3 ms·
Your first point is definitely correct - their guide is confused at best. As to your second point, I agree in terms of 'best practices', but in terms of teachi
by verbify 8y ago
Your first point is definitely correct - their guide is confused at best.
As to your second point, I agree in terms of 'best practices', but in terms of teaching about phishing, the fact is, companies do use multiple domains (and some deliverability guides actively encourage different domains for marketing emails and transactional emails - companies should use subdomains for this, but not all are that savvy).
Given that companies are sending from multiple domains, I think the litmus test for phishing is:
"Is the email trying to get me to give me information? E.g. a login on the wrong site, sending card details or anything like that"
Your pdf reader should allow you to open a pdf without being compromised (just as your browser should allow you to click a dodgy link without being compromised). So I think that item should pass the litmus test (unlike the email reading one).