Skip to content
Utah Community Learning

When the email looks internal: spoofed addresses and off tone

About 20 minutes

When the email looks internal: spoofed addresses and off tone

Two techniques are now behind us: the package text and hovering over links. This lesson addresses the sneakier one. The email that looks like it came from inside your own house.

By "internal" I mean it looks like it is from your work, your ward, your school, your kid's soccer team. Not some stranger. Somebody you already trust. That is what makes this one harder to catch than the delivery texts.

Why this one gets past people

Most of us operate a mental filter that says "I know this sender, so I can relax." Scammers know you have that filter too. So instead of pretending to be a stranger with a prize, they pretend to be your boss, your bishop, your school's front office. The name looks right. The logo looks right. And your guard drops.

Tiffany actually caught one of these before I did. It was a fake ward donation email, spoofed to look internal, and I was checking the address while she had already clocked that the tone was wrong. It did not sound like anyone who actually writes those emails. Fair is fair, she beat me to it, and I credit her in class every time.

What to actually check

The hands-on part. Do not just read the display name. Tap or click on the sender's name and examine the full email address underneath it.

  • On a phone, tap the sender's name at the top of the message.
  • On a computer, hover over the name, or click the little arrow to expand the header.
  • Compare it letter by letter to a real email you already have from that person or organization.

You are looking for small stuff. An extra letter. A number swapped in for a letter. A ".net" where it should be ".org." A completely different domain hiding behind a familiar display name. Scammers can put any name they want on the "From" line. What they cannot fake as easily is the actual address behind it.

The tone check, which matters just as much

This is the part people skip, and it is the part Tiffany nailed. Ask yourself whether this actually sounds like the person.

Does your bishop usually email you about money with this much urgency? Does your boss usually skip the normal greeting and go straight to "I need you to do this now"? Is there a request to keep it quiet, or to not mention it to anyone else in the office? That secrecy element is a huge tell. Real internal requests do not usually ask you to keep them from your coworkers.

Slow down and read it as though you were reading someone's handwriting, not just their words. If something feels off but you cannot name it, that feeling is worth trusting.

Don't let anyone onto your computer to check it

This is where I bring up Kylie. She got a call from "Microsoft" saying she had a virus, and she let them onto her computer before she thought better of it. We spent an afternoon wiping and resetting that machine. I do not say this to embarrass her. I say it because it is exactly what happens to normal, careful people when someone sounds official and urgent at the same time.

The spoofed internal email version of that trap looks like: "IT needs remote access to fix your account" or "click here to verify your login before it's suspended." Don't click. Don't let anyone remote into your machine because an email told you to. If your actual IT department needs in, they will tell you in person or by phone, using a number you already have, not one from the email.

If you're not sure, verify outside the email

This is the practical habit to build. Do not reply to the suspicious email to ask if it is real, because you are just talking to the scammer again. Instead:

  • Call the person directly, using a number you already had saved, not one in the message.
  • Walk down the hall or text them separately if you can.
  • Check with someone else who would know, like another leader in your ward or a coworker.

My position on this, stated plainly: almost every scam runs on urgency. The spoofed internal email works because it layers trust on top of urgency, which is a nastier combination. Slow down anyway. Verify outside the message. Being five minutes late to respond has never hurt anybody. Clicking the wrong thing has hurt plenty of people.

Before next time

Pull up one email from your ward, your work, or your kid's school, and actually examine the full sender address, not just the name. Simply get in the habit of checking. That is the whole assignment.

~kenneth

When the email looks internal: spoofed addresses and off tone — Online Safety and Scam Prevention · Utah Community Learning