Draft NOINDEX expansion 2026-08-10; overall scores unpublished

Published by By SecurityChecklist

Reviewed Independent reviewer role open

Experts policy

Phishing Email Checklist

Habits before gateway logos: SecurityChecklist keeps this draft free-first and claim-safe. Most phishing wins are rushed clicks and MFA code sharing, not missing suite logos. Optional paid cards use claim-ledger prices from 2026-08-09 (Bitdefender Antivirus Plus from $24.99/yr first year; Malwarebytes from $59.99/yr). Overall scores stay unpublished (N/Pub). Who should not buy: anyone who has not confirmed OS updates and built-in protection, anyone stacking multiple always-on engines, or anyone who needs published lab detection rates before deciding.

  • Guide · Free-first · Draft NOINDEX

Priority checklist

  1. 1Pause on urgency, money, or threat language
  2. 2Check display name vs real address; hover links
  3. 3Open sites via bookmark instead of email links when money is involved
  4. 4Never share passwords or MFA codes with callers
  5. 5Report phishing in your mail client
Start Antivirus Finder →

Checklist

  1. 1

    Slow down urgency theater

    Free

    Phishing leans on fear and deadlines. Take a breath. Real banks and IT teams do not need gift cards.

    • Pause on urgent payment demands
    • Reject gift-card or wire remediations
    • Call known numbers, not numbers in the email
  2. 2

    Verify before you click

    Free

    Inspect sender addresses, hover links, and unexpected attachments. Prefer bookmarks for financial and school portals.

    • Check full sender address
    • Hover links before clicking
    • Open sensitive sites via bookmark
  3. 3

    Protect MFA and sessions

    Free

    Never read MFA codes to callers. If you entered credentials on a fake page, reset from a trusted device immediately.

    • Never share MFA codes
    • Reset if credentials were entered
    • Review mailbox rules after incidents
  4. 4

    Optional tools later

    Optional paid

    Email security gateways and suites can help organizations. Individuals should still keep habits first; paid AV is not a phishing-thinking substitute.

    • Keep habits even with filters
    • Buy tools only for a named leftover job

What this checklist does not cover

  • Perfect prevention of every spearphish
  • Users who will approve every prompt
  • Invented phishing click-rate guarantees

Sources

  • Phishing hygiene patterns, Sender verification, bookmark habit, MFA code discipline; no invented click rates
  • Bitdefender claim ledger, data/claim-ledgers/bitdefender.json#bitdefender-starting-price; from $24.99/yr first year captured 2026-08-09
  • Malwarebytes claim ledger, data/claim-ledgers/malwarebytes.json; from $59.99/yr captured 2026-08-09
  • Overall scores unpublished (N/Pub), No invented lab scores, detection rates, or aggregate ratings on Batch39/40/41 drafts
  • Vendor marketing pages, bitdefender.com / malwarebytes.com feature and pricing claims, not independent lab evidence
  • Security Checklist methodology, How antivirus pages are structured before scores and detection rates publish, /methodology/
  • Claim ledger (T014), data/claim-ledgers/bitdefender.json + malwarebytes.json, starting prices verified 2026-08-09; lab scores unpublished

Next steps

Frequently asked questions

Internal links

Continue in this cluster

Hub, tools, and related pages from the inventory. No invented URLs.

Expert guides & insights

Related guides

Stay in the same problem space without jumping brands.

Want launch updates?

The email newsletter is not running yet. Use Contact if you want a human reply when it opens. No fake signup form.