Quotes | Summary | When Email Best? | Email Account |
Malware | Spam | Web Mail | Client App | Tracking |
References: General | Android | Gmail, Google | Government | iCloud |
iOS | macOS | ReplyAll | Spam | Tracking | Windows | Yahoo
Quotes
- "Email: nothing more than...
- 'Spam will soon be...
- "I just got an email about how to read maps backwards, but...
- A child was watching her mother sift through and delete a long list of junk E-mail.
"This reminds me of the Lord's Prayer," the child said.
"What do you mean?" the mother asked.
"You know... - "I've Never Sent an Email"...
Summary
- [1] Is Email the Best Communication Method?
- [1] Protect Email Account
- [1] Avoid Malware in Attachments and Links
- [1] Reduce Spam
- [2] Webmail in Browser: use HTTPS:
- [2] Email Client App: use TLS/SSL for login, transfer, sending
- [2] Reduce Email Tracking
- [3] see section: Encryption, Anonymity
- References
[1] Is Email the Best Communication Method?
- Type of information -- and its sensitivity? Audience? Timeliness?
- Even though email should be encrypted in transit to mail server, it may no longer be private when stored on mail server or on recipient's computer; what if it becomes public later?
- Verify intended addressees before sending, i.e., To:, cc:; autocomplete/autofill may be incorrect; Reply vs. Reply All
- Use bcc: for groups to protect privacy and reduce Reply All volume
- Email is not the best way to send large / many attachments -- see Share Files Privately
- Is the email service provided by your ISP adequate, reliable, secure, well-maintained?
- Email provider's privacy policy and business model?
some providers, e.g., ProtonMail; Posteo; Tutanota; FastMail; Thexyz; Kolab Now; Mailbox.org, may provide more privacy or "end-to-end encryption"; section Encryption, Anonymity - Ethical.net: Email services
- Maybe communicate fragments of secrets over different channels, e.g., phone, text message, video, etc., to replace / complement email -- see section Talk and Chat Privately
[1] Protect Email Account
- Use a 'permanent' account if possible, e.g., icloud.com, gmail.com, outlook.com
- If you rely primarily on your ISP (charter, comcast, ashlandhome), what happens to your address if you move or change ISPs?
- If your email account is hacked, change password immediately.
- If that same password was used for any other accounts, be sure to update those accounts also.
- Check Sent/Trash for any messages sent by hacker, e.g., password resets for other accounts.
- Strengthen security answers; turn on 2-factor authentication if available, etc.
[1] Avoid Malware in Attachments and Links
- Don't open/download unexpected attachments in messages; enable malware protection; check Sender:
- [1] macOS: click on the little downward pointing “v” at the right of the From address to see address of sender
- [2] macOS:
Mail > View > Message > All Headers
- Most email applications display messages as mini-web pages -- with problems (like web) of ad tracking, fraudulent links, etc.
- Don't click on links in messages; even truer for unexpected messages about products/sites/services you don't use
- Exceptions: after changing an email address on an account, the site often sends an email with a link to verify the address; others??
- If an email asks you to click a link/button to address a problem or change your password, log in to the site directly using your password manager -- not the email links, unless you've just initiated a "I forgot my password" request
- If it's an offer to update software, use the official methods described earlier to check, download and install
- Quiz: Can You Identify Phishing Emails?
