Suspicious messages: checks before clicking

When a message is unexpected, verify the requested action and sender’s identity first. A familiar logo, professional tone or browser padlock does not prove legitimacy.
Warning signs
Unusual urgency, payment changes, password requests and unexpected attachments justify verification. Open the service through your usual route instead of the message link.
After uncertainty or a mistake
Preserve the message and contact your organisation’s designated owner. If you shared a secret or performed an operation, report it promptly so appropriate action can follow. The official phishing guidance distinguishes responses by situation.
Prepare for next time
Keep official service channels available and protect account access. A password manager and unique secrets reduce reuse of compromised credentials.
The aim is not to recognise every fraud by appearance, but to have a reliable way to confirm sensitive requests.
How Belentia can help
Belentia offers assessments of an authorised web scope, with findings and remediation priorities. Specialist or certification audits require a separate scope.
Explore web security assessment services · Describe your project


