When it comes to phishing e-mails, or like in this scenario hacked e-mail, i have simple rule: if there is e-mail requirement to click on link in it, then i just ignore and i go to control panel instead as usually in 99% of cases things can be done over it.
For example, paypal often send TOS update e-mails, but you dont need to check it over e-mail link, you can simply load paypal.com .
|