- To avoid displaying possible mal-content, don't open or display message in first place:
- macOS:
Mail > ctrl-click msg > Delete
(individual msg) - macOS:
Mail > Mailbox > Erase Junk Mail
(delete all w/o opening) - macOS:
Mail > (drag dot on separator bar -- between message list & preview area -- to bottom of window)
; select & delete message(s); restore bar - iOS:
Mail > (swipe left on title in message list) > Trash
- When sending large attachments, enable "Mail Drop", which uses iCloud temporarily
- macOS:
Mail > Preferences > Accounts > (account) > Advanced > Send Large Attachments with Mail Drop
- iOS: no need to set -- triggered automatically; select
Use Mail Drop
from popup - When sending attachments to a Windows user:
- macOS:
Mail > File > Attach Files > Options > Send Windows-friendly Attachments
[1] Reduce Spam
- Don't forward chain letters or spam; check Snopes
- Unsubscribe from reputable sources only; otherwise, you just confirmed validity of your address to a spammer
- Limit auto-reply usage: omit dates when your house can be burgled, spam confirmations
- It's difficult to reduce/eliminate spam once your email address has been disseminated, e.g., by replying to spammers, by making address public on a web site or forum, by malware harvesting your friend's Contacts, etc.
- Use filters to minimize danger from phishing, and annoyance from spam;
check Junk/Spam folder periodically for good messages, move messages to "train" - If using multiple devices and IMAP, centralize settings with mail provider
- gmail.com: Spam: no setup required
- gmail.com:
Settings > Filters
- If not centralized, spam and filter settings for individual device:
- macOS:
Mail > Preferences > Junk Mail
- macOS:
Mail > Preferences > Rules
- The most common scams will target you through fake emails, text messages, voice calls,
letters or even someone who unexpectedly shows up at your front door.
Review all five scenarios for important red flags that could signal a scam. - 1. You're pressured to act immediately
- Remember: In some cases, scammers can be friendly, sympathetic and seem willing to help.
In others, they use fear tactics to persuade a potential victim, for example: - You're instructed to not trust your bank, or to respond to questions in untruthful ways.
- You're pressured to send money.
- You're threatened with law enforcement action.
- You receive a request from a government agency or the IRS
asking you for a payment and/or to verify your personal information.
Scammers may threaten lawsuits or law enforcement action to trick you in to acting quickly. - 2. You're asked to provide authorization codes
- Remember: Authorization codes are important ways to verify who you are in order to access your account.
- Never share your authorization codes, regardless of the reason someone gives you,
unless you've contacted the company through a verified method.
Once a scammer has your codes, they can gain full access to your accounts. - Your company should never text, email or call you asking for an authorization code.
If someone reaches out to you and asks for it, it is a scam. - 3. You've received a suspicious text or email
- Your account should not use email or text to ask you for personal information
such as your account number, card PIN, Social Security number or tax ID number. - The best way to avoid email or text fraud is to remain vigilant.
Never click on a link in an email or text message unless you are absolutely certain
who sent the email and where the link is taking you. - Fraudulent emails or texts typically imply urgency, attempting to get you to act quickly
before you have time to carefully read and examine the message.
They often don't address you by name and contain obvious grammar and/or spelling errors. - 4. You're told to buy a gift card to pay a debt or a service.
- Never share gift card information (such as the card's unique identifier number) with someone you don't know.
- Criminals may pressure you to send funds via gift cards by asking for the code numbers
or PINs on the backs of the cards so they can be redeemed immediately. - A scammer may tell you a story that they urgently need funds to pay a debt,
for a medical emergency or they want to travel to see you. - 5. You're asked to deposit a check and return the money
- Never cash a check for someone you don’t know.
The bad check will be held against your account when it doesn't clear. - If you're asked to return money for overpayment of an item you’re selling, it’s most likely a scam
and the bad check will be held against your account when it doesn't clear. - You're approached by a stranger who claims to have left their wallet at home and asks you to cash a check for them.
Or you may be asked to deposit a check that overpays for something you’re selling, then send the difference elsewhere.
