First, confirm: did you just trigger this email?
The first step is not studying the email’s design—it’s recalling what you just did. Were you registering for the service, requesting a login, or changing your email on the same device? Do the service, action, and timing match? If you never made the request, don’t click or reply, even if the email says “your code expires in ten minutes.”
A temporary inbox can separate this registration from your everyday address, but it can’t tell you whether the message is genuine. When using a BoxTmp temporary inbox , match it to the task at hand: accept only the message you’re waiting for. Unrelated password resets, payment requests, or attachments should all be treated as additional warning signs.
Practical rule: content that doesn’t match what you just did is more concerning than whether the message “looks official.” Logos and email templates are easy to copy; only you know the action that triggered the message.
Check the sender domain—not just the display name
“Security Team” is only a display name; any sender can enter it. Expand the email headers, find the full sender address, and inspect every character after the @. Watch for substituted letters, extra hyphens, unfamiliar subdomains, and lookalike extensions. Don’t skip this step just because the name and avatar look right.
Check the reply address too
Some emails have a legitimate-looking From address but route replies to another domain. Legitimate automated verification usually won’t ask you to reply with a code, password, or identity document. If the message says “reply to keep your account,” return to the service’s official app or type a known official website address yourself to verify it.
| What to check | Reassuring signal | Stop and investigate |
|---|---|---|
| Timing | Arrives right after an action you initiated | Arrives unexpectedly, without a request |
| Sender address | Domain matches the known service | Similar-looking spelling or unfamiliar extension |
| What it asks for | Provides a one-time code only | Asks you to reply with a password or code |
| Tone | Explains the purpose and expiry | Pressures you to pay immediately with threats of account closure or a fine |
A verification code should flow only from your inbox to the page you’re using
A one-time code is still a login credential. The safe flow is: open the service page yourself, request a code, then enter the numbers from your inbox on that same page. Support agents, chat contacts, callers, and “security specialists” should never ask you for the code.
If the email includes both a button and a numeric code, return to the page you were using and enter the code manually. This reduces the chance of landing on a fake login page. Check the browser address bar again before entering it, and don’t post a screenshot of the email in a public community; the code and receiving address may still be valid.
Don’t repeatedly request a new code if the email is late
Repeated requests can invalidate the previous code or trigger the sender’s rate limits. Wait one or two minutes, then follow the email troubleshooting steps to check the address spelling, spam settings, and sending status. Once the email arrives, use the newest code clearly identified by the service page.
If you must click, check where the login link really goes
Some passwordless logins can be completed only through an email link. On desktop, hover over it to preview the destination; on mobile, press and hold to preview it. Check that the protocol is HTTPS, the main domain belongs to the intended service, and no unfamiliar domain appears before the path. Don’t rely on the link text alone—the visible text and actual destination can be completely different.
- Open the service’s official website or app yourself and confirm that you can complete the same action there.
- If you must use the email link, verify the main domain first, then open it; never ignore a browser certificate warning.
- If the landing page asks again for your email password, payment card, or recovery key, close it immediately and try again through the official entry point.
- If a short link hides the final domain, don’t use it for an important account.
After verification, secure the next access route according to the account’s value
After a one-off trial or download, you can let the temporary address expire with the session. But if the account contains purchase history, work, or a long-term subscription, you need a stable recovery channel. Move it to your regular email, or use a long-term forwarding alias to keep your real address private while retaining ongoing access to incoming mail.
If you suspect you opened a fake page, immediately change your password through a trusted entry point, revoke other sessions, and review your multi-factor authentication settings. Don’t just delete the suspicious email—the sessions and credentials that may already be exposed are what need attention.
Prepare a separate address for your next low-risk verification
Open the workspace to copy an address, watch the countdown, and read verification emails on the same page. For important accounts, use an email address with long-term recovery.
Create a temporary email