Email Safety Guide
Phishing
Social engineering is the art of manipulating people into giving up confidential information or performing actions that compromise security. Phishing is a specific type of social engineering attack delivered via email.
In both attacks, attackers exploit psychological triggers such as:
-
- Urgency: Creating a false sense of emergency (e.g., “Your account will be deleted in 1 hour!”) to bypass critical thinking.
- Authority: Pretending to be your supervisor, IT support, payroll, or a government official.
- Fear: Threatening legal action, financial loss, or reputational damage.
- Rewards: Offering unrealistic rewards, prizes, or investment opportunities.
- Helpfulness: Impersonating someone in distress who needs immediate assistance.
Identifying Phishing
Common characteristics of phishing emails include:
-
- Spoofed Sender Addresses: The display name might say “IT Support,” but the actual email address is support@secure-login-update.example instead of @clark.edu.
- Suspicious Links: Hovering over a link reveals a URL that doesn’t match the claimed destination (e.g., a link claiming to go to paypal.com that actually goes to paypal1-security.example).
- Unexpected Attachments: Files you weren't expecting, especially executable files (.exe, .scr), office documents (.docx, .pdf), or compressed archives (.zip). These may appear to be invoices, receipts, shipping confirmations, or official documents from legitimate organizations.
- Urgent Calls to Action: Demanding immediate password resets or payment verification.
- Requests for Sensitive Information: Legitimate organizations rarely ask for passwords, Social Security numbers, or payment details via email. Be wary of messages requesting you to verify account credentials or MFA security codes, or provide financial data.
How to Handle Email Quarantine
An email quarantine is a security feature used by email providers to isolate suspicious messages before they reach your inbox. If you receive a notification that an email has been quarantined:
-
- Review the Message: You may be able to view the email content or see a preview. Check the sender and the subject line.
- Determine Legitimacy:
-
-
- If it looks legitimate: If you were expecting the email and the content seems safe, you can choose to “release” the message. This moves it to your inbox.
- If it looks suspicious: Leave it in quarantine. It is safer to miss a legitimate email than to click a phishing link.
-
How to Handle Phishing
If you suspect an email is a phishing attempt, do not click any links or download attachments. Follow these steps instead:
-
- Verify the Source: If the email claims to be from a company or colleague, contact them through a known trusted channel to confirm they sent it.
- Inspect the Details: Look closely at the sender’s email address, not just the display name. Check for misspellings in the domain name.
- Report It: Click the "Report Phishing” button in Outlook or forward the email to Clark College’s phishing inbox (phishing@clark.edu). For more information on reporting phishing emails, visit the Report an Incident page.
- Delete It: Remove the email from your inbox to prevent accidental clicks.
Junk & Spam
While both junk mail and phishing attempts arrive in your inbox unwanted, they serve very different purposes. Junk or spam is primarily a nuisance. There are mass-blasted emails sent to random addresses with the goal of advertising products or selling items. Phishing, on the other hand, is a criminal act with a much higher risk profile.
Please note that mislabeling legitimate junk or spam as phishing diverts the InfoSec Team's attention and consumes crucial time that should be focused on genuine threats.
How to Handle Junk & Spam
Here is the best approach to dealing with spam:
-
- Block the Sender: Use the blocking feature in your email settings to prevent future emails from that specific sender by following these steps: https://support.microsoft.com/en-US/Outlook/mail/block-or-unblock-senders-in-outlook.
- Report It: Click the "Report Junk” button in Outlook to flag suspicious messages. This helps train Outlook's filters and protects your Clark College’s inboxes from future threats.
- Delete It: If you are confident an email is harmless spam, simply delete it. Do not open attachments or click links as some spam can contain tracking pixels that confirm your address is active.
- Do Not Unsubscribe: Unlike legitimate newsletters, never click the “Unsubscribe” link. Scammers often use these links to verify that your email address is active. Once verified, they may sell your address to other spammers.
Contact Us
General Inquiries: For non-urgent questions, email infosec@clark.edu.
Report an Incident: To report an information security incident, please visit the Report an Incident page.
Additional Resources
Multi-Factor Authentication Guide