Don't give out personal information (such as a password, credit card number, Social Security Number, birthday, etc) to any request you receive in email without verifying the authenticity of the email. Just because someone sends you an email asking for personal information doesn't mean you have to give it to them.
Don't click on anything inside an email without verifying the authenticity of the email. Links can be hidden, misleading, or lead to sites that automatically install viruses or trojans. Just because a link looks like it has a name you recognize doesn't mean it leads to the real organization.
Don't trust an email simply because you think you recognize the sender. Malicious emails often have the sending address “spoofed” to make the them appear legitimate.
Phishing Home
3 Rules
Email Authenticity
Warning Signs
Actions