Jane's Guide

Here's all the help you need to use Jane.


How to Stay Safe from Phishing Messages

This guide covers phishing messages and how to keep your information safe. You can check out our webinar on the topic.

What are phishing messages?

Phishing is a type of social engineering attack where someone attempts to steal sensitive information (like login credentials or credit card information) by posing as a trusted sender. Phishing messages can be sent by email, SMS, or phone call.

How can I recognize a phishing message?

There's no single way to tell for certain, but there are a few signs to watch out for that may indicate you've received a phishing message.

Check the sender's email address

  • Look carefully at the full email address, not just the display name. Phishing emails often use addresses that are a slight variation of a real domain (for example, @int-google.au instead of @google.com).
  • Check for typos or extra characters in the domain.
  • If you don't recognize the sender or haven't received emails from that address before, treat it with caution.

📣 Heads up: emails from Jane will always come from @janeapp.com or @jane.app. If you receive an email claiming to be from Jane using any other domain, it isn't from us. Contact us at [email protected] if you're unsure.

Check links before clicking

  • Hover your cursor over any link before clicking to preview the destination URL. If the URL doesn't match where you'd expect to be sent, don't click it.
  • When in doubt, go directly to the website by typing the address into your browser rather than clicking the link in the email or by using a bookmark you've previously saved. This applies to links to third-party services like Google Drive as well.

Hovering over a link in an email to preview the destination URL before clicking

Don't enter credentials through email links

If you click a link and are taken to a login page, don't enter your credentials. Go to the website directly through your browser to log in instead.

Be cautious with attachments

  • Only download attachments from senders you trust and whose email address you've verified.
  • If you weren't expecting to receive the attachment, confirm with the sender through a separate channel (for example, a phone call to the sender) before downloading.

Watch for other warning signs

Here are a couple of other red flags to watch out for when confirming if an email is legitimate:

  • The email doesn't address you by name. Phishing emails are often sent in bulk and use generic greetings.
  • The email contains grammar or spelling mistakes.
  • The email asks you to enter personal or sensitive information. Legitimate organizations rarely request sensitive information by email.
  • The email creates a sense of urgency, such as claiming your account will be suspended or a payment must be made immediately. Remember that urgency is an oddity!

As phishing attempts become more sophisticated, some are difficult to spot even with a careful eye. When in doubt, don't click.

What should I do if I receive a phishing message?

  • If your email provider offers a "Report phishing" option (Gmail does), use it. If that option isn't available, mark the email as spam. Otherwise, delete the email.

The Gmail Report phishing option shown in the email menu

  • For SMS messages, most phone providers include the option to report the message as spam.
  • For any kind of phishing message, including phone, you can also report the message to your local authorities. For instance, Canada's Anti-Fraud Centre offers options to report phishing messages.

If you have questions about a suspicious email or anything related to security or privacy, contact Jane's Privacy and Security Support Team at [email protected].

Related Guides