Three questions before you touch anything
Every email you receive deserves three quick questions before you click, reply, or download anything. Was I expecting this message from this sender? Who actually sent it — not the friendly display name at the top, but the real address that sits after the @ symbol? And is the message pushing you to hurry, with words like 'urgent', 'expires today', or 'act now'? A prize you never entered, a school notice nobody mentioned in the group chat, or a delivery you did not order all fail the very first question, and that alone is enough reason to stop. This three-question habit works because it targets the exact mechanics scammers rely on. Phishing email — a message designed to trick you into giving up money, passwords, or personal details — succeeds by borrowing the visual language of organisations you already trust: a bank logo, a courier's colours, a familiar 'IT Department' signature. The email itself costs the sender almost nothing to produce, and they send millions of copies hoping a small percentage of people react on autopilot rather than pausing. You do not need to understand mail servers or encryption to defend yourself. You only need the discipline to ask these three questions every single time, because the habit works regardless of how convincing the fake becomes. The psychology behind why this works is worth understanding in plain terms. Our brains are wired to react quickly to authority, urgency, and reward — a message that appears to come from your bank, threatens a locked account within 24 hours, and promises to fix it with one click is engineered to short-circuit careful thinking. Scammers test different wording, subject lines and logos the same way a business tests adverts, keeping whatever gets the most clicks. Recognising that you are the target of deliberate psychological pressure, not just an unlucky recipient of a stray email, makes it much easier to slow down. The real-world cost of getting this wrong ranges from mildly annoying to devastating. A single click on a fake login page can hand over the password to your email account, which is often the master key to every other account you own, because 'forgot password' links usually go there. From that one email account, an attacker can reset your banking passwords, message your contacts pretending to be you, or lock you out entirely while they clean out what they can. This is why the pause before clicking matters so much more than any piece of security software: no filter catches everything, but a moment of doubt catches almost anything.