JatzoOnline Security
JATZO GUIDE

How to check a suspicious email safely

A practical seven step process for checking a suspicious email before you click, reply, pay or sign in, written so anyone can follow it without help.

Choose the explanation that suits you. Both versions cover the same topic.

1. Stop before you act

Do not click, reply, pay, call a number from the message, scan a QR code or open an unexpected attachment while you are still deciding whether the request is genuine. Moving slowly removes one of phishing's biggest advantages: pressure.

2. Ask what the email wants from you

Identify the requested action before judging the design. Sign in, approve an OAuth prompt, change bank details, download a file, call support, send information or pay a cryptocurrency demand are very different security decisions.

3. Check the full sender identity

Look past the display name. Compare From, Reply-To and Return-Path, then consider whether the domains and sending infrastructure make sense for the organisation the message claims to represent.

4. Treat authentication correctly

SPF, DKIM and DMARC can show that a domain authorised a message. Criminals can also authenticate domains they control, so a pass is useful evidence but never a guarantee that the offer, identity or destination is safe.

5. Inspect destinations and attachments

Button text can hide a different destination. Unexpected PDFs, Office files, archives, HTML files and nested emails can also be part of multi-stage attacks. Use static analysis rather than opening a suspicious file just to see what happens.

6. Verify high-impact requests independently

For payments, account recovery, payroll, bank-detail changes or sensitive data requests, contact the organisation using a phone number, website or internal channel you already trust. Do not use contact details supplied only by the suspicious message.

7. Read Jatzo's result as evidence, not permission

Low risk means Jatzo found limited threat evidence in what it could inspect. Suspicious, High and Very high risk indicate increasing concern. No automated tool can prove every message safe, so important requests still deserve independent verification.

HTTP and reputation are different checks

An explicit HTTP URL carries a connection warning independently of the phishing score. HTTPS does not establish legitimacy. A provider no-match only means no match was returned at the stated time; skipped or failed checks are not clean results.

Export coverage and retention

Detailed PDFs use an account-owned in-memory evidence snapshot for up to 30 minutes. Restarts or capacity limits may clear it earlier. History keeps a compact summary, not the original message. Export promptly and handle downloaded reports as potentially sensitive evidence.