• frickineh@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    11 months ago

    We get those, but the sender email shows up as [email protected] or whatever. Literally the most obvious possible address. I’m always tempted to forward one to IT and ask if they’re serious with that shit.

    • ArbitraryValue@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      11 months ago

      Ours are the opposite: the sender’s email shows up as a normal [email protected] email. Gmail is supposed to warn when a return address is being spoofed like that, but I guess my company turned that warning off for these fake phishing emails. There’s still no SPF but I don’t check the SPF unless an email looks suspicious so I hope that that warning will work for real, sophisticated phishing.