Skip to content
?
Tech & Cybersecurity

What to Do If You Receive a Scam Email

Receiving a phishing or scam email can be alarming. Follow these immediate steps to secure your accounts, report the message, and protect your personal information.

3 min read • Written by Administrator • Reviewed by Mohamed IDBRAHIM • • • 6 reads

Quick answer

5 steps — read this before anything else

  1. 1

    Do not click any links, open attachments, or reply to the email.

  2. 2

    Mark the message as phishing or spam in your email provider.

  3. 3

    Change your passwords immediately if you submitted credentials on a fake site.

  4. 4

    Notify your bank right away if financial details were shared.

  5. 5

    Report the email to official cybersecurity authorities.

Receiving a scam or phishing email is a common online threat designed to trick you into revealing sensitive personal information, such as passwords, credit card numbers, or government identification details. Knowing how to handle these messages safely protects your identity and your devices.

What to Do First

  1. Stop and do not interact: Avoid clicking any links, opening attachments, or replying to the sender. Simply interacting with a malicious message can confirm your email address is active or infect your device with malware.
  2. Verify the sender address: Check the actual email address behind the display name. Scammers often use domain names that closely imitate legitimate organizations or companies.
  3. Mark as phishing or spam: Use your email provider built-in options to flag the message. Flagging helps train automatic security filters to block similar emails in the future.
  4. Report the scam: Report the email to official fraud prevention platforms such as the Federal Trade Commission (FTC) or the Anti-Phishing Working Group (APWG).

If You Clicked a Link or Provided Information

  1. Change affected passwords immediately: Update the password for any account that may have been compromised. Use a strong, unique password and turn on multi-factor authentication (MFA).
  2. Contact your financial institutions: If you shared banking details or credit card numbers, call your bank immediately to lock cards, block unauthorized transactions, and monitor account activity.
  3. Run a full malware scan: If you downloaded an attachment or clicked a suspicious link, run an updated antivirus scan on your computer or mobile device.
  4. Place a fraud alert: If sensitive identity details like your Social Security number or national ID were exposed, contact major credit bureaus to place a fraud alert on your credit file.

What NOT to Do

  • Do not call phone numbers inside the email: Always look up official customer service numbers directly from an official website or payment card.
  • Do not forward the email to friends or family: Forwarding suspicious emails increases the risk that someone else might accidentally click a dangerous link.
  • Do not attempt to confront the scammer: Replying confirms that your inbox is actively monitored, leading to a higher volume of targeted attacks.

How to Prevent Future Phishing Attempts

  • Enable Multi-Factor Authentication (MFA): Add secondary verification to all primary online accounts for enhanced protection.
  • Keep software updated: Ensure your operating system, web browser, and security software receive automatic updates.
  • Use a password manager: Password managers automatically detect domain mismatches and will not auto-fill credentials on fake login websites.

Taking quick action limits potential damage from phishing attempts. If you suspect identity theft or financial loss, file an official report with local law enforcement and federal consumer protection agencies immediately.

Sources & references

Information verified with official organizations.

Fact-checked: Not yet

Spotted an error? Report it — we correct factual mistakes promptly.

Based on your reads

Recommended for you

Guides that match your recent interests.

Cookies & advertising

We use cookies to measure traffic and show personalized ads through Google AdSense. You can accept or decline. Learn more