[2] Webmail in Browser: use HTTPS:
- Webmail on your ISP's website, e.g., icloud.com/#mail, gmail.com, mail.yahoo.com, webmail.aol.com
- Some ISPs, e.g., ashlandhome.net, may support HTTPS: only for desktop (not mobile) browser
- If ISP also doesn't support SSL/TLS in email client (next), obtain a separate, secure account for your main communication; also more portable if you move or change providers
- Some sites communicate only via secure email "portal", e.g., medical, financial
[2] Email Client App: use TLS/SSL for login, transfer, sending
- Use SSL (Secure Socket Layer, or newer TLS: Transport Layer Security) in an email client app, e.g., Mail on iOS / macOS; Thunderbird, Outlook, Outlook Express; network: {Figure 6. TCYOP-4: 67}
- i.e., for your account: login, transfer, sending
- When adding an account, certain providers may have automatic settings/templates
- iOS:
Settings > Accounts & Passwords > Add Account
- macOS:
Mail > Accounts > +
- Otherwise, check email app or email provider's site for configuration details, e.g., mail settings tool
- Login, transfer: enable SSL for IMAP or POP email; {Figure 16: TCYOP-4: 120; TCYOP-3: 96}
- Do not use unencrypted POP, e.g., earthlink
- IMAP: better for sharing messages & folders between devices; webmail; backup?
- if using IMAP, check if supported by email provider; enable if necessary
- iOS:
Settings > Mail, Contacts, Calendars > (account) > Account > Advanced > Use SSL
- macOS: generally, adding a new account will automatically enable SSL for receiving & sending; to check this:
- macOS:
Mail > Inbox > (ctrl-click) > Account Info > Summary > Incoming SSL: on
- macOS (older):
Mail > Preferences > Accounts > (account) > Advanced > Use SSL
- Sending: enable SSL, i.e., SMTP server
- Can you access email easily while traveling, esp. sending?
- iOS:
Settings > Mail, Contacts, Calendars > (account) > Account > SMTP > (server) > Use SSL
- macOS:
Mail > Inbox > (ctrl-click) > Account Info > Summary > Outgoing SSL: on
- macOS (older):
Mail > Preferences > Accounts > (server) > Account Info > Outgoing Mail Server (SMTP) >
Edit SMTP Server List > (server) > Advanced > Use SSL
[2] Reduce Email Tracking
- Disable image display -- to minimize tracking; extra benefit: slightly faster display
- macOS:
Mail > Preferences > Viewing > Load content in remote messages
- macOS:
Mail > (individual message) > Load Remote Content
- iOS:
Settings > Mail,Contacts,Calendar > Load Remote Images
- Some messages provide a link to view the message in browser, which, if configured properly, might provide better security.
- more selective solutions are being developed to block 1x1 tracking pixels (all, or selected marketers) --analogous to Browsing : Adware); e.g., PixelBlock, UglyMail; stay tuned
- Create different email addresses or aliases for different purposes -- via different providers: iCloud, Yahoo, Gmail, Live, etc.
- Apple allows 3 aliases that are redirected to main account, e.g., main: johsmith@icloud.com; aliases: jsmithabc@icloud.com, jsmithdef@icloud.com, jsmithghi@icloud.com
- macOS:
Mail > Preferences > Accounts > iCloud > Edit: Email Address > (icloud.com/) > Mail > Add an alias
- Some providers allow "+" suffix, e.g., johnsmith+amazon@icloud.com, john.smith+facebook@gmail.com; those recipients appear in main Inbox
- This allows you to track who gave out your address, and to setup email filters; addresses completely separate from your main account are desirable for password resets, even though inconvenient; it also could provide some anonymity if your address is leaked later; unfortunately, some sites may not allow "+" in username or email contact fields.
