THE SHORT ANSWER

Start with the identity claim, move to a channel you already know, require stronger authentication where the system supports it, compare the request with expected context, and seek independent confirmation when the consequence is high. Each method has limits.

Use a verification ladder

CLAIM ↓ KNOWN CHANNEL ↓ SECOND FACTOR ↓ CONTEXT ↓ INDEPENDENT CONFIRMATION.

A proportionate ladder
LayerExampleLimit
ClaimName, account or role presentedSelf-assertion is not proof
Known channelSaved number, official app, internal directoryThat account or directory can be outdated
Second factorA strong authenticator or established internal checkAuthentication does not prove every request is appropriate
ContextExpected timing, amount and relationshipAccurate context may be stolen
Independent confirmationAnother authorized person or in-person checkAdds time and must be designed for the consequence

Evidence & context: National Institute of Standards and Technology

Separate identity proofing from authentication

NIST distinguishes establishing who a person is from proving control of an authenticator. A logged-in account can still be compromised, and a real employee can still make an unauthorized request. Verify identity, authority and the action.

Evidence & context: National Institute of Standards and Technology

Known means established before this request

Use an official website or app, an internal company directory, a previously saved contact method or in-person confirmation. A number, link or support account supplied inside the suspicious interaction is not an independent channel.

Evidence & context: United States Federal Trade Commission

Stop when confidence is sufficient for the consequence

Perfect certainty is rarely available. A low-consequence conversation may need little friction; a payment change or privileged-access request should need stronger, recorded confirmation. For evaluating the source behind a claim, continue to How to Evaluate Sources.

Sources & further reading

  1. NIST SP 800-63-4: Digital Identity Guidelines

    National Institute of Standards and Technology. The 2025 guideline distinguishes identity proofing, authentication and federation and selects assurance according to risk. It is written for United States federal systems but offers a useful conceptual reference beyond them.

  2. How To Avoid a Government Impersonation Scam

    United States Federal Trade Commission. Official consumer guidance on urgency, payment demands, caller-ID limits and contacting an organization through a known channel. Agency examples and reporting routes are United States-specific.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