Golden rules for avoiding phishing
Phishing tricks you into handing over passwords, money, or personal details by pretending to be someone you trust. Five habits stop most of it.
Rule one: slow down when you feel rushed
Almost every phishing attempt pushes you to act fast. Your account is locked. A payment failed. The rush stops you checking the details. Treat a racing heart as a signal to slow down. Real companies give you time.
Rule two: check who is really contacting you
- Read the full email address, not only the display name. A message signed by your bank can come from an unrelated address.
- Hover over a link before clicking to see where it really goes. On a phone, press and hold.
- Watch for lookalike domains: a swapped letter, an extra word, or an unusual ending.
- If a message asks you to confirm something, contact the company through a number you already have, not the one in the message.
Rule three: guard your passwords and codes
- No real company will ask for your full password.
- Never share a one-time code or read it aloud. A code that arrives while someone is on the phone with you is a red flag.
- Never approve a sign-in request or a device code you did not start yourself.
- Never type a wallet recovery phrase into a website.
Rule four: reach sites your own way
- To sign in, open a new tab and type the address yourself, or use a bookmark.
- A password manager fills your details only on the exact site they belong to, so a lookalike page gets nothing.
- Do not judge a site by its logo or padlock. Read the main domain instead.
Rule five: build a safety net
Even careful people slip. A few things set up in advance limit the damage.
- Turn on two-step verification on your important accounts. It blocks most sign-ins even if a password leaks.
- Use a different password for each account, so one leak does not open the rest.
- Keep your browser and devices updated.
- If you slip, change the password on the real site right away and watch the account.
Fish Catcher is a second set of eyes: it checks pages on your device and warns you in plain language when one looks like phishing. It never blocks a page, so the final choice stays with you.
Common questions
Isn't phishing easy to spot from bad spelling and clumsy design?
Not anymore. Many scams look polished. The habits above work even against a message that looks perfect.
I only clicked a link but did not type anything. Am I at risk?
Often low. The danger comes when you enter details or open a file. Close the page, do not sign in, and do not open anything it downloaded.
Which single habit protects me the most?
Two-step verification, together with not signing in from links in messages. That pair stops the most common attacks.