- [Spam]: 'Gmail: Your address has more or fewer dots (.) or different capitalization'
References
- {TCYOP-4: 110-131; TCYOP-3: 91-106; Understand the Privacy Risks of Email: On your end, In transit, On email servers, On the recipient's end, In backups; Are Gmail Ads an Invasion of Privacy? Log In Securely; Transfer Email Securely; IMAP vs. POP Privacy Implications; Email Your Doctor, Accountant, or Lawyer Privately}
- sections: Android; Gmail, Google; Government; iCloud; iOS; macOS; ReplyAll; Spam; Tracking; Windows; Yahoo
- topics:
- Wikipedia: E-mail; Email address; phishing attempt to acquire sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication
- Wikipedia: phishing types e.g., Spear phishing, Clone phishing, Whaling, Rogue WiFi (MitM)
- Wikipedia: webmail web-based email, e.g., via browser
- Wikipedia: email client (application): Mozilla Thunderbird
- Wikipedia: AOL Mail; Gmail; Windows Live Mail; Yahoo! Mail
- Wikipedia: Post Office Protocol (POP); Internet Message Access Protocol (IMAP); Simple Mail Transfer Protocol (SMTP)
- Wikipedia: Multipurpose Internet Mail Extensions (MIME) encoding for non-text file attachments
- Wikipedia: Secure MIME (S/MIME)
- HowStuffWorks: How E-mail Works; Quiz
- Email - How does it work? video: 1:17
- HowStuffWorks: POP and IMAP servers; SMTP Server
- Wikipedia: email fraud; Internet memex; Internet hoaxes; urban legend
- hoaxes: snopes.com; Urban Legends; Dept. Homeland Security
- HowStuffWorks: How Phishing Works; Phishing Quiz; How E-mail Scams Work
- HowStuffWorks: How do viruses and worms spread in e-mail?; Can the government read your private e-mails?
- Ethical.net: Email services
- How to Back Up Your Emails in Gmail, Outlook, and iCloud Wired; 1/1/2024
- These Are the Best Free Email Accounts
Gmail, Outlook, Proton, Yahoo, Zoho; LH; 10/26/2023 - All the Different Email Addresses You Should Set Up (and What to Use Them For) apps, newsletters, ...; LH; 10/24/2023
- Why ISP email services are terrible, and what to use instead
Apple's iCloud, Google's Gmail, Microsoft's Outlook.com; paid services; ApIn; 5/12/2023 - Everyone Wants Your Email Address. Think Twice Before Sharing It. UID 2.0;
create a bunch of email addresses; use email-masking tools;
when possible, opt out; NYT; 1/25/2023 - Anyone can sign up for DuckDuckGo's privacy-protecting @duck.com email address Verge; 8/25/2022
- 4 Quick Tips for Managing Email Overload on the Go NYT; 6/1/2022
- Now Is a Good Time to Update Your Recovery Email Addresses
make sure those 'emergency' email addresses (you can use to get into your email
and other accounts in case you're locked out) are up to date; Wired; 1/23/2022 - How to Hide Your Email From Data Collectors
Apple's Hide My Email / Sign in With Apple;
Firefox Relay; [Anon]addy; Simplelogin;
DuckDuckGo Email Protection;
1Password and Fastmail's Masked Email;
Use a Temporary Burner Email;
Verge; 12/6/2021 - The Best Ways to Hide Your Email Address
Gmail: add . anywhere, or +label before @;
Yahoo: create up to 500 aliases w/ text appended;
Outlook: create up to 10 aliases;
Apple: Hide My Email;
Firefox: Relay; 5 free aliases; Premium plan for unlimited;
DuckDuckGo: Email Protection;
Fastmail + 1Password: Masked Email;
others: Protonmail, SimpleLogin, Addy;
Giz; 11/23/2021 - Firefox Relay offers unlimited email aliases as part of its new premium plan Eng; 11/16/2021
- How To Fix Email -- with Science!
behavioral changes; Wired; 11/8/2021 - Cut Down on Junk Mail with iCloud+'s Hide My Email TB; 10/21/2021
- 1Password gets its own 'hide my email' feature
Create Masked Email -- unique email aliases for logins, much like
Apple's iCloud Plus Hide My Email function but integrated and not only for Apple users;
video; Verge; 9/28/2021 - Cloudflare Is Taking a Shot at Email Security
Email Routing and Email Security DNS Wizard, built on top of Gmail, Outlook, Yahoo, and others to prevent phishing, spoofing, and more; Wired; 9/27/2021 - Could Gen Z Free the World From Email? NYT; 7/10/2021
- [2] 21Nails vulnerabilities impact 60% of the internet's email servers 5/4/2021
- How to Back Up Your Most Important Emails Forward Emails to a Backup Account; Use POP and IMAP; Download Everything To a Desktop Client; Other Options; Wired; 1/24/2021
- 6 Privacy-Focused Alternatives to the Apps You Use Every Day Signal for Messaging; Firefox for Web Browsing; DuckDuckGo for Search; OsmAnd for Maps; ProtonMail for Email; Jumbo for Social Media; Wired; 12/13/2020
- Some email clients are vulnerable to attacks via 'mailto' links GNOME Evolution, KDE KMail, IBM/HCL Notes, and older versions of Thunderbird that support 'dangerous' parameters like 'attach', 'attachment'; ZD; 8/18/2020
- How Do I Get Into My Email If I've Lost My Recovery Codes? LH; 8/7/2020
- [2] Decades-Old Email Flaws Could Let Attackers Mask Their Identities 18 exploits that take advantage of inconsistencies in the email plumbing most people never think about; Wired; 8/4/2020
- How to Change Your Email Address LH; 6/17/2020
- New Firefox service will generate unique email aliases to enter in online forms Firefox Private Relay add-on; ZD; 5/1/2020
- How Apple ‘Intercepts' And Reads Emails When It Finds Child Abuse using hashes; Forbes; 2/11/2020
- How Big Companies Spy on Your Emails e.g., Edison, Cleanfox: scrape the contents of your email inbox, sell data; MB; 2/10/2020
- How Can I Save All My Emails for a Personal Backup? LH; 1/27/2020
- Switch From Your Internet Provider’s Email to Something Better Gmail, Outlook, iCloud, Fastmail, ProtonMail; NYT; 1/24/2020
- What Your Email Signature Says About You NYT; 12/9/2019
- How to Change Your Email Address Without Screwing Everything Up LH; 10/7/2019
- Automatically Unsubscribe From Unwanted Emails With 'Leave Me Alone' paid, but more private than Unroll.me; LH; 9/24/2019
- Don't Put Your Work Email on Your Personal Phone Mobile Device Management potentially gives your company the ability to spy on your location, your web browsing, and more; 7/23/2019
- Can You Switch ISPs Without Losing Your Email Address? LH; 7/5/2019
- 'The world's greatest email app' is a privacy nightmare Superhuman; tracking pixels; TNW; 7/3/2019
- Your Fake Email Isn't Keeping Your Health App Data Private LH; 5/17/2019
- How to Write the Ultimate Canned Email checklist; LH; 2/25/2019
- 'Catastrophic' hack on email provider destroys almost two decades of data VFEmail says data for virtually all US users is gone for good; Ars; 2/12/2019
Android
Gmail, Google
- Google Is Finally Cracking Down on Mass Emails new bulk email rules; LH; 2/17/2024
- Google will start deleting inactive accounts after two years Ars; 5/16/2023
- Google brings dark web monitoring to all U.S. Gmail users BC; 5/10/2023
- Your Gmail Account Has Unlimited Addresses "+", googlemail.com; LH; 11/21/2022
- How to (hopefully) restore your Gmail account if you lose access Verge; 8/4/2021
- Tired of Gmail? Try a Privacy-First Email Provider ProtonMail, Lavabit, Burner Mail; Wired; 8/16/2020
- 5 Simple Ways to Make Your Gmail Inbox Safer
1. Block Persistent Spammers;
2. Increase the Undo Send Time;
3. Use Confidential Mode;
4. Delete Cached Offline Data;
5. Hide External Images; Wired; 5/23/2020 - How to Free Up Space in Gmail if 15Gb isn't enough; Wired; 10/31/2019
- Gmail confidential mode is not secure or private 6/20/2019
- Gmail becomes first major email provider to support MTA-STS and TLS Reporting new security standards; ZD; 4/11/2019
- Gmail is now blocking 100 million extra spam messages every day with AI using TensorFlow; Verge; 2/6/2019
- Using Gmail "Dot Addresses" to Commit Fraud Schneir; 2/6/2019
Government
iCloud
- Apple will delete your inactive iCloud account faster than Google MW; 5/17/2023
- Three ways to add an iCloud.com address, even if you already have one
AppleID w/o icloud.com address; aliases; new AppleID; MW; 3/20/2023 - How to add an alias email address to your iCloud account MW; 1/23/2023
- How to use iCloud to create rules that automatically sort, delete, & forward Mail ApIn; 9/29/2021
- How to Set Up Custom Email Domains with iCloud Mail TB; 8/27/2021
- Apple announces iCloud+ with privacy-focused features
Private Relay: combines DNS-over-HTTPS with proxy servers);
Hide my email: generate random email addresses;
TC; 6/7/2021 - iCloud email won't send? Here's what to check to fix it
Invalid iCloud sender address;
Too many (> 500) recipients in one message;
Too many recipients across all messages (daily limits);
Attachment size exceeded (w/o MailDrop); MW; 3/4/2021 - How to Set Up and Use iCloud Email Aliases OSXD; 8/15/2020
- How to use iCloud aliases to send and receive email MW; 1/15/2020
iOS
- How to Change Your Default Email and Web Clients in iOS 14 and iPadOS 14 TB; 9/25/2020
- Why the iOS Mail app shows a phantom unread message badge and what to do about it sorting glitch; MW; 7/16/2020
- How to Keep Yourself Safe From the Zero-Day iOS Mail Attacks update imminent, or change from Mail client? LH; 4/23/2020
- How to Add AOL Account to Mail on iPad & iPhone OSXD; 2/16/2020
- How to Fix "No Sender" & "No Subject" Mail Bug in iOS 13 & iPadOS 13 OSXD; 9/28/2019
- Five of the Best Email Apps on iOS Spike, Polymail, Airmail, Spark, Edison Mail; MR; 1/31/2019
macOS
- Wikipedia: Apple Mail
- Take Control: Apple Mail
- How to stop macOS Mail from using a bad email address MW; 7/8/2021
- Can't Scroll a Message in Mail? Here's One Reason Why embedded IFRAME; TB; 3/4/2021
- How to consolidate mail from multiple Macs using Apple Mail MW; 10/30/2020
- Twelve years later, Apple is still trying to erase mac.com email addresses and me.com; ApIn; 8/31/2020
- How to Add an Outlook.com Email Address to Mac Mail OSXD; 2/8/2020
- Apple is fixing encrypted email on macOS because it's not quite as encrypted as we thought Verge; 11/8/2019
- How does Apple's "click to unsubscribe" feature in Mail work? 10/19/2019
- How to Format Emails on Mail for Mac the Easy Way OSXD; 3/21/2019
- If you can't get macOS Mail to work after upgrading to two-factor authentication, here's a way to fix it MW; 1/23/2019
Outlook, Hotmail
- Wikipedia: Microsoft Outlook
- Microsoft Outlook for Mac Now Free, with Strings Attached
no Office license or Microsoft 365 subscription required;
ad-supported and requires the “New Outlook” user interface; TB; 3/8/2023 - Your Microsoft Exchange Server Is a Security Liability
Endless vulnerabilities. Widespread hacking campaigns. Slow and technically tough patching.
It's time to say goodbye to on-premise Exchange; Wired; 10/21/2022 - Microsoft Office 365 vulnerability lets hackers sidestep email encryption 10/14/2022
- Microsoft adds support for custom '+' email addresses in Office 365 feature already present in Hotmail; Ars; 7/13/2020
- Hackers could read non-corporate Outlook.com, Hotmail for six months Ars; 4/15/2019
Reply All
- SNAFU: The Air Force Just Survived a Reply-All Apocalypse
'email storm' or a 'Replyallcalypse'; Giz; 9/3/2022 - How to Handle the Dreaded 'Reply All Moment' 'humailiation'; 1/17/2019
Spam
- Wikipedia: spam email
- HowStuffWorks: How Spam Works
- Gmail: Your address is similar but has more or fewer dots (.) or different capitalization
- Email Unsubscribe Services Don’t Really Work
privacy, pricey, ineffective.
Follow This (Free) Advice Instead.
1. Hit the Unsubscribe button or link; 2. Mark it as spam;
3. Set email rules and filters; 4. Create an email alias; NYT; 8/19/2024 - Comparing Blogtrottr, Feedrabbit, and Follow.it for Receiving RSS Feeds in Email TB; 8/22/2024
- Best Free Email Providers LH; 8/15/2024
- You’ve Got (Scam) Mail
is everyone being swindled all the time and just not talking about it? NYT; 9/22/2023 - Personalized AI-Written Spam May Soon Be Flooding Your Inbox Giz; 4/23/2023
- An Annotated Field Guide to Identifying Phish TB; 1/16/2023
- 10 of the Biggest Scams of 2022 LH; 12/287/2022
- No, You Haven't Won a Yeti Cooler From Dick's Sporting Goods
it circumvents some of Google's robust anti-spam tools for Gmail; Wired; 12/23/2022 - The Top 10 Scams of 2022 LH; 12/17/2022
- Ongoing phishing campaign can hack you even when you’re protected with MFA Ars; 7/12/2022
- How to Help a Friend Whose Email Has Been Hacked to Send Scams TB; 5/5/2022
- How to Spot the Seasonal Scams
IRS, charities, Ukraine; NYT; 3/30/2022 - Why Are Online Scams Called 'Phishing'? MF; 1/20/2022
- 4 Steps to Change Your Email Address AARP; 1/12/2022
- I maxed out the number of spammy addresses Gmail can block Ars; 11/20/2021
- Cut Down on Junk Mail with iCloud+'s Hide My Email TB; 10/21/2021
- Beware this new phishing attack that's after your passwords!
that (redirect) email link might not send you where you expect; PC; 9/1/2021 - How to protect yourself from phishing emails
Disable loading images; Don’t click on site links in email;
Hover over links before clicking; Look for warnings in email;
Check the padlock; Watch for blatant/moderate security warnings;
Use a password manager; MW; 6/25/2021 - The Young Fall for Scams More Than Seniors Do. Time for a Warning. NYT; 6/25/2021
- How to Tell the Difference Between a Spam Email and a Scam LH; 6/1/2021
- How to spot an online scam: 3 dead giveaways PC; 4/29/2021
- How to Avoid Phishing Emails and Scams
Always Think Twice Before Clicking;
Consider the Source;
Lock Your Accounts Down (PM, 2FA); Wired; 2/16/2021 - Who's Making All Those Scam Calls? NYT; 1/27/2021
- GoDaddy: Sorry We Promised Holiday Bonuses, That Was Just a Phishing Test Giz; 12/25/2020
- Avoid This Fake Zoom Meeting Invite Phishing Scam LH; 12/2/2020
- How to Spot the Latest Netflix Phishing Scam LH; 7/29/2020
- Environmentalists Targeted Exxon Mobil. Then Hackers Targeted Them. NYT; 6/9/2020
- Iran- and China-backed phishers try to hook the Trump and Biden campaigns Ars; 6/4/2020
- The problem with Apple Mail's junk filtering if your email provider changes how it marks messages as spam, they have to provide controls, too; MW; 5/25/2020
- GitLab runs phishing test against employees – and 20% handed over credentials 5/21/2020
- How to Avoid Spam—Using Disposable Contact Information the next time you sign up for a coupon code or retail promotion, use these apps to avoid spam text and email messages; Disposable Email Addresses: Sign in with Apple, 10 Minute Mail; Guerrilla Mail; Burner Mail; Firefox Private Relay; Disposable Cell Numbers: Burner; Wired; 5/16/2020
- List of all known Coronavirus (COVID-19) Scams 5/2020
- Don't Share a Screenshot of Your Stimulus Payment Online LH; 4/23/2020
- Deep dive on a “sextortion” spam email scheme that raked in 50.98 BTC, or ~$473K, over five months and, on some days, accounted for 20%+ of all observed spam; 4/22/2020
