Phishing guide

How can I inspect a sender, link, attachment, or QR code safely?

Safely evaluate sender addresses, destination domains, attachments, QR codes, and login pages without supplying sensitive data.

Content reviewed
Short answer

Inspect without following the message’s path: reveal the full sender, read the actual destination when your client can show it without opening it, identify the controlling domain, and verify the claimed event through an independently opened app or site.

What you may be seeing

Messages can hide a full email address behind a display name and a destination behind button text, shortened URLs, or QR codes.

Attachments and QR codes reduce what you can inspect at a glance. Treat an unexpected item as unverified; do not open it merely to decide whether it is safe.

Signals to inspect—and why they matter

Strong evidence

The controlling domain differs from the claimed organization

Read a hostname from right to left. In login.brand.example, the owner of example controls the site; the word “brand” is only a subdomain.

The login page requests a secret unrelated to the verified task

Passwords, one-time codes, recovery codes, payment details, and identity data should only be entered after independently reaching the intended service.

Contextual signals

The attachment or QR code was unexpected

Unexpected content raises uncertainty but is not proof. Verify the sender and business context through a known channel without opening the item.

The message has mistakes—or is perfectly polished

Writing quality is weak evidence in both directions. Legitimate messages can contain mistakes and malicious messages can be professionally produced.

Contextual signals can justify caution, but they do not authenticate or condemn a message by themselves.

Safe verification steps

  1. Reveal the full From and Reply-To fields using your mail client’s details view.
  2. Use the client’s built-in destination preview only if it can be viewed without navigating. Do not visit a suspicious URL to analyze it.
  3. Find the hostname and identify the registrable domain; ignore brand words in the path, query string, or left-side subdomains.
  4. For a QR code, do not scan it just to discover whether it is safe. Verify the claimed task independently or use an organization-approved analysis process.
  5. For an attachment, confirm the sender and expected business process through a known contact method before opening it.

What to do next

  • Navigate independently to the claimed account or transaction.
  • Use the organization’s reporting control while preserving the original message when policy requires it.
  • If you already opened, submitted, approved, or paid, follow the action-specific response guide.
Evidence

Authoritative references

Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.

Limitations and uncertainty

What this guide cannot establish

  • A correct-looking domain does not rule out a compromised legitimate account or abused service.
  • URL shorteners, redirects, internationalized domains, and mobile interfaces can make manual inspection difficult. When uncertain, do not proceed.
  • Baitaphish does not accept uploads of real suspicious messages, attachments, QR codes, or credentials.