WHO
- Is the sender someone you know and usually communicate with?
- Is the email sent to an unusual group of people?
- Does the email address match the email in the signature?
WHAT
- What action does the sender want you to take?
- Is the action something you’d expect from the sender?
- Does the email contain typos?
WHY
- Why do they want you to click on a link, download an attachment, or send information?
- What is the consequence they are threatening if you do not act?
- Are they presenting a sense of urgency?
