Golden rules for avoiding phishing
Phishing is a scam that tricks you into handing over passwords, money, or personal details by pretending to be someone you trust.
Rule one: slow down when you feel rushed
Almost every phishing attempt shares one feature. It pushes you to act fast. Your account is locked. A payment failed. A prize expires tonight. The rush is the point. It stops you from thinking clearly and checking the details.
When a message makes your heart beat faster, treat that feeling as a signal to slow down, not speed up. Real companies give you time. They do not threaten to close your account in the next ten minutes. Take a breath and read again before you click anything.
Rule two: check who is really contacting you
A name is easy to fake. The address behind it is harder.
- Read the full email address, not just the display name. A message signed as your bank can come from a random address that has nothing to do with the bank.
- Hover over a link before clicking to see where it truly goes. On a phone, press and hold to preview the address.
- Be careful with lookalike domains. A brand name with a swapped letter, an extra word, or an unusual ending is a common trick.
- If a message asks you to confirm something, contact the company yourself using a number or address you already have. Do not use the contact details in the message.
Rule three: guard your passwords and codes
Your passwords and one-time codes are the keys to your accounts. Treat them that way.
- No real company will ask for your full password. Support staff do not need it and will not ask.
- Never share a one-time code or read it aloud to anyone. A code that arrives while someone is on the phone with you is a red flag.
- Never approve a sign-in request or a device code you did not start yourself.
- Never type a wallet recovery phrase into a website. That phrase controls your funds, and no genuine service needs it.
Rule four: reach sites your own way
The link in a message is where many scams begin. You can sidestep them by not using the link at all.
- To sign in, open a new tab and type the address yourself, or use a bookmark you saved before.
- Use a password manager. It fills your details only on the exact site they belong to, so a lookalike page gets nothing.
- Do not judge a site by its logo or padlock. Both are easy to copy. Read the main domain in the address bar instead.
Rule five: build a safety net
Even careful people slip once in a while. A few defenses set up in advance limit the damage.
- Turn on two-step verification on your important accounts. It blocks most sign-ins even if a password leaks.
- Use different passwords for different accounts so one leak does not open the rest.
- Keep your browser and devices updated so known weaknesses stay closed.
- If you slip, act fast. Change the password on the real site, then watch the account for activity you do not recognize.
A second set of eyes helps too. Fish Catcher is a free, open-source browser extension that checks sites on your device and warns you in plain language when a page looks like phishing. It shows a simple color, from green for no suspicious signs up to red for strong signs of a fake. It needs no account, keeps its default checks on your own computer, and never blocks a page. The final choice always stays with you.
Common questions
Isn't phishing easy to spot from bad spelling and clumsy design?
Not anymore. Many scams now look polished and read cleanly. Do not rely on typos as your only test. The steady habits above work even against a message that looks perfect.
I only clicked a link but did not type anything. Am I at risk?
Often the click alone is low risk, and the danger comes when you enter details or open a file. Still, close the page, do not sign in, and if the link tried to download something, do not open it. Run a scan if you are unsure.
Which single habit protects me the most?
Turning on two-step verification, together with not signing in from links in messages. That pair stops the most common attacks even when a password slips out.