Be cautious with unexpected password resets, urgent payment demands, account-closure threats, gift-card requests, or attachments you were not expecting. A familiar display name alone does not prove who sent a message.
- Check the sender’s full address, not just the display name.
- Use a saved bookmark or type the known website address yourself instead of following a sign-in link. On a phone, you can leave the message and open the trusted app or website directly.
- Verify unusual requests through a separate contact method you already know.
- Do not open suspicious attachments or reply with passwords, payment information, or patient details.
If you entered your mailbox password on a suspicious page, change it through the Dashboard and follow the compromised-mailbox steps.
To ask for help, open a support ticket with a description and non-sensitive error or sender details. Do not upload a suspicious attachment or include patient information.