Account security

Check an urgent university email before acting on it

An urgent message about your student account can arrive while you are rushing between classes. That is a poor moment to decide whether a payment demand, document request or password link is genuine. Give yourself a short pause and verify the claimed task through a channel you already know.

The NCSC explains phishing and provides a route for reporting suspicious email. Use its current guidance alongside your university's security instructions. The process below is about checking a request and getting help; it does not attempt to certify an email as safe from its logo, writing style or the fact that it reached a university inbox.

We may earn a commission from retailer links. This guide does not claim first-hand product testing. Our editorial approach

Identify the action being requested

Read what the message actually wants you to do: sign in, send a document, approve a prompt, make a payment or open an attachment. Separate that action from the alarming wording around it. A claim that access will disappear immediately is something to verify, not a reason to skip the verification.

Consider whether the request fits a task you were already expecting, but do not treat familiarity as proof. A message can mention a real module or a normal student process and still need checking. Keep the question concrete: does the responsible university team confirm this action through its established channel?

Reach the service independently

Open the student portal using your usual bookmark or the university's official website. Look for the relevant notice or task there. If you need to contact a team, obtain its details from the official directory rather than from the message you are checking. Do not reply with sensitive information merely to ask whether the sender is genuine.

For a request involving a lecturer or project partner, use an existing contact route where appropriate. Ask a precise question about the task without forwarding private credentials or unnecessary personal documents. If the message asks you to change payment details or send money, resolve the instruction with the responsible organisation before taking action.

Handle links and attachments cautiously

Do not open a suspicious link or attachment to investigate it yourself. A professional-looking page or document does not establish that the request is legitimate. Avoid entering a password or approving a sign-in prompt that you did not initiate through a known service. Keep the message available for the university's reporting process.

If you need to describe it to support, include the claimed sender, time and requested action. Follow the team's instructions for submitting the original message where required. Do not post a live suspicious link into a busy student group chat without context; that can expose more people to the same request.

Report through the appropriate route

Use the university's published suspicious-message reporting process, especially when the message involves its accounts or systems. The NCSC also accepts suspicious emails through its reporting address, report@phishing.gov.uk. Follow the linked official guidance for what to send and what happens next. Reporting is a separate action from recovering an affected account.

If classmates may also receive the message, share a short warning that directs them to the verified university notice or reporting guidance. Avoid claiming a new scam campaign has been confirmed unless the responsible team has said so. Describe what you observed and let the institution communicate any wider finding.

Act promptly if you already responded

If you entered account details, opened an unexpected attachment or approved an unknown sign-in, contact university IT immediately through verified details and follow its incident process. Tell them what happened as accurately as you can. Do not conceal the action because it feels embarrassing; the information helps them choose the right response.

For personal accounts or financial information, follow the relevant provider's official recovery and reporting guidance as well. Keep a record of the messages and support references you are instructed to retain. Buying security software is not a substitute for reporting a possible account compromise and changing access through the provider's supported process.

Your next steps

  • Name the requested action before responding.
  • Verify through the official portal or known contact.
  • Avoid opening suspicious links to investigate.
  • Report promptly if you shared information or approved access.

Sources and further help

Sources were consulted on 5 September 2026. Provider terms and services can change; check your exact booking, product or university service.

Keep planning

Suggest a correction