Sealine is a private demonstration page, not an email provider or security vendor, and is not affiliated with any company named on it.
Secure email
The sender name on a message is free text. Anyone can type anything into it. The authentication that exists checks a domain, not a person — and a look-alike domain the sender owns outright passes every check cleanly. Which is why the habit below matters more than any setting.
The message shown below was written for this page. It is not a real email and the addresses in it do not exist.
Read it the way an attacker wrote it
Every guide describes what phishing looks like. Almost none of them show you one. The tells are numbered on the right, and none of them require you to inspect a header.
Dear Customer,
We attempted to renew your subscription and the payment was declined. Your account is scheduled for suspension within 24 hours unless your billing details are confirmed.
To keep your account active, confirm your payment method using the secure link below. This link expires shortly for your protection.
Confirm billing detailsA company that bills you knows your name. Generic address at the top is the cheapest tell there is, and it survives because the message is sent to thousands of people at once.
account-secure-notice.com is a domain someone registered and owns. It passes SPF, DKIM and DMARC perfectly, because the checks confirm the sender controls that domain — not that the domain is the one you think.
The visible sender and the address your reply would actually go to are different. Legitimate billing mail almost never splits those, and most mail clients hide the difference until you press reply.
Twenty-four hours exists to stop you checking. Real account problems do not resolve themselves in a day, and no genuine provider makes suspension contingent on speed of response to an email.
Link text is decorative — it can say anything while pointing anywhere. On a phone you often cannot preview the target at all, which is why phishing performs better on mobile.
Every part of the message pushes you to begin at their link rather than at your own bookmark. That is the whole mechanism, and refusing it is the entire defence.
In order of how much they actually do
Most of the value sits in the first two. The rest is worth doing and will not save you on its own.
Does the most
Open the site the way you normally open it — your own bookmark, the app, the address you have always typed. A convincing message becomes harmless the moment you refuse to use its route in.
Does a lot
A passkey cannot be handed to a look-alike site, because it is bound to the real domain. An authenticator app is the next best thing. SMS codes are better than nothing and are the one factor that can be intercepted or talked out of you.
Worth doing
One address for banking and government, another for shopping and newsletters. When the second one leaks — and it will — nothing that arrives there can be about your accounts, which makes the fake obvious.
Worth knowing
A common move after an account is taken over is a quiet rule that forwards or deletes mail. Check your own rules occasionally; an inbox that has stopped showing you receipts is not a mail glitch.
It happens to careful people
Clicking alone rarely does the damage. What you typed afterwards is what matters, so the order below starts there.
Do it from a different tab you opened yourself, not from anything in the message. If the same password is on other accounts, those are compromised too — change them in order of what holds money or mail.
Most services have a “sign out of all sessions” control in security settings. A stolen password is often used hours later; ending existing sessions closes that window and forces a fresh sign-in you will see.
Check forwarding, filters and recovery addresses on the email account itself. This is the step people skip, and it is the one that lets an intruder keep reading after you have changed the password.
A passkey or an authenticator app on the mail account before anything else. Your inbox is the reset route for every other account you own, which makes it the one worth protecting first.
Forward the message to the Anti-Phishing Working Group and report it to the FTC. Do not reply to it, and do not engage to see what happens — a reply confirms the address is read by a person.
Straight answers
Go straight to the source
One email, then we leave you alone
The checklist fits on one page: the tells from the specimen, the two settings worth changing, and the habit that makes the rest optional.