Thread with 4 posts

jump to expanded post

‪every time i get one of those i kinda want to click the links to be contrarian because they're such a distinct species of email. no real phishing email would pretend to be from a sketchy hr department domain i've never heard of. they would simply pretend to be Service Now‬

Open thread at this post
Zimmie , @bob_zim@infosec.exchange
(open profile)

@hikari Or they would pretend to be from KnowBe4 or some other paid phishing company. Most such services have an “Allow this sketchy email through the filtering and deliver it right to the user’s inbox” header, and these headers are well-known, so a real phishing attempt would use them too.

I just run a script on the mailserver which looks at the last five messages or so in my inbox, checks for the header, and automatically flags it as phishing.

Open remote post (opens in a new window)