Spam Wipe
Spam Wipe · Clean inbox, clear mindPublished guidance · inbox defense

Spam Wipe field note

Spam Vs Phishing

Spam and phishing can both arrive without invitation, but they pose different problems. Spam is usually an unwanted message sent widely to gain attention,

A warm tactile mail-sorting console separates a crowded tray of repetitive promotional envelopes from a single deceptive envelope routed toward a red hook and credential card.

Spam and phishing can both arrive without invitation, but they pose different problems. Spam is usually an unwanted message sent widely to gain attention, traffic or sales. Phishing is a deceptive message intended to steal information, money or access. Spam and phishing differ in purpose and risk, even when they use the same delivery method.

The distinction matters because the safest response depends on the sender's aim. An unwanted promotion may need reporting or unsubscribing. A suspected phishing message requires more caution: do not follow its instructions, and check whether any account or payment information has already been exposed.

The Essential Difference

Spam relies on volume. A sender distributes similar material to many recipients in the hope that some will read it, visit a page or respond. Common examples include unsolicited promotions, irrelevant newsletters and repeated messages from unknown senders. Spam is disruptive and may include misleading material, but an unwanted message is not automatically an attempt to steal from its recipient.

Phishing relies on impersonation and manipulation. The sender pretends to be a trusted organisation, colleague or familiar contact, then creates a reason to act. The request may involve signing in, opening a file, sharing a verification code, changing payment details or sending money. The apparent sender and the story vary, but the objective is fraudulent gain.

The categories can overlap. A criminal may distribute one phishing email to thousands of addresses, making it both a bulk campaign and a deceptive attack. Classify the message by its most serious feature: if it tries to obtain credentials, funds or sensitive data through deception, treat it as phishing.

  • Likely spam: a broad promotion with no personal context and no attempt to impersonate someone you trust.
  • Likely phishing: an unexpected request for a password, code, payment, confidential file or account action.
  • Unclear: any message whose sender, destination or purpose cannot be verified independently. Handle it as suspicious until checked.

Where These Messages Appear

Email is a common channel, but the same judgement applies to text messages, messaging apps, social networks and collaboration tools. A phishing attempt may arrive as a fake delivery notice, an account warning, an invoice, a document-sharing request or a message from a copied profile. A phone notification can be as deceptive as an email.

Display names, profile photographs and logos are easy to imitate. A familiar appearance therefore proves little. Examine the full sender address or account handle, the context of the request and the destination of any link. On social platforms, check whether the account history and handle match the person or organisation you already know.

Targeted phishing can contain accurate details about a role, supplier or current project. Correct context does not make an unusual request safe. A compromised account can also send convincing messages from a genuine address, so an unexpected payment or access request still needs separate confirmation.

Warning Signs of Phishing

No single clue proves that a message is fraudulent. Look for combinations of mismatched identity, unusual pressure and a request that exposes something valuable.

Sender and context mismatches

Check whether the sender's full address matches the organisation or person named in the message. Be cautious when a business request comes from an unrelated address, when a reply address differs from the sending address, or when the greeting and subject do not fit the supposed relationship. Also ask whether you expected the message at all.

Pressure, secrecy and unusual requests

Phishing often invents an immediate consequence, such as loss of access, a failed payment or disciplinary action. Urgency is especially concerning when paired with secrecy or a request to bypass an established process. Pause if someone asks for credentials, one-time codes, gift cards, bank-detail changes, confidential files or an unplanned transfer.

Links and attachments

Link text can hide a different destination. On a device that shows it, inspect the destination before opening it. Watch for misspellings, extra words and unrelated domains. A safer route is to open a fresh browser window and use an address or bookmark you already trust. Do not rely on a padlock symbol alone; it indicates an encrypted connection, not an honest website.

Treat unexpected attachments as suspicious, including documents and archives, not only obvious programs. A file that asks you to enable active content, relax security settings or enter credentials may be attempting to install malware or capture information. Even a file from a known contact should be confirmed if it arrives without context.

Professional appearance

Spelling mistakes and poor formatting can be warning signs, but polished writing does not prove legitimacy. A well-designed message may still lead to a false sign-in page. Judge the request, identity and destination rather than the quality of the presentation.

How to Check a Suspicious Message

Verification should take place outside the message. Do not reply, call a number it supplies or follow its link to ask whether it is genuine. Instead, use a saved contact, a number from an existing statement, an official app or a website address you type yourself. The FTC recommends this approach when verifying whether a message is a phishing scam.

  1. Stop before clicking, downloading, replying or approving a sign-in prompt.
  2. Identify what the message wants: attention, credentials, money, data or access.
  3. Inspect the full sender details and link destination without opening the link.
  4. Check the request through a separate, trusted channel.
  5. Report the message using the relevant mail, platform or workplace process.
  6. Delete it after reporting unless a security team asks you to preserve it.

Unsubscribing is reasonable for a newsletter you recognise but no longer want. Do not use an unsubscribe link in a message that appears deceptive, because the link itself may be unsafe or may confirm that the address is active. Mark the message as phishing or spam through the service's reporting control instead.

If You Already Interacted

Act promptly, but use a known-safe device and reach services independently. If you entered a password, change it on the real service and change any other account that reused it. Sign out unfamiliar sessions, review recovery details and forwarding rules, and enable multi-factor authentication. Never approve an unexpected sign-in prompt or share a one-time authentication code.

If you disclosed card or bank information, contact the financial institution through its official channel and review recent activity. If money was sent, report the transaction immediately through the appropriate internal and financial processes. If identity information was exposed, follow the reporting and protection guidance provided by the relevant public authority in your country.

If you opened an unexpected attachment or installed software, disconnect the affected device from shared networks where practical and contact the responsible technical team. Do not continue using the device for sensitive work until it has been checked. CISA describes malware as software used to gain unauthorized access, steal data, disrupt services, or damage networks.

When reporting an incident at work, state what happened, when it happened and what information was entered or opened. Accurate details help responders contain the problem. Hiding a mistake delays investigation and can allow the same message to reach other people.

Reducing Future Risk

Individuals should use unique passwords, a password manager and multi-factor authentication. Keep devices, browsers and applications updated. Review account alerts through the official service rather than through message links. These habits reduce the damage if a password is captured or a device is exposed.

Organisations need several layers of protection. Mail filtering can block known malicious senders, dangerous attachments and suspicious destinations, while domain authentication can make some forms of sender impersonation harder. Access should be limited to what each role needs, and important payment or account changes should require independent verification.

Training should focus on repeatable behaviour rather than memorising a list of slogans. Staff need a simple reporting route, permission to pause unusual requests and practice checking through another channel. Short exercises are useful when they teach how to inspect a sender, verify a payment change and report an accidental click without delay.

The practical rule is simple: unwanted promotion is usually spam; deceptive impersonation intended to take information, money or access is phishing. When the category is uncertain, do not engage with the message. Verify the request independently, report it through the proper channel and protect any account that may have been exposed.