When an external email comes in but the headers say it's from one of your own domains, Put a warning image into the picture slot and put a warning as the first line of the email.

For example. If we owned test.com and an email came in saying it was from ceo@test.com but was actually sent from an external server put the warnings on the email.

If staff want to send from their work address they would do it from groupwise / webmail / GMS / Connecting Directly to the LDAP Server, so the chances are this is a phishing email.

Comments

  • Yes please!