Most security experts believe the weakest point of defence against hacking and internet scam is the users. Also known as “Phishing”, these emails look pretty convincing these days.
From people advertising non-existent rental properties, to refund from UK’s HMRC (Tax Office), driving fines from Spanish Trafico, or invoices from utilities, they all look very genuine until you dig deeper.
So how do you stop being a victim of a Scam?
Human Condition vs Fraudsters
Scammers rely on 2 basic human conditions!
- Firstly, humans are eternal optimists so when good fortune appears to have happened to them, they never ask “Why me?”. So the idea of having won something, an unexpected order, a tax rebate, or any good fortune is highly attractive to us.
- Secondly, humans are also curious. They have the urge to peek at things, even when they know it may be harmful!
What are the Warning Signs
There are 2 fundamental aspects of internet scams that you need to watch out for and closely inspect:
1. The Storyline Flaws
- “Why me?”- We tend to ask this question only when bad things happen. When good fortune arrives, and someone tells us we have won a prize or are entitled to an unexpected money, we don’t often question it.
- “Why this way?” – Why would your bank, tax office, etc. contact you on this email address? Is this your normal means of communications? Have you ever given them this email address?
- “Salutation” – Is it normal for the tax office to address you by your first name? If not, then ask yourself why they have this time. There are lots of telltale signs that can give away the plot, but we tend to ignore them because the news is so good or worrying bad like a traffic fine!
- “Are there any spelling mistakes, or poor use of language?” – Most official communications are read, reread, and proofread, so it is unusual for spelling mistakes or obvious grammatical errors to get through.
- “Can you Verify?” – Contact the company by other means (phone, website, emails you trust, etc.), and ask “Is this from you?”. If they sound puzzled, you know the answer.
2. The Technology Flaws
If you can’t get clear answers from the above, you need to investigate the technology signals that might give you the warning signs.
a) Email Address
Ignore who the email claims it is from. All email addresses have 2 visible identities. One is the “Alias” (the name you see displayed), and the other is the email address (the real address of the sender). So don’t just rely on the email sender claiming they are from “Tax Office” or “XYZ Company”. Click on the email name field and to reveal the real email address. But, beware that email addresses can be cloned (see below under Headers).
If the email address is not from the expected domain (XYZCompany.com or similar), then it is not to be trusted.
If it is from Gmail, Hotmail, Outlook, or any other generic email address, then you know for sure it is a scam. Genuine companies do not use these addresses, as they have emails that is linked with their website domain name such as something@companyname.com or similar.
The bad news is even seeing the company’s domain name in the email address is not a guarantee for it being genuine! Email addresses can be cloned. When you get a suspicious email, you really have to check who and how they sent it to you by checking the Full Header (see below).
b) Email Headers
When you receive an email your email application shows you a “summary” header, which includes the email Alias name, Email Address, the recipient (you), subject line, and time and date. This is what most people see.
You need to check the “Full Header”, but this requires a little bit of technical skill and detective work.
As people use different applications to collect emails, there is no single method of getting to see the Full Header. The best way to find out how to do it is to search for “How to view Full email Header in ABC”, and ABC is your email application, and if using Gmail, or Hotmail, etc., replace ABC with Gmail or Hotmail, etc.
The full header gives you the ID of the real sender, their IP Address, the path, and sent time stamp. As you can see from the example here (click on the image to see clearly), we have highlighted the information that should alarm you in red.
The email claimed to be from “burofax”, Spain’s secure email service used to deliver official notice from legal professionals, courts, and official bodies. Rather unlikely for their server to be located in Russia (.ru)!!
c) Embedded Links
Using HTML coding you can hide the real destination of the link from the person reading the email. Depending on the email software you are using, you can reveal the true URL destination. Usualy, you can hover your mouse over the link and see the real link (or the hidden link). However, not all email apps allow you to do this, and of course if you are using a mobile or tablet, you cannot hover because you don’t have a mouse!
However, you can copy the link which will show you real target URL, without clicking on it (very important you do not activate the link).
If using a mouse, right click on the link > select “Save Link Location” > Paste it in a Word or Text document so that you can see the real and full URL (do not paste in your browser in case you actually visit it by mistake!).
If using the touchscreen device, press and hold the link (DO NOT TAP), and you get options to Save or Copy the link. Now do the same by pasting it in a text document so that you can see the real link.
If it is not going to the website it claims, then do not open the link under any circumstances, not even to take a peak out of curiosity.
What to do next
Once you suspect the email is phishing or scam, you should always report it to your email hosting provider. Don’t just mark it as Spam or delete it.
When you report them as “Phishing” or “Scam”, you need to send the full header with it. Most reputable hosting companies follow them up and try to either stop it at source, or blacklist the sender.
Once a sender is blacklisted, email servers will not accept further emails from that source. Additionally, the IP Address and domain name is added to the “Black Lists” used by email providers that identify suspect senders, and in turn reject emails from them.
You can see why it is so important to report these incidents, rather than just delete them or mark them as spam. Failing to report them means the scam continues to claim victims.
Summary
You have to be vigilant. Always verify and examine emails you were not expecting, or from people you do not know.
Check and verify the sender as well as any links in the email before clicking on them. If you are not sure, then forward it to your email administrator or your email service provider.
Do not be content with you not becoming a victim, and report it to your mail service providers, so that they can stop others becoming a victim.

