clt_email_legitimacy_checklist
Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
clt_email_legitimacy_checklist [2025/10/16 21:08] – created thesaint | clt_email_legitimacy_checklist [2025/10/16 22:32] (current) – [5) Optional: Template to report to IT (see wanip.io for info below)] thesaint | ||
---|---|---|---|
Line 6: | Line 6: | ||
---- | ---- | ||
\\ | \\ | ||
- | Sir David — here’s a clean DocuWiki edit-page version tailored **for all incoming emails** (includes your two “Am I expecting…” checks). Paste directly into your wiki. | + | **Audience: |
- | + | **Purpose: | |
- | ``` | + | **Updated:** 2025\\ |
- | ====== Quick Email Legitimacy Checklist (For All Incoming Emails) ====== | + | |
- | **Audience: | + | |
- | **Purpose: | + | |
- | **Last updated:** @@2025-10-17@@ | + | |
---- | ---- | ||
- | ===== 0) Hard Stops — If any are true, **stop** and report | + | ===== THINK … (before you click) ===== |
- | * Asks for passwords, 2FA codes, remote access, or confidential data. | + | * **Are you expecting anything** right now? |
- | * Urgent payment | + | * **Are you expecting anything from these people/ |
- | * You were **not expecting** this email or request. | + | * If the email mentions **domains/ |
+ | * If it asks you to **click**, **hover** your mouse over the button/ | ||
+ | * Want more certainty? In **Outlook (desktop)**: | ||
+ | * **Geo note:** Country/TLD is only a **weak signal**—attackers use any country and many generic TLDs. Treat geo as **extra-scrutiny**, | ||
---- | ---- | ||
- | ===== 1) Expectation Check (first, 10 seconds) ===== | + | ===== Quick Email Legitimacy Checklist |
- | * **Am I expecting anything** right now? | + | **Stop now if any are true:** asks for passwords/2FA, urgent payment/ |
- | | + | |
- | * Do I actually have an account | + | |
- | If **No** to any → treat as suspicious | + | **1) Sender** |
+ | - Name matches someone you know or a real department. | ||
+ | - Email **address** matches the real domain (no look-alikes like `rnicrosoft.com`). | ||
+ | - **Reply-To** is the same as **From**. | ||
+ | |||
+ | **2) Context** | ||
+ | - Am I **expecting anything** right now? | ||
+ | - Am I **expecting anything from these people/ | ||
+ | - You were expecting this email (invoice, file, delivery, password reset). | ||
+ | - You actually have an account/ | ||
+ | |||
+ | **3) Links** | ||
+ | - Hover shows the **same brand domain** (e.g., `https:// | ||
+ | - No link shorteners (bit.ly, tinyurl) or random strings. | ||
+ | - No QR codes you’re being pushed to scan. | ||
+ | |||
+ | **4) Attachments** | ||
+ | - You expected an attachment from this sender. | ||
+ | - Avoid risky types: `.exe .js .scr .bat .ps1 .vbs .iso .img .zip .html .htm` | ||
+ | - Office/PDF files do **not** ask to “Enable Content/ | ||
+ | |||
+ | **5) Language & look** | ||
+ | - Uses your correct name and specific details you recognise. | ||
+ | - No odd grammar, threats, or too-good-to-be-true offers. | ||
+ | - Branding looks right (logos not blurry; footer/ | ||
+ | |||
+ | **6) Client warnings** | ||
