A phishing email tries to make you act before you verify. In Gmail, the safest response is to slow down: inspect the full sender address, treat urgent requests as untrusted until confirmed through another channel, avoid opening unexpected links or attachments, and use Gmail’s Report phishing action when the message is suspicious.
The fastest safe check
- Pause if the message creates urgency, fear, secrecy, or an unusual reward.
- Expand the sender details and read the complete email address and reply-to address.
- Do not use the phone number or sign-in link in the message. Open the organization’s known app or website yourself.
- Verify money, credential, document-sharing, or account-recovery requests through a second channel.
- Report the message in Gmail, then follow your employer’s incident process if it is a work account.
1. Read the real sender address
A familiar display name is not proof of identity. A message can say “Google,” “your bank,” or a coworker’s name while using an unrelated address. Look for misspellings, substituted characters, unexpected subdomains, and a reply-to address that differs from the visible sender.
Gmail warns about spoofed addresses and unconfirmed senders in some cases. Google’s spam and phishing guidance says not to reply or open links when an address looks similar to a known sender or Gmail cannot confirm the sender. A missing warning does not prove safety.
2. Treat urgency as a request to verify
Phishing commonly claims that an account will close, a payment failed, a document is waiting, a refund is expiring, or an executive needs an immediate transfer. The pressure is part of the attack. A real deadline can survive a one-minute verification through a trusted channel.
For a coworker or vendor, call a known number or start a new message to an address you already have. For a service, open its official app or type the known domain yourself. Do not verify using contact information supplied by the suspicious message.
3. Inspect links without following them
On a Mac, hover over a link to preview its destination. Compare the registered domain—the part immediately before the first slash—with the organization you expect. Shortened links, lookalike domains, unfamiliar file-sharing sites, and encoded redirect URLs deserve extra caution.
A link using HTTPS only means the connection to that site is encrypted. It does not prove that the site belongs to the company shown in the email.
4. Be skeptical of attachments and shared documents
Unexpected invoices, password-protected archives, macros, HTML attachments, and “secure message” files are common delivery paths. Confirm the sender and the reason for the file before opening it. A cloud-document invitation can also be phishing if it leads to a fake sign-in page.
If a work account receives a suspicious attachment, preserve the message and follow the organization’s reporting process instead of forwarding the attachment casually.
5. Never enter credentials from an email path
A legitimate security notice may alert you to a problem, but you can respond from the service’s known app or website. If a page opened from email asks for a password, passkey, recovery code, payment card, or OAuth approval, close it and navigate independently.
Read OAuth consent screens as carefully as password pages. Confirm the app name, developer, requested Google services, and level of access. A permission prompt can grant ongoing mailbox access even when no password is shared.
6. Check the request, not only the grammar
Modern phishing can be grammatically polished and visually accurate. Stronger signals are behavior and context: an unexpected change in payment instructions, a new bank account, secrecy, a request to bypass process, an unfamiliar login location, or a conversation that suddenly changes tone.
For financial requests, verify the payee and account details through an established process. Do not rely only on a reply inside the same possibly compromised email thread.
7. Use Gmail’s reporting tools
Google advises users not to reply or open links in suspicious messages and to report phishing when the sender cannot be trusted. Open the message, use the More menu, and choose Report phishing. Google’s Gmail help for suspicious mail explains the warnings and actions.
Reporting spam and reporting phishing are related but not identical. Spam is unwanted mail; phishing is an attempt to steal information, money, access, or trust. Use the more specific phishing report when that is the risk.
If you already clicked or replied
- Close the page and do not continue entering information.
- If you entered a Google password, change it from your Google Account and review active sessions.
- If you granted an app access, review Google Account third-party connections and remove access.
- If you disclosed payment or identity information, contact the relevant institution through a known channel.
- For a work account, notify security or IT promptly and preserve the original message.
Google lets you review and remove third-party connections at any time. Its account-access guidance notes that removing access stops future access but may not delete data an app already copied.
Screening reduces exposure, not the need to verify
Separating mail from unfamiliar senders can reduce inbox noise, but a trusted sender can be compromised and a familiar brand can be spoofed. Use sender screening as an attention boundary, not an authentication system. Read how ZenMail’s Screener handles first-time senders and how ZenMail Shield approaches suspicious messages.
Before connecting any client that can read or modify Gmail, use the Gmail email-client privacy checklist and compare the best Gmail clients for Mac.
