Draft NOINDEX expansion 2026-08-10; overall scores unpublished
Phishing Email Checklist
Habits before gateway logos: SecurityChecklist keeps this draft free-first and claim-safe. Most phishing wins are rushed clicks and MFA code sharing, not missing suite logos. Optional paid cards use claim-ledger prices from 2026-08-09 (Bitdefender Antivirus Plus from $24.99/yr first year; Malwarebytes from $59.99/yr). Overall scores stay unpublished (N/Pub). Who should not buy: anyone who has not confirmed OS updates and built-in protection, anyone stacking multiple always-on engines, or anyone who needs published lab detection rates before deciding.
- Guide · Free-first · Draft NOINDEX
Priority checklist
- 1Pause on urgency, money, or threat language
- 2Check display name vs real address; hover links
- 3Open sites via bookmark instead of email links when money is involved
- 4Never share passwords or MFA codes with callers
- 5Report phishing in your mail client
Checklist
- 1Free
Slow down urgency theater
Phishing leans on fear and deadlines. Take a breath. Real banks and IT teams do not need gift cards.
- Pause on urgent payment demands
- Reject gift-card or wire remediations
- Call known numbers, not numbers in the email
- 2Free
Verify before you click
Inspect sender addresses, hover links, and unexpected attachments. Prefer bookmarks for financial and school portals.
- Check full sender address
- Hover links before clicking
- Open sensitive sites via bookmark
- 3Free
Protect MFA and sessions
Never read MFA codes to callers. If you entered credentials on a fake page, reset from a trusted device immediately.
- Never share MFA codes
- Reset if credentials were entered
- Review mailbox rules after incidents
- 4Optional paid
Optional tools later
Email security gateways and suites can help organizations. Individuals should still keep habits first; paid AV is not a phishing-thinking substitute.
- Keep habits even with filters
- Buy tools only for a named leftover job
What this checklist does not cover
- Perfect prevention of every spearphish
- Users who will approve every prompt
- Invented phishing click-rate guarantees
Sources
- Phishing hygiene patterns, Sender verification, bookmark habit, MFA code discipline; no invented click rates
- Bitdefender claim ledger, data/claim-ledgers/bitdefender.json#bitdefender-starting-price; from $24.99/yr first year captured 2026-08-09
- Malwarebytes claim ledger, data/claim-ledgers/malwarebytes.json; from $59.99/yr captured 2026-08-09
- Overall scores unpublished (N/Pub), No invented lab scores, detection rates, or aggregate ratings on Batch39/40/41 drafts
- Vendor marketing pages, bitdefender.com / malwarebytes.com feature and pricing claims, not independent lab evidence
- Security Checklist methodology, How antivirus pages are structured before scores and detection rates publish, /methodology/
- Claim ledger (T014), data/claim-ledgers/bitdefender.json + malwarebytes.json, starting prices verified 2026-08-09; lab scores unpublished
Frequently asked questions
Internal links
Continue in this cluster
Hub, tools, and related pages from the inventory. No invented URLs.
Expert guides & insights
Related guides
Stay in the same problem space without jumping brands.
Want launch updates?
The email newsletter is not running yet. Use Contact if you want a human reply when it opens. No fake signup form.
