My employer uses Google for email, etc. There are email headers in the tests we get like X-PHISHTEST and X-SECURITY-TEST. I wrote a Google script that analyzes incoming emails for these headers and adds a “Phishing” tag to anything with one of these headers. So they show up highlighted in my inbox. I doubt I’m the only person who has done something like this.
If the words “email headers” are anything more than gobblygook to you, then you’re not the one the clicker trainings are intended for.
The phish test emails are however quite handy for staying vigilant. When good defenses make it take years for a real phishing email to sneak through, then being already primed by the quarterly phish tests to be suspicious helps ensure that as many people as possible don’t get compromised
My employer uses Google for email, etc. There are email headers in the tests we get like X-PHISHTEST and X-SECURITY-TEST. I wrote a Google script that analyzes incoming emails for these headers and adds a “Phishing” tag to anything with one of these headers. So they show up highlighted in my inbox. I doubt I’m the only person who has done something like this.
If the words “email headers” are anything more than gobblygook to you, then you’re not the one the clicker trainings are intended for.
The phish test emails are however quite handy for staying vigilant. When good defenses make it take years for a real phishing email to sneak through, then being already primed by the quarterly phish tests to be suspicious helps ensure that as many people as possible don’t get compromised
The people who know how to do that are probably not the people falling for the mails anyway.