+ | - No “External sender” or “Failed authentication (SPF/ | ||
+ | - Not flagged by your mail client | ||
+ | |||
+ | **7) Verify safely (don’t use email links)** | ||
+ | - Open the website/app yourself from a **saved bookmark** or by **typing** the address. | ||
+ | - Call/ | ||
+ | - For payments/ | ||
+ | |||
+ | **8) If suspicious** | ||
+ | - Don’t click, don’t reply, don’t forward (except to IT/ | ||
+ | - Use **Report phishing** in your mail app, then delete. | ||
+ | - If you clicked or entered details: **change password**, enable **MFA**, inform IT/bank, run a malware scan. | ||
+ | - Optional: forward to **reportphishing@apwg.org**. | ||
---- | ---- | ||
- | ===== 2) Sender Check ===== | + | ===== Visual Example (hover reveals mismatched domain) ===== |
- | * Display **name** matches someone you know or a real department. | + | {{:picture1.png?400|}} |
- | * **Email address** uses the real domain (no look-alikes like `rnicrosoft.com`, | + | |
- | * **Reply-To** matches the **From** address (no domain switch). | + | |
---- | ---- | ||
- | ===== 3) Link Safety | + | ===== Country & ccTLD Reference (weak signal only) ===== |
- | * Hover links: target stays on the **brand’s real domain** | + | ^ ISO ^ Country ^ ccTLD ^ |
- | * No link shorteners | + | | AF | Afghanistan | .af | |
- | * Avoid scanning QR codes from emails. | + | | AL | Albania | .al | |
+ | | AM | Armenia | .am | | ||
+ | | AO | Angola | .ao | | ||
+ | | AZ | Azerbaijan | .az | | ||
+ | | BA | Bosnia and Herzegovina | .ba | | ||
+ | | BD | Bangladesh | .bd | | ||
+ | | BF | Burkina Faso | .bf | | ||
+ | | BG | Bulgaria | .bg | | ||
+ | | BH | Bahrain | .bh | | ||
+ | | BI | Burundi | .bi | | ||
+ | | BJ | Benin | .bj | | ||
+ | | BM | Bermuda | .bm | | ||
+ | | BN | Brunei | .bn | | ||
+ | | BO | Bolivia | .bo | | ||
+ | | BS | Bahamas | .bs | | ||
+ | | BT | Bhutan | .bt | | ||
+ | | BY | Belarus | .by | | ||
+ | | BZ | Belize | .bz | | ||
+ | | CD | Congo (Democratic Republic) | .cd | | ||
+ | | CF | Central African Republic | .cf | | ||
+ | | CG | Congo (Republic) | .cg | | ||
+ | | CI | Côte d’Ivoire | .ci | | ||
+ | | CL | Chile | .cl | | ||
+ | | CN | China | .cn | | ||
+ | | CO | Colombia | .co | | ||
+ | | CR | Costa Rica | .cr | | ||
+ | | CU | Cuba | .cu | | ||
+ | | CV | Cabo Verde | .cv | | ||
+ | | CY | Cyprus | .cy | | ||
+ | | CZ | Czechia | .cz | | ||
+ | | DJ | Djibouti | .dj | | ||
+ | | DM | Dominica | .dm | | ||
+ | | DO | Dominican Republic | .do | | ||
+ | | DZ | Algeria | .dz | | ||
+ | | EC | Ecuador | .ec | | ||
+ | | EE | Estonia | .ee | | ||
+ | | ER | Eritrea | .er | | ||
+ | | ET | Ethiopia | .et | | ||
+ | | GA | Gabon | .ga | | ||
+ | | GD | Grenada | .gd | | ||
+ | | GE | Georgia | .ge | | ||
+ | | GH | Ghana | .gh | | ||
+ | | GM | Gambia | .gm | | ||
+ | | GN | Guinea | .gn | | ||
+ | | GQ | Equatorial Guinea | .gq | | ||
+ | | GT | Guatemala | .gt | | ||
+ | | GW | Guinea-Bissau | .gw | | ||
+ | | GY | Guyana | .gy | | ||
+ | | HN | Honduras | .hn | | ||
+ | | HR | Croatia | .hr | | ||
+ | | HT | Haiti | .ht | | ||
+ | | HU | Hungary | .hu | | ||
+ | | IN | India | .in | | ||
