Suspicious-message guide

Is this email phishing?

Treat unexpected urgency as a reason to slow down. You can verify most messages without opening an attachment, clicking a link, replying, or sharing the message with HackProof.

If you already entered a password: go directly to the real service, change that password, sign out other sessions, turn on MFA, and change any other account that reused the password.

A two-minute safe check

  1. Do not use the message’s controls. Avoid links, attachments, QR codes, reply addresses, and phone numbers in the message.
  2. Open the service independently. Use its official app, a saved bookmark, or type the known address yourself. Check alerts or account messages there.
  3. Inspect the real sender address. A familiar display name is not proof. Look for misspellings, unrelated domains, or unusual reply-to addresses.
  4. Question pressure and unusual requests. Requests for passwords, recovery codes, gift cards, crypto, remote access, or immediate secrecy are high-risk.
  5. Verify through a separate channel. Contact the person or organization using a number or address you already trust—not one in the message.

What HackProof does not do

HackProof does not accept pasted message bodies, headers, links, or attachments. Those can contain personal data, tracking tokens, or hostile instructions. Automated classification can also be wrong, so HackProof does not label a message “safe.”

Report and remove

Use your mail provider’s built-in phishing report control after verifying the message is suspicious. If the message impersonates a bank, employer, or government agency, use that organization’s official reporting channel.