read the link’s domain from the right — the part just before the first single slash is where you would land.
  3. Look for the FBI’s specific failure: an address that should end in .gov ending in .com, or any other wrong domain or misspelling.
  4. Treat a shortened URL as unresolved, not as neutral. CISA lists untrusted shortened URLs as an indicator in itself.
  5. Ignore the padlock. It attests to encryption in transit only, and the FTC notes scammers encrypt fake sites specifically so they look safe.

Check three: verify on a channel they did not choose

This is the check that decides it, and the only one that still works when the message is flawless. CISA’s rule: rather than using the contact details in the message, look up another way to contact the company or person directly.

In practice that means the number printed on your card, the phone number on a statement you already had, the app on your phone, or a web address you type yourself. The FTC’s habit for links is the same principle — type the URL directly rather than clicking.

If the message is genuine, this costs you two minutes. If it is not, it ends the attack completely, regardless of how good the forgery was.

How often to redo this

Every time. That is the point of keeping it to three checks — a routine you run selectively is a routine that fails on the one message that mattered.

The routine itself needs revisiting roughly whenever the sources do. The most recent change was significant: CISA’s addition of the AI caveat means any checklist still leading with spelling errors is out of date, and should be corrected rather than supplemented.

What this routine does not cover

It does not help with a genuine account that has already been compromised and is sending real mail from a real address. It does not detect a breach at a company you deal with. And it does nothing about a message you already acted on last week.

For that last case: if you may have downloaded something, update your security software and run a scan. If you handed over a Social Security, credit card or bank account number, go to IdentityTheft.gov. Report the message at ReportFraud.ftc.gov, forward it to reportphishing@apwg.org, and file internet crime at IC3.gov.

One further limit is worth naming. The routine tells you a message is suspicious; it never tells you a message is safe. Something that passes all three checks has merely failed to trigger them. If the request itself is unusual, verify it anyway.

Sources: CISA — Recognize and report phishing · FTC — How to recognize and avoid phishing scams · FBI IC3 — PSA on the HTTPS padlock (I-061019-PSA) · FTC — Are public Wi-Fi networks safe? · FTC IdentityTheft.gov

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories