Glossary Security

Phishing

Phishing is a scam in which attackers pose as a trusted organisation or person, usually by email or text, to trick you into revealing credentials or money.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

Typical signs are urgency, a link to a look-alike domain, an unexpected attachment and a mismatch between the displayed and real sender. Defences include checking the actual address, never signing in through an emailed link, Multi-factor authentication (MFA) (which limits what a stolen password gives) and DMARC on your own domain. A defanged URL, with dots and the scheme altered, is safe to share when reporting.

Try these tools

See also

  • Glossary Social engineering
    Social engineering is manipulating people, rather than breaking technology, to get them to reveal information or take a harmful action.
  • Glossary Multi-factor authentication (MFA)
    Multi-factor authentication (MFA) requires two or more kinds of proof to sign in.
  • Glossary DMARC
    DMARC is a DNS policy that tells receivers what to do with email that fails SPF and DKIM alignment, and where to send reports about it.
  • Guide How Email Authentication Works: SPF, DKIM and DMARC
    What SPF, DKIM and DMARC each check, what their DNS records look like.
AdSense Placeholder
Slot: footer_leaderboard