I think the whole principle of "anyone who knows your email address / phone number can contact you" was already obsolete over 20 years ago. Access to my inbox and ringer should be by revocable invitation only.
I think the whole principle of "anyone who knows your email address / phone number can contact you" was already obsolete over 20 years ago. Access to my inbox and ringer should be by revocable invitation only.
Email campaigns from companies are a mess. Even the company I work for sends official emails out from addresses at numerous 3rd party domains each using different mail servers. They often go out with verbiage nearly identical to what I see in phishing emails. They've contained links that point to URL shorteners or some other random 3rd party site that we don't own with URLs full of unintelligible tracking info.
I deal with phishing issues almost every day. Most of the time phishing emails are pretty obvious, but I've had customers ask me if an email claiming to come from the company I work for was legitimate and even after looking over the message and the headers I couldn't give a clear answer. I've had several talks with marketing about it, and I've managed to catch a few horrific communications before they went out, but they aren't willing to stop sending from or linking to third parties.
Developer: Does anyone know why helpdesk@company.com is being flagged as a spam address? All of our customers are saying our support emails are ending up in their spam folder.
Marketing guy: Yeah does anyone know why our support and advertising emails are being marked as spam?
Developer: …never mind.
It still doesn't justify companymarketing.com and companyhelpdesk.com though.
Arguably, email addresses are (much) simpler to parse than postal addresses (including thing's like c/o, post boxes, etc.)
Both are equally easy to fake. The difference is sending fake bulk postal mail is much more expensive than email.
Detecting scams like this is a skill and some people - like elderly or disabled people - just aren't good at it. It doesn't help that some legit businesses are officially using gmail/hotmail/whatever addresses.
But this is what I hate most about Slack specifically and Electron in general. It’s so obviously a web app shoved into what kinda looks like a native window. But all the behavior is webpagey, except not in my browser, which I already know how to use.
Here’s a fun one:
Click in the conversation history panel. Use your “select all” shortcut. Despair.
In many cases, no. They simply see that it has Venmo (or whatever) in it and assume it must be legit.
I've tried to explain this exact thing a few times. Not even sure I managed to get them to understand that a big company wouldn't use Gmail, but rather their own domain.