Email security basics
Last updated: July 19, 2026
Email is the front door
Nearly every incident we respond to starts with an email: a fake invoice, a spoofed boss, a login page that is not what it claims to be. The filters we run catch most of it. This page covers what to do about the rest — the messages that reach a human.
Reporting phishing
- Use the Report Phishing button in your mail client — it sends us the message with the technical details intact.
- If you are not sure it is phishing, report it anyway. We would much rather check ten harmless emails than miss one bad one.
- Do not forward the suspicious email to coworkers to ask “is this real?” — that just spreads the bait.
- If you already clicked a link or entered a password, call us now at (931) 355-7256. No blame, ever. Minutes matter far more than embