Identify and Report Phishing Emails

更新时间:
复制 MD 格式

Phishing emails trick you into revealing passwords, clicking malicious links, or downloading malware. Learn to recognize and report them.

What is a phishing email?

Any email that requests your password or directs you to enter credentials on an external site is phishing. Never trust such messages. Report them as spam, delete them, and never click links or open attachments.

Common phishing tactics

1. Fake pretexts to steal credentials. Scammers copy official branding, forge trusted domains, or reference your contacts' details to appear legitimate, then trick you into submitting your password or making a payment.

Common pretexts include:

  • "We are upgrading the Mailbox Account Center."

  • "We are removing inactive accounts."

  • "Your order payment has been sent to your Alipay account. Log in to check."

  • "My bank account for remittances has changed. Please transfer funds to my new account."

  • "Mailbox password expiration notice"

  • "Alert: Insufficient storage space"

2. Urgent or alarming subject lines. Phishing emails use subject lines that create urgency, fear, or temptation to make you act without thinking.

Common examples include:

  • "Alert: Abnormal activity on your email account! Log in to check immediately."

  • "Security risk detected on your account" or "Verify your information now, or your account will be closed!!!!"

  • "Congratulations! You won an iPhone in our promotion. Submit your personal information to claim your prize."

  • "Notice to all departments"

image

3. Spoofed sender addresses and URLs. Scammers forge sender addresses and URLs that closely resemble legitimate ones. Always inspect them carefully.

A phishing email may appear to come from a trusted sender or link to a legitimate website. Inspect the sender's address or view the email source to spot the forgery. Scammers typically swap, add, or remove a single character to create a look-alike address.

For example:

  • A customer's real address is hellenliu@ali****.com, but the scammer sends from helleneliu@all****.com (note the extra "e" and "l").

  • The legitimate URL is http://taobao.com/****, but the phishing link is http://taoboa.com/***** (note the swapped letters).

  • "The administrator has changed your login permissions."

4. Malicious attachments. Scammers trick you into downloading attachments containing spyware or malware that can steal your password and give the attacker full control of your account.

Alibaba Mail scans attachments for viruses, but some threats may evade detection. Never download attachments from unknown or untrusted senders.

  • "I m p o r t a n t N o t i c e"

5. Generic greetings. Phishing emails often address you as "Dear Customer" or "Dear User" instead of your real name. A generic greeting strongly suggests the sender does not know you.

6. Broken images that link to credential-harvesting pages. The email contains a broken or unloaded image. Clicking it redirects you to a fake page designed to capture your credentials.

How to protect your account

  1. Report and delete any email that asks for your account credentials.

  2. To verify an email, type the company's URL directly into your browser. Never click links in the email.

  3. Use strong, complex passwords and change them regularly.

  4. Use a unique password for each online service. Never reuse passwords across services.

  5. Never save your credentials on shared or public computers, such as those in internet cafes or hotels.

  6. Be cautious before entering your email credentials on any third-party website.

  7. Sign out of all websites when you are done, even on your personal computer.

  8. Enable two-factor authentication (2FA) for your email login and use app-specific passwords for third-party clients. This blocks attackers even if your password is compromised.

  9. Technology alone cannot stop all phishing attacks. Provide security training during onboarding and at regular intervals, and run phishing simulations to help employees recognize and report threats.