Browse all 2 guides

First ask: did you just trigger it?

A verification code is a short-lived key. An email’s design, logo, and wording can all be copied, but an attacker cannot create a genuine action context for you: did you just enter your email on the right website, click Send, and leave the page waiting for that same code?

If not, do not click just because the email says your account is at risk. More likely, someone entered the wrong address or is trying to sign in to your account. Check account activity from a browser bookmark or by typing the official site address yourself—not by following the path provided in the email.

Align the timeline

  • Did the code arrive within a few minutes of you clicking Send?
  • Do the product, device, or location mentioned in the email match what you are doing now?
  • If the page is waiting for a six-digit code but the email asks you to download an attachment or reply with information, stop immediately.

Next check: can the sender’s identity be verified?

A display name can be anything; “Security Center” does not prove who sent the message. Expand the full sender address and focus on the domain after @, not the brand-like text before it. Attackers often add a letter, swap characters, or use a very long subdomain to create a visual imitation.

Do not rely on the padlock icon alone. Encryption in transit means the email was protected on its way to you; it does not prove the sender is the organization you expect. If the service publishes its notification domains, open its help center in a new tab and verify them there—not through a “verify domain” link in the email.

Signal observedReasonable explanationNext step
Domain exactly matches the official siteMore credible, but still check the action contextReturn to the original page and enter the code
Display name looks right, domain is unfamiliarCould be third-party delivery—or impersonationVerify the sending domain through the official help page
Domain has extra letters or hyphensHigh-risk visual impersonationDo not click; report and delete

Most code-only emails do not require you to click anything. If an email shows both a number and a prominent “Verify now” button, return to the page you just opened and enter the number manually. That way, even if the email button has been replaced, your session will not be handed to another site.

On desktop, hover over a link to preview its destination; on mobile, press and hold to preview it—but do not open it just to see where it goes. Shortened links, numeric IP addresses, and sign-in pages unrelated to the service’s main domain are all stop signs. Even if the destination looks convincing, never enter your email password there again.

The code belongs only on the original page

Customer support agents, sellers, and “helpers” in group chats do not need your verification code. Anyone asking you to screenshot, forward, or read out a code is trying to complete an authentication action on your behalf. Copy the code only from the email to the original page that you opened yourself and that is still waiting for it.

If the email clearly says “do not share,” an attacker may twist that into “the system bot does not count as sharing.” That is just a trick. Once a code enters a chat, remote-support app, or unfamiliar form, it has crossed the safety boundary.

What to do if you receive a code you did not request

Do not panic, and do not repeatedly click the email’s “That wasn’t me” button. For important accounts, open the official website or app manually and check recent sign-ins, logged-in devices, and whether the recovery email was changed. After confirming suspicious activity, change your unique password and enable two-factor authentication.

A single unexpected email may simply be a typo. If codes keep arriving within a short period, save the times and sender domains for investigation, but do not reply. For one-time trials completed with a temporary email, let the address expire when the task is over; this reduces the chance that an old address will later be mistaken for a recovery channel.

What temporary email can—and cannot—do

A temporary email can isolate your everyday address and reduce marketing and data linking after a one-time signup. It cannot verify the sender for you, and it does not make malicious links safe. Whether a message reaches a long-term mailbox or a short-lived inbox, the same four checks apply.

Temporary addresses work well for trials, one-time confirmations, and short-term downloads that you will not need to recover later. Do not use them for banking, work, healthcare, order support, or any account where you may need to reset a password months from now. Recoverability matters more than receiving fewer promotional emails.

30-second checklist

  1. Confirm that you just initiated an action with the same service.
  2. Expand the full sender address and verify the real domain.
  3. Do not click an email button; return to the original page and enter the code.
  4. Never send the code to anyone or to an unfamiliar form.
  5. For suspicious messages, check account activity through the official site.

Use a separate address for your next short-term verification

VuSend creates a temporary inbox with a clear countdown right on the page. Copy the address, receive your code, and let the email and address be cleared on schedule when you are done.

Open temporary inbox