How to recognize a fake password-reset message without clicking
Fake password-reset messages often combine a familiar brand, an alarming request, and a link that leads somewhere else. I’ll explain how sender details, URLs, urgency, authentication alerts, and account activity fit together so you can verify safely.
A password-reset message can look convincing because it imitates a real security notification at the moment you’re worried about losing access. The safest response isn’t to decide whether the message “looks right” at a glance. Instead, treat it as a set of clues: who sent it, what it asks you to do, where its links lead, and whether your account shows any related activity.
The goal isn't to prove that a message is fake from one detail alone. Legitimate services can use unfamiliar sending addresses, and a real password reset can arrive when you didn’t request one because someone else entered your email address. The useful habit is to avoid the message’s links and verify the situation through a channel you open yourself.
Start with the request, not the link
Ask whether you initiated a password reset. If you did, a message from the service may be expected, but that still doesn’t make every email or text genuine. If you didn’t request one, the message deserves extra caution. It could be a phishing attempt designed to make you sign in on a fake page, or it could mean that someone tried to start a reset using your address.
A genuine unexpected reset message doesn't automatically mean that an attacker changed your password. Many services send a reset email merely because a reset form was submitted. The important question is what happened next. Check the account through its official app or by typing the known website address yourself rather than using the message.
A message that says your account will be deleted, locked, or compromised within minutes is using urgency to prevent careful inspection. Security teams do sometimes notify users about important events, but urgency isn't evidence of authenticity. It is a reason to slow down and verify independently.
Inspect the sender details
The displayed sender name is only a label. A message can show a familiar company name while coming from an unrelated address. Open the message details or expand the sender field and examine the complete address, including the domain after the @ symbol.
Look for small changes such as an extra word, a substituted letter, an added hyphen, or a different ending. An address using example-support.com isn't the same as one using the company’s official domain, even if the message uses the company’s logo and colors. Be especially cautious when the sender’s domain belongs to a free email provider or an unrelated business.
Sender information is useful, but it isn't conclusive. Email addresses can be forged or messages can pass through legitimate delivery systems that make the visible details confusing. Don’t treat a familiar-looking address as permission to click. Use it as one piece of evidence alongside the link, wording, and account activity.
Examine links without opening them
A password-reset message usually wants you to select a button such as Reset password, Secure account, or Review activity. That button may display a trustworthy destination while actually leading to a different address.
On a computer, place your pointer over the link without selecting it and read the destination shown by your browser. On a phone or tablet, you can often press and hold the link to preview its destination, although the exact behavior depends on the app. If you’re unsure how your app previews links, don’t test it by tapping the message; open the service another way instead.
Read the important part of the address carefully. The real domain is generally the portion immediately before the first single slash after the domain name. For example, in https://login.example.com/account, example.com is the relevant domain. In https://example.com.account-check.example.net, the actual domain is example.net, not example.com.
Watch for shortened links, long strings of unexplained characters, misspellings, and domains that only resemble the service you use. A padlock or https in the address doesn't prove that a site is legitimate. It usually indicates an encrypted connection, and a phishing site can use encryption too.
The safest option isn't to inspect a suspicious destination interactively at all. Open the official app, type the service’s known address into the browser, or use a bookmark you created previously. Avoid searching for the company and choosing a sponsored result when you’re responding to a security alert; search results can also be misleading.
Consider the wording and the requested action
Phishing messages often ask for more than a normal password reset. Be cautious if the message requests your current password, an authentication code, recovery phrase, payment information, identity documents, or remote access to your device. A service may ask you to establish a new password through its normal sign-in process, but an unexpected message asking you to reply with a code is a strong warning sign.
Look for pressure, unusual grammar, vague greetings, and explanations that don’t match how the service normally communicates. None of these proves fraud by itself. Automated messages can be awkward, and legitimate companies may use different templates. The stronger warning is a combination: an unexpected request, pressure to act, a questionable sender, and a link you can't verify.
Also consider whether the message matches the account. A password-reset email for a service you don’t use may be spam or a sign that someone typed your address by mistake. Don’t create an account or provide information just to investigate the message.
Treat authentication alerts as a separate clue
Some fake reset messages are paired with real-looking alerts about a new sign-in, one-time code, or multi-factor authentication request. They may tell you to call a phone number, reply to the message, or “confirm” the activity through a link. Don’t use those routes.
If you receive an authentication prompt you didn’t initiate, deny it when the prompt is clearly shown inside the official authentication app or device interface. Never approve an unexpected request merely to make it stop. Repeated prompts can be an attempt to wear you down, sometimes called prompt bombing.
Open the account’s official security or sign-in activity page independently. Check for unfamiliar devices, locations, sessions, recovery details, and changes to your authentication methods. Location estimates aren’t always precise—mobile networks and privacy tools can make them look unusual—so consider the device, time, and activity together.
Check the account safely: Open the service’s official app or type its known address yourself, then review recent sign-ins, active sessions, recovery email addresses, phone numbers, and authentication methods. Menu names change, so use the service’s current help pages if you can’t find these settings.
Understand what account activity can and can’t tell you
An unexpected reset message and no suspicious account activity may mean that someone simply tried to start a reset. It’s still sensible to use a strong, unique password and confirm that your recovery information is correct. If the account shows a successful sign-in, a password change, a new recovery method, or an unfamiliar session, treat that as a possible compromise.
Take action through the official account settings, not through the message. Change the password to a new one that you don’t use elsewhere, sign out unfamiliar sessions, remove unknown recovery methods, and review connected apps or forwarding rules where the service provides them. Turn on multi-factor authentication if it isn’t enabled. A password manager can help generate and store a unique password, and some password managers can warn when the current site doesn’t match the saved login domain.
If you reuse the same password on other accounts, change those accounts too, starting with email. Your email account often controls password recovery for other services, so protecting it can prevent a chain reaction. Prioritize accounts involving money, personal records, work access, or other recovery functions.
If you clicked the message
Clicking a link doesn't always mean your account was compromised, but the next steps depend on what you did. If the page only opened, close it without downloading files, installing software, or entering information. If you typed a username and password, change that password immediately by navigating to the official service yourself. Change it anywhere else you reused it.
If you entered a one-time authentication code, approved an unexpected sign-in, downloaded a file, or installed an app, respond more urgently. Revoke unfamiliar sessions and authentication methods, contact the affected service through its official support channel, and check your device for unfamiliar software or security changes. If financial information was submitted, contact the relevant financial provider using the number on its official website or card—not the number in the message.
Don’t continue a conversation with the sender, even if it offers to help undo the problem. Report the message using your email or messaging service’s phishing option, then delete it. Reporting is useful, but it should come after you’ve secured any account that may have been exposed.
Build a reliable habit for future messages
You don’t need to memorize every sign of phishing. A dependable routine is more valuable: don’t use unexpected password-reset links, inspect the full sender when useful, verify through an app or address you open independently, and review account activity when the alert concerns a real service you use.
Keep your email account protected with a unique password and multi-factor authentication, because it may be the recovery path for many other accounts. Keep your browser, phone, computer, and password manager updated through their normal settings. These steps won’t make deceptive messages disappear, but they reduce the chance that one convincing message becomes a lasting account problem.
When a reset message arrives, pause before reacting. The message can tell you that something may need attention, but the message itself shouldn't control how you investigate it. Use a trusted route to determine whether a reset was requested, whether anyone signed in, and what—if anything—you need to change.