The safest first response to a suspicious email is to pause the requested action and verify it through a channel you already trust. Do not use the phone number, QR code, reply address or link inside the same message to prove that it is genuine. A polished message can still be phishing, and an AI assistant cannot replace identity, domain, process and technical checks.
Malaysians face convincing email, messaging and impersonation attempts that can arrive without the old warning signs of awkward grammar. CyberSecurity Malaysia has published alerts about spoofed messages and malicious attachments, including an October 2025 alert involving a PDF attachment presented as communication from a Malaysian bank. The lesson is practical: judge the request through evidence and normal procedure, not visual polish.
This phishing email checklist Malaysia readers can use is designed for employees, freelancers, students, online sellers and small teams. It helps you decide what to check before you click, reply, open a file, disclose information or approve payment.
What counts as a phishing warning sign?
A warning sign is an observation that justifies more verification. It is not proof on its own. A legitimate message may be urgent, and a fraudulent message may be calm. Strong verification combines several checks:
- the exact sender and domain;
- the requested action and its consequences;
- whether the request matches normal procedure;
- the real destination of links or QR codes;
- the expected file type and reason for an attachment;
- independent identity confirmation;
- approved technical scanning and reporting routes.
AI can help turn these observations into questions or explain unfamiliar security terms. It should not issue the final “safe” verdict. A language model may not have the full email headers, current reputation data, redirect path, device behaviour or organisational context.
Phishing email checklist Malaysia: 12 checks
1. Pause before acting
Do not reply, click, scan, download, pay or share data while you are still deciding whether the request is genuine. If the email claims there is an immediate deadline, pausing may feel uncomfortable. That pressure is precisely why a predefined verification process matters.
2. Read the exact sender address
Display names are easy to imitate. Expand the sender details and inspect the full address. Look for misspelled domains, extra words, unexpected free-email services or a reply-to address that differs from the visible sender. Do not assume a familiar name proves control of the account.
3. Identify the requested action
Write the action in plain language: reset a password, open a file, send employee records, change supplier bank details, install software or approve a payment. Then name the worst plausible consequence. The bigger the consequence, the stronger the independent verification should be.
4. Compare the request with normal procedure
Ask whether this organisation normally requests the action by email. A supplier may not usually change payment details through a message. An employer may use a specific internal portal for password resets. A bank will publish its official channels. A process change needs verification, even when the message contains correct names and branding.
5. Inspect links without following them
Where your approved device and email client allow it, reveal the actual destination without opening the link. Compare the exact registered domain with the organisation’s known official domain. Shortened links, lookalike spellings, unexpected subdomains and redirect chains deserve caution. Do not search for a suspicious link and click a result merely because it ranks highly.
6. Treat QR codes as links
A QR code can hide its destination until a phone scans it. Do not treat it as safer because it appears in a PDF or poster. If the action is legitimate, reach the service through a trusted app, saved bookmark or manually entered official domain instead.
7. Verify unexpected attachments
Confirm why the file was sent, whether the type is expected and whether the sender can confirm it through another route. Do not upload an unknown attachment to a public AI tool so that the model can judge it. A chatbot explanation is not malware scanning or forensic analysis. Use your organisation’s approved isolation, scanning and incident process.
8. Check urgency, secrecy and bypass requests
Be cautious when the sender asks you to avoid a colleague, skip a normal approval, move to a personal account or keep the request secret. The safest response is not to challenge the sender inside the same suspicious conversation. Pause and verify independently.
9. Verify identity through a trusted channel
Use contact information that was established before the message arrived: an official website you navigate to separately, a known internal directory, a saved supplier contact or an existing authenticated portal. CyberSecurity Malaysia’s impersonation guidance similarly advises people to check with the organisation using official telephone numbers rather than a number supplied by the caller.
10. Protect credentials and one-time codes
Never send passwords, recovery codes, API keys, session tokens or one-time authentication codes by email or paste them into an AI assistant. If a secret may have been exposed, follow the official recovery route promptly from a trusted device. Changing a password through a link in the suspicious message may deepen the compromise.
11. Preserve evidence and report
Follow your employer, bank, platform or institution’s reporting process. Preserve the original message and relevant header, time, sender, link and attachment information as directed. Do not forward a potentially malicious attachment casually to colleagues. Cyber999 is Malaysia’s national point of contact for reporting computer security incidents and publishes current channels on its official page.
12. Record the decision
For consequential requests, record who verified the identity, which independent channel was used, what evidence was checked and why the action was approved, rejected or escalated. This small record is useful when a similar attempt returns or when a team needs to improve its process.
Can AI detect a phishing email?
AI can assist, but “detect” is too strong when the model sees only copied text or a screenshot. It may identify pressure language, unusual requests or lookalike wording. It may also miss hidden redirects, account compromise, malicious file behaviour or a genuine-looking message sent from a compromised real account.
A safer AI-assisted workflow uses abstracted observations instead of unnecessary live data. You might record: new sender domain, urgent payroll request, unexpected attachment and request to bypass the usual portal. Ask the AI to list evidence gaps and alternative explanations. Then run the actual domain, identity, process, attachment and incident checks through approved methods.
If you want the complete system for safer prompts, files, accounts, permissions and incident response, see AI Cybersecurity Malaysia: A Beginner’s Guide to Safer Prompts, Files and Decisions. The downloadable guide includes 20 templates, eight labs and a 14-day plan.
A five-minute practice exercise
Create a fictional email that asks an employee to open a “revised invoice” and change supplier payment details today. Do not use a real logo, real personal data or an active link. Give a colleague the checklist and ask them to document:
- the requested action;
- the asset that could be harmed;
- the independent verification channel;
- the attachment handling route;
- the approval or escalation owner;
- the evidence that should be preserved.
The purpose is not to trick the colleague. It is to make the safe workflow familiar before a real urgent message arrives.
Malaysia sources and responsible use
Use current official pages because reporting channels, technical guidance and obligations change. CyberSecurity Malaysia maintains Cyber999 reporting guidance and alerts and advisories. NACSA publishes information on Malaysia’s Cyber Security Act 2024. Malaysia’s National AI Office provides privacy and security guidance for AI, while the Personal Data Protection Commissioner explains the personal data protection principles.
For additional risk-management practice, consult the NIST Generative AI Profile and CISA Secure Our World. These sources provide context and good practice; they do not decide how a specific Malaysian law, contract or incident applies to you.
Frequently asked questions
Should I reply to ask whether the email is genuine?
Not as your only verification. A reply stays inside the possibly compromised channel. Contact the person or organisation through a route you already trust.
Is a PDF attachment safer than a spreadsheet or ZIP file?
No file type is automatically safe. Confirm the origin and purpose and use approved scanning and isolation controls. CyberSecurity Malaysia’s October 2025 alert specifically described a suspicious PDF attachment.
What if the sender knows private details?
Correct details can come from previous messages, public sources, data exposure or a compromised account. Treat them as context, not proof of identity.
Should a small business have an incident plan?
Yes. Keep it proportionate and practical: primary and backup owners, trusted contact routes, containment authority, evidence steps, recovery information and current external reporting channels.
Conclusion
A good phishing checklist does not rely on fear or perfect detection. It creates a pause between a message and a consequential action. Inspect the exact sender and request, use trusted independent channels, protect secrets, handle files through approved controls and record important decisions.
Ready to build the complete workflow? Get the AI Cybersecurity Malaysia ebook for RM9.99 and use its 20 templates to protect prompts, files, accounts, permissions and incident response.
Author: Dr. Muhamad Hariz Bin Muhamad Adnan


