Email Safety: The Human Firewall

It’s time that we had “The Talk” again. No, not that one—the “Stranger Danger” talk.

In our hyper-connected world, interacting with the internet is unavoidable. Unfortunately, there are people out there with bad intentions masquerading as your friends. While your email provider automatically shuffles most malicious emails into “Spam hell” before you ever see them, some inevitably slip through the net.

Building a “Human Firewall” is about simple, practical defence that goes beyond panic and hysteria. The more you learn, the stronger your wall becomes.

Phase 1: Spotting the Scam

Inspect the Sender’s Actual Address

  • The Trap: The “Sender Name” displayed can be spoofed to look like a friend, a company, or an official.
  • The Defence: Always check the actual Sender Email Address. In most desktop apps, right-click the name; on mobile devices, tap the name at the top of the email.
  • Example: If the display name says “President” but the underlying email address is xyz@zyx.com instead of president@u3atauranga.org.nz, be very suspicious!

Look for the Five Red Flags Scam

Emails usually rely on psychological pressure. Watch out for:

  • Urgency: Creating a false crisis so you don’t have time to think.
  • Secrecy: Insisting you “don’t tell anyone” about a deal too good to miss.
  • No Internal Knowledge: They may know your name, but they lack specific, personal details about you.
  • Overfamiliarity: Getting a bit too chummy, too quickly.
  • Excuses: Claiming they are too busy, too ill, or unable to talk directly right now.

Investigate Links:

Before Clicking * On a PC: “Hover” your mouse cursor over the link without clicking. The real destination URL will appear at the bottom or top of your screen. (You can practice this safety measure on a trusted site like u3atauranga.org.nz) .

  • On a Phone or Tablet: Press and hold your finger down on the link to reveal a secure preview of the destination URL.
  • Warning: Links don’t always look like underlined text—images and buttons are often links too.
    If a “Harvey Norman Super Deals” graphic links to xpw.somewhereelse.blah, do not click it!

Phase 2: Taking Action & Verifying

  • Pause and Reflect: This is your most important asset. Take a breath and think. There is rarely an email request that cannot wait a few minutes while you verify its legitimacy.
  • Verify via a Separate Channel: If you need to check the information, look up the organization’s contact details independently. For instance, your bank’s phone number is located on the back of your debit/credit card or your official statements. Never call a phone number provided inside a suspicious email.
  • Do Not Forward Danger: Avoid forwarding suspicious emails to friends or family to ask “Is this real?” Sending them further only helps scammers flourish and risks infecting others.

Phase 3: What to Do If You’ve Fallen for a Scam

  • Stop Immediately: Cease all interaction with the email, sender, or linked websites right away.
  • Report It: Use the “Report Phishing” or “Report Spam” button in your email application to alert your provider.
  • Tell Someone: Reach out to trusted family, friends, or colleagues. They can offer an objective perspective and help you take the next security steps.
  • Change Passwords Immediately: If you entered a password, change it right away on the real website—and anywhere else you use that same password.
  • Call Your Bank: If you provided financial details or credit card numbers, call your bank’s fraud department immediately so they can freeze the cards.
  • Contact the Authorities: Report the incident to Netsafe (New Zealand’s independent online safety organization) at netsafe.org.nz for official support and advice.

Stay Safe! Your awareness is the ultimate firewall.