- So you received the Bitcoin 'sextortion vid' email -- here's what to do TNW; 4/20/2020
- How to Avoid the New 'NetSupport Manager' Phishing Scam LH; 3/3/2020
- How Can I Tell if This 'Sextortion' Email Is Legit? LH; 2/21/2020
- Don't Click on Links in Texts From 'Your Bank' enter link yourself, or use mobile app; LH; 2/17/2020
- How to Protect Yourself From Real Estate Scams NYT; 1/3/2020
- Researcher Releases Data on 100,000 Phishing Attempts This massive dataset can help teach and understand phishing better; MB; 12/16/2019
- Cybercrime Booms As Scammers Hack Human Nature To Steal Billions NPR; 11/18/2019
- The Language Of Cybercrime scripts, digitized voice; NPR; 11/18/2019
- Scammers favor malicious URLs over attachments in email phishing TNW; 11/8/2019
- PSA: Tell your parents to never wire you money before calling you first TNW; 10/30/2019
- How to stop iCloud calendar spam and junk mail steps in Apple Mail on Mac and iOS; AI; 8/26/2019
- 7 Ways to Protect Yourself from the Newest Phishing Scams on the Net
1. Be Wary of Emails Asking You To Click a Link to Confirm or Update Sensitive Details.
2. Don't Fall For Pop-Ups Asking You to Verify Account Information.
3. Even If An Email Looks Like It Was Sent By Someone You Know, Double Check the Sender's Address For Typos.
4. Be Careful When Logging Into Your Email.
5. Watch Out For "Cloned" Emails.
6. Don't Trust "Copyright Notices" on Social Media.
7. Enable Two-Factor Authentication; MF; 7/2/2019 - How to Keep Spam Out of Your Google Calendar LH; 6/24/2019
- Tricky Scam Plants Phishing Links in Your Google Calendar Wired; 6/17/2019
- Security researcher finds massive spam operation in an unsecured server now inactive, which sent 5M+ emails over 10 days that 160K+ people clicked through; discovered because spammer had forgotten to set a password; TC; 4/2/2019
- How Phishing Scams Are Evolving -- And How Not to Get Caught threatening language, misspellings, inaccuracies in the text, pressure to act quickly, attempts to cause panic, and requests to transfer money (even if you're expecting them); Giz; 3/20/2019
- Google Made a Quiz to See if You Can Identify Phishing Emails quiz; MB; 1/22/2019
Tracking
- Wikipedia: web bug object embedded in a web page or email, which unobtrusively (usually invisibly) allows checking that a user has accessed the content. Common uses are email tracking and page tagging for web analytics. Alternative names are web beacon, tracking bug, tag, or page tag. Common names for web bugs implemented through an embedded image include tracking pixel, pixel tag, 1x1 gif, and clear gif.
- How to delete an email without opening it on iPhone or Mac MW; 7/14/2022
- Apple Mail Now Blocks Email Tracking. Here's What It Means for You Wired; 5/7/2022
- DuckDuckGo launches a new Email Protection service that scans emails for trackers then forwards them from a free '@duck.com' address to a user's regular inbox \
cross-platform; Verge; 7/20/2021 - How to block tracking pixels in Apple Mail Mac blanket approach: don't load any Remote Content/Images; extensions? MW; 3/2/2021
- Spy pixels in emails have become endemic BBC; 2/17/2021
- How to Stop Emails From Tracking You LH; 7/8/2019
- How to See if Someone is Tracking Emails They Send You LH; 3/24/2019
Windows
- How to Set Up Mail on Your Windows 10 Computer LH; 5/15/2020