Stay Safe Online

Staying Safe with Email

Recognise dangerous emails, avoid attachments that carry viruses, and keep your inbox clean.

Start the guide

Build confidence Global

Start with the first step, try it on your own device, and use the next-step section at the end if you want a clear follow-on guide.

Guide details and who this is for

Guide details

Published
January 15, 2025
Country scope
Global

Who this is for

Best for anyone checking whether a message, website, payment, or request is safe.

Be careful

Pause if anything asks for passwords, OTP codes, money transfers, or urgent action. Real organisations do not need you to panic to prove they are genuine.

Before you begin

What this guide helps you do

This guide shows the main warning signs to check before you click, reply, log in, share details, or pay.

Best time to use it

Use it when something feels urgent, unusual, or asks for personal information, codes, or money.

Common mistake to avoid

Do not act while pressured. Slow down first, then verify the sender, website, or request.

Helpful tech words

Open a plain-English term first if you need it

Browse all jargon help

Staying Safe with Email

Email is one of the most common ways scammers try to reach you. Learning to spot a dangerous email protects your personal information and your device.

Warning signs in an email

Check the sender’s email address carefully

  • Hover over or tap the sender name to reveal the full email address.
  • Genuine organisations normally use a domain that matches their official website.
  • Scammer addresses often add words, swap letters, or use free email services to imitate a trusted sender.

Urgency and threats

  • “Your account will be closed in 24 hours.”
  • “Immediate action required — your national ID has been flagged.”
  • “You have an outstanding fine. Pay now to avoid arrest.”

Real government agencies and banks do not threaten you by email.

Requests for personal information No legitimate organisation will ask you to reply to an email with your:

  • Password
  • Bank account number
  • OTP or verification code
  • Credit card number

Links in emails Before clicking any link, look at where it actually goes:

  • On a computer: hover your mouse over the link without clicking — you will see the real address at the bottom of the screen.
  • On a phone: press and hold the link to see a preview of the address.

If the address does not match the organisation, do not click.

Safe email habits

  1. Do not click links in unexpected emails — even if they look official. Go directly to the website by typing it yourself.
  2. Do not open attachments from senders you do not recognise or did not expect.
  3. Use a spam filter — Gmail and Outlook automatically catch most spam. Check your Spam folder occasionally but be careful opening anything in it.
  4. Keep your email password strong — use a password manager or a long passphrase.
  5. Enable 2-step verification on your email account — this prevents access even if someone knows your password.

Setting up 2-step verification on Gmail

  1. Go to myaccount.google.com on your phone or computer.
  2. Tap Security2-Step Verification.
  3. Follow the steps to link your phone number — Google will send an SMS code when you sign in from a new device.
  1. Do not enter any information on the page that opened.
  2. Close the browser immediately.
  3. Run a security scan if you have antivirus software.
  4. Change your email password.
  5. If you entered banking details, call your bank immediately.
Try it yourself — follow along now Click to expand

Follow along and tick each step as you go. You can use a real device right now!

✨ Tip: Ticking these boxes only works on your screen — nothing is saved or sent anywhere.

You finished this guide

What do you want to do next?

Move to the next recommended guide if you want a clear progression, or ask a real person if you would rather check before trying something new.