Read subject lines as if they were billboards selling emotion, then check who paid for the ad by inspecting the sender’s domain. Compare it to the organization’s real domain on a trusted website, not the email. If anything feels off, pause, screenshot, and ask peers before proceeding.
Hover without clicking and read the full URL slowly, left to right. Look for subtle typos, extra subdomains, unexpected country codes, and tracking parameters that mask destinations. When in doubt, open a new tab, navigate manually, or use a secure preview tool before interacting.
Treat attachments like packages delivered to a shared office: verify the sender, expectation, and purpose before opening. Favor cloud previews over downloads, and quarantine anything surprising. If testing is necessary, use an isolated sandbox or dedicated device, then report suspicious items promptly.