Scams
How to read a phishing message before it reads you
Phishing works on timing and emotion far more than on typos. Here is a practical way to check a message in under thirty seconds.
The advice to 'look for spelling mistakes' has aged badly. Modern phishing messages are well written, correctly branded, and often arrive at a moment when the request seems plausible — right after you ordered something, right before a tax deadline, right when a colleague would reasonably ask.
A more durable habit is to check structure rather than style.
The thirty second check
Ask four questions in order. If any answer is uncomfortable, stop.
- What is this message asking me to do right now? Legitimate organisations rarely need an action within minutes.
- Where does the link actually go? Long-press or hover to see the real host. Look at the domain immediately before the first single slash, not at the words in the link text.
- Did I initiate this? An unexpected verification code, invoice, or delivery fee is a prompt to check independently.
- Can I verify through a channel I chose? Open the app or type the address yourself instead of following the link.
Urgency is the tell
Almost every successful scam compresses your decision time. Account suspension in 24 hours, a package held at customs, a manager who needs gift cards before a meeting. The pressure is not incidental — it exists specifically to stop you doing the check above.
Treat urgency itself as the warning sign, independent of how convincing the rest of the message looks.
If you already clicked
Clicking a link is not automatically a compromise. Entering credentials is. If you entered a password, change it immediately on the real site, sign out all other sessions, and check whether recovery details such as backup email or phone number were altered.
Then write down what happened while it is fresh. If the incident later needs reporting to a bank or a platform, the dates and screenshots you captured in the first hour are worth far more than a reconstruction a week later.
Keep reading
Fundamentals
Password reuse is the breach that keeps happening to you
Most account takeovers do not start with a clever attack on your account. They start with a leaked password from somewhere else entirely.
Architecture
What end-to-end encryption does not protect
Encryption is not a single property that a product either has or does not have. Knowing where it stops is what makes it useful.
Safety
Documenting online harassment so a report actually goes somewhere
Platform reports and police complaints both fail for the same reason: missing dates, missing context, missing links. Here is what to capture.