Sender or reply-to mismatch
The display name looks familiar, but the actual address, domain, or reply-to route contains a different organization, misspelling, or unexpected country domain.
Free first check
Spot pressure, money, identity, and access signals in a redacted example.
Paid early access · USD 19 reference
Turn one redacted situation into a one-page decision brief, official routes, and 15-minute / 24-hour actions.
Clear boundary
No guaranteed verdict or recovery promise. Scope and timing come before payment.
A convincing logo or familiar sender name is not proof. Review the identity, request, link, attachment, and pressure pattern before you sign in, pay an invoice, download a file, or reply.
Check a redacted emailOne clue can be harmless. Several together are a reason to stop and verify outside the email.
The display name looks familiar, but the actual address, domain, or reply-to route contains a different organization, misspelling, or unexpected country domain.
An account warning, security reset, invoice, or document asks you to sign in immediately through a link supplied in the email.
A document, invoice, delivery file, or shared-drive notice asks you to open a file, enable macros, or install software before you can view it.
A request changes bank details, asks for gift cards or crypto, demands a transfer, or tells you not to confirm with a colleague or the official provider.
Look for shortened links, extra subdomains, strange characters, generic greetings, unusual grammar, or a story that does not match your recent activity.
Unexpected refunds, prizes, jobs, investment returns, or account upgrades are often used to make you click before you think.
Open the official app or type the known website yourself. Do not call the phone number or reply address supplied by the suspicious email.
Hover without opening when possible. Compare the destination with the organization’s known domain, not just the visible link text.
Use a saved phone number, a known colleague, or the official support channel. For invoices or bank changes, confirm through a second route.
Remove passwords, codes, payment details, personal addresses, private attachments, and unique links before using MindDividend Shield for a first-pass review.
The next step depends on whether you only opened the link, entered credentials, downloaded a file, approved a login, or sent money.
Follow the post-click response checklist →General scam message checker · Bank alert guide · WhatsApp guide · Safety and privacy
Send the guide instead of forwarding a private email. Remove passwords, codes, payment details, attachments, and personal information before sharing.
Try a free first-pass review with a non-sensitive, redacted example.
Open MindDividend Shield →Send only a redacted summary. We confirm scope, turnaround, and the hosted payment step before any commitment.
Ask about the USD 19 plan →