Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Expand
titleClick here to see an outline of this page.

Table of Contents

Phishing Quiz

Can you spot when you're being phished? Take this quiz from Google and Jigsaw.

Sample Malicious Email

Here is an example of a malicious email message, and eight points that show you this is fake:

...

  1. The Sender name does not match other emails from this sender.
  2. The email address does not match the Sender name.
  3. In this example, the email does not open in the same way other emails from this sender usually do (that is, with your name).
  4. Why is the domain name in parentheses?
  5. Your Drew email does not have a quota.
  6. Typographical errors are often an indicator of spam or phishing emails. With the spread of AI-generated or proofread messages, typos are less prevalent.
  7. The URL does not match typical Drew URL and is not secure (http - you should always look for https)
  8. The signature does not match standard emails from this department. 

...

  • Does the name in the subject match the From: address? What about the signature?
  • What does the To: address say?
  • Are you listed in To: or in Bcc: (you should be in To: if the message is specifically addressed to you).
  • As with most spam, check for extra typos - but recognize that AI generated messages are less likely to have typos now.

Viewing a file that is shared with you should not prompt you to approve additional access. Always pay close attention to WHO is asking for WHAT access, and consider carefully whether they need it or not (this is true of the apps you install on your phone, as well!).

Do not download an attachment you are not expecting. 

Another Phishing Strategy: Fake Invitations

If you receive a surprise email invitation from someone you know (well, or maybe someone you haven't spoken to in ages), take a beat before clicking any links.

A new phishing technique is using compromised (or spoofed) email accounts to send what appear to be invitations from places like Punchbowl, Paperless Post, or Evite. 

The New York Times published an article about this on April 23, 2026. You can read it here (after you hover over the link to make sure you know where it is pointing you!).

If you've held on to a real invitation from one of these places, you can compare the layout and the sender address. As with the example above, that sender address is significant. 

If you receive one of these phishing attempts, please flag the item as phishing so that your email service provider can learn to recognize it.

Current Spam or Phishing Strategies to Be Aware Of

  • Free Musical instruments
  • Notice of Electronic Filing (check the sender and names carefully before trusting any attachments)
  • Account termination notices
  • Employee status/review notifications
  • Part-time job offers

Steps to Take After Receiving Spam or Phishing Emails

...

Phishing is more targeted and more malicious. It is an attempt to garner personal information - often usernames and passwords - that can be sold and/or used to gain access to other information, systems, and/or money.

...

Was your account

...

  1. Google offers a multifactor option at https://myaccount.google.com/security
  2. Drew offers Duo Security at drew.edu/duo

...

compromised?

Excerpt Include
Google Account Security Checklist - Was your account compromised?
Google Account Security Checklist - Was your account compromised?
nopaneltrue

What about spam texts?

Visit this page at the Federal Trade Commission website, https://consumer.ftc.gov/articles/how-recognize-and-report-spam-text-messages, for information about recognizing and reporting spam text messages.

Additional Examples, Resources and Information


Reviewed 4/29/26