+ | | IQ | Iraq | .iq | | ||
+ | | IR | Iran | .ir | | ||
+ | | JM | Jamaica | .jm | | ||
+ | | JO | Jordan | .jo | | ||
+ | | JP | Japan | .jp | | ||
+ | | KE | Kenya | .ke | | ||
+ | | KG | Kyrgyzstan | .kg | | ||
+ | | KH | Cambodia | .kh | | ||
+ | | KI | Kiribati | .ki | | ||
+ | | KM | Comoros | .km | | ||
+ | | KN | Saint Kitts and Nevis | .kn | | ||
+ | | KP | North Korea | .kp | | ||
+ | | KR | South Korea | .kr | | ||
+ | | KW | Kuwait | .kw | | ||
+ | | KZ | Kazakhstan | .kz | | ||
+ | | LA | Laos | .la | | ||
+ | | LB | Lebanon | .lb | | ||
+ | | LC | Saint Lucia | .lc | | ||
+ | | LK | Sri Lanka | .lk | | ||
+ | | LR | Liberia | .lr | | ||
+ | | LS | Lesotho | .ls | | ||
+ | | LT | Lithuania | .lt | | ||
+ | | LV | Latvia | .lv | | ||
+ | | LY | Libya | .ly | | ||
+ | | MD | Moldova | .md | | ||
+ | | MG | Madagascar | .mg | | ||
+ | | MK | North Macedonia | .mk | | ||
+ | | ML | Mali | .ml | | ||
+ | | MM | Myanmar | .mm | | ||
+ | | MN | Mongolia | .mn | | ||
+ | | MR | Mauritania | .mr | | ||
+ | | MT | Malta | .mt | | ||
+ | | MU | Mauritius | .mu | | ||
+ | | MW | Malawi | .mw | | ||
+ | | MX | Mexico | .mx | | ||
+ | | MY | Malaysia | .my | | ||
+ | | NE | Niger | .ne | | ||
+ | | NG | Nigeria | .ng | | ||
+ | | NI | Nicaragua | .ni | | ||
+ | | NP | Nepal | .np | | ||
+ | | OM | Oman | .om | | ||
+ | | PA | Panama | .pa | | ||
+ | | PE | Peru | .pe | | ||
+ | | PG | Papua New Guinea | .pg | | ||
+ | | PK | Pakistan | .pk | | ||
+ | | PL | Poland | .pl | | ||
+ | | PR | Puerto Rico | .pr | | ||
+ | | PS | Palestine | .ps | | ||
+ | | PW | Palau | .pw | | ||
+ | | PY | Paraguay | .py | | ||
+ | | QA | Qatar | .qa | | ||
+ | | RO | Romania | .ro | | ||
+ | | RS | Serbia | .rs | | ||
+ | | RU | Russia | .ru | | ||
+ | | RW | Rwanda | .rw | | ||
+ | | SA | Saudi Arabia | .sa | | ||
+ | | SB | Solomon Islands | .sb | | ||
+ | | SC | Seychelles | .sc | | ||
+ | | SD | Sudan | .sd | | ||
+ | | SG | Singapore | .sg | | ||
+ | | SI | Slovenia | .si | | ||
+ | | SK | Slovakia | .sk | | ||
+ | | SL | Sierra Leone | .sl | | ||
+ | | SM | San Marino | .sm | | ||
+ | | SN | Senegal | .sn | | ||
+ | | SO | Somalia | .so | | ||
+ | | SR | Suriname | .sr | | ||
+ | | SS | South Sudan | .ss | | ||
+ | | ST | São Tomé and Príncipe | .st | | ||
+ | | SV | El Salvador | .sv | | ||
+ | | SY | Syria | .sy | | ||
+ | | SZ | Eswatini | .sz | | ||
+ | | TJ | Tajikistan | .tj | | ||
+ | | TL | Timor-Leste | .tl | | ||
+ | | TM | Turkmenistan | .tm | | ||
+ | | TN | Tunisia | .tn | | ||
+ | | TO | Tonga | .to | | ||
+ | | TT | Trinidad and Tobago | .tt | | ||
+ | | TV | Tuvalu | .tv | | ||
+ | | TW | Taiwan | .tw | | ||
+ | | TZ | Tanzania | .tz | | ||
+ | | UA | Ukraine | .ua | | ||
+ | | UG | Uganda | .ug | | ||
+ | | UZ | Uzbekistan | .uz | | ||
+ | | VC | Saint Vincent and the Grenadines | .vc | | ||
+ | | VE | Venezuela | .ve | | ||
+ | | VG | Virgin Islands (British) | .vg | | ||
+ | | VI | Virgin Islands (U.S.) | .vi | | ||
+ | | VN | Vietnam | .vn | | ||
+ | | WS | Samoa | .ws | | ||
+ | | YE | Yemen | .ye | | ||
+ | | YU | Yugoslavia | .yu | | ||
+ | | ZA | South Africa | .za | | ||
+ | | ZM | Zambia | .zm | | ||
+ | | ZW | Zimbabwe | .zw | | ||
+ | | AX | Åland Islands | .ax | | ||
+ | | FO | Faroe Islands | .fo | | ||
+ | | GI | Gibraltar | .gi | | ||
+ | | GL | Greenland | .gl | | ||
+ | | GG | Guernsey | .gg | | ||
+ | | JE | Jersey | .je | | ||
+ | | MF | Saint Martin (French part) | .mf | | ||
+ | | MQ | Martinique | .mq | | ||
+ | | RE | Réunion | .re | | ||
+ | | SX | Sint Maarten (Dutch part) | .sx | | ||
+ | | SH | Saint Helena, Ascension and Tristan da Cunha | .sh | | ||
+ | | PM | Saint Pierre and Miquelon | .pm | | ||
+ | | TF | French Southern and Antarctic Lands | .tf | | ||
+ | | WF | Wallis and Futuna | .wf | | ||
+ | |||
+ | |||
+ | |||
+ | **Notes:** | ||
+ | |||
+ | *.yu* (Yugoslavia) = **retired**.\\ | ||
+ | *.mf* (Saint Martin, FR) = **reserved/ | ||
+ | **Reminder: | ||
---- | ---- | ||
- | ===== 4) Attachments | + | ====== WHAT TO DO If You Clicked — And If You Entered Info ====== |
- | * You were expecting an attachment from this sender. | + | **Audience: |
- | * **Block risky types:** `.exe .js .scr .bat .ps1 .vbs .iso .img .zip .html .htm` | + | **Goal:** Fast, idiot-proof actions that limit damage.\ |
- | * Office/ | + | **Use when:** You clicked a suspicious link OR you entered details on a fake site. |
---- | ---- | ||
- | ===== 5) Language & Look ===== | + | ===== 0) TL;DR ===== |
- | * Uses your correct name and specific details | + | * If you only **clicked**: |
- | | + | * If you **entered any info**: **Change that password NOW (from a different device)** → **Enable/ |
- | * Branding looks normal | + | |
---- | ---- | ||
- | ===== 6) Mail Client Warnings | + | ===== 1) Scenario A — Clicked the link, did NOT enter anything |
- | * No “External Sender” or “SPF/DKIM/DMARC failed” banners. | + | **Within 10 minutes** |
- | * Not auto-flagged | + | |
+ | - Close the tab/app. If it won’t close, reboot. | ||
+ | - **Clear only the phishing site’s data**: | ||
+ | * Chrome/Edge: Menu → Settings → Privacy → Cookies & Site Data → **See all site data** → search the domain → Remove.\\ | ||
+ | * Safari (iOS/ | ||
+ | | ||
+ | |||
+ | **Within 1 hour** | ||
+ | | ||
+ | * **Windows: | ||
+ | * **macOS:** Update macOS, then run a full scan if you have reputable AV.\\ | ||
+ | * **Android: | ||
+ | * **iOS/ | ||
+ | - If that browser was already **logged in** to email/ | ||
+ | |||
+ | **Report** | ||
+ | - Use **Report phishing** in your mail app and send the message to IT/ | ||
+ | - Optional public reporting: **[[https:// | ||
---- | ---- | ||
- | ===== 7) Verify Safely (never via email links) ===== | + | ===== 2) Scenario B — You entered info on the phishing site ===== |
- | * Open the website/app yourself from a **saved bookmark** or by **typing** the address. | + | Do **all** applicable items below, in this order. |
- | * Call/message | + | |
- | * For payment/bank-detail changes: perform a **voice check** with your contact. | + | **A) If you entered your work or personal account password** |
+ | | ||
+ | - Turn **MFA on** (or re-enrol a fresh MFA method). | ||
+ | - **Sign out everywhere**:\\ | ||
+ | * Google: myaccount.google.com → Security → **Manage all devices** → Sign out of unrecognised devices; **Third-party access** → Remove unknown apps.\\ | ||
+ | * Microsoft 365: myaccount.microsoft.com → Security info → **Sign out everywhere**; | ||
+ | | ||
+ | * Look for auto-forward to unknown addresses, reply-to changes, or auto-delete rules. Remove anything suspicious. | ||
+ | |||
+ | **B) If you entered card or banking info** | ||
+ | - Call your bank immediately (use the number on the card/official app) → **block | ||
+ | - Turn on transaction alerts. Consider a **temporary credit ban/freeze** with AU credit bureaus | ||
+ | |||
+ | **C) If you entered ID documents (driver’s licence, passport, Medicare)** | ||
+ | - Contact the issuing authority to **flag** or **replace** the document | ||
+ | | ||
+ | |||
+ | **D) If you installed anything or accepted an extension** | ||
+ | | ||
+ | - Run the scans listed in *Scenario A* (Defender Offline etc.). | ||
+ | - For managed work devices: **isolate** the device and notify IT to run full EDR scans. | ||
+ | |||
+ | **E) Tell IT/Security (work accounts)** | ||
+ | - Send the original email (as attachment if possible) and include: | ||
+ | - Expect IT to: force password resets, revoke sessions/ | ||
---- | ---- | ||
- | ===== 8) If Suspicious | + | ===== 3) What NOT to do ===== |
- | | + | |
- | * Use “Report phishing” in your mail app, then delete. | + | |
- | | + | |
- | | + | |
---- | ---- | ||
- | ===== 9) One-Minute Flow (print-friendly) ===== | + | ===== 4) Aftercare |
- | - Expecting? → From these people? → Account exists?\ | + | - Watch your inbox for password-reset emails you didn’t initiate. |
- | - Check From + Reply-To domain → Hover every link → Attachment type safe?\ | + | - Review recent account activity/ |
- | - Read tone/ | + | - For banking: monitor transactions; |
- | - Verify via bookmark/known number → If doubt, report and delete. | + | - Consider a **security check-up** (Google/Microsoft account security pages). |
---- | ---- | ||
- | ===== Notes for Admins (optional) ===== | + | ===== 5) Optional: Template to report to IT ===== |
- | * Add your internal report address here: **security@yourdomain.tld**\ | + | (see [[https:// |
- | * Add your policy page link here: **[[https://portal.yourdomain.tld/security-policy|Email Security Policy]]**\ | + | |
- | * Train users to screenshot headers when reporting. | + | > **Subject:** Possible phishing — clicked/ |
- | ``` | + | > **When:** YYYY-MM-DD HH:MM (local time) |
+ | > **From address of email:** (copy/ | ||
+ | > **Link hovered/ | ||
+ | > **What I did:** Clicked only / Entered password | ||
+ | > **Device & OS:** (e.g., Windows 11 laptop) | ||
+ | > **Browser: | ||
+ | > **Actions taken so far:** Disconnected, | ||
+ | > **Attachments: | ||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== 6) Quick Reference (one-minute flow) ===== | ||
+ | - Clicked? **Disconnect → Close → Clear site data → Scan → Report.**\ | ||
+ | | ||
clt_email_legitimacy_checklist.1760648897.txt.gz · Last modified: by thesaint