Short answer
Phishing often uses fake emails, text messages or websites that appear to come from a trusted organization.
Common warning signs
Urgency, threats, unexpected attachments, strange domains and demands for quick sign-in are common signs.
Check the domain
Look carefully at the browser address. A small spelling difference can mean you are on the wrong website.
Practical protection
Use a password manager, 2FA, an updated browser and go to the website yourself instead of clicking suspicious links.
Common questions
Can phishing sites use HTTPS?
Yes. HTTPS protects the connection but does not guarantee the website is legitimate.
What should I do if I clicked?
Change passwords, check the account, enable 2FA and contact the provider if sensitive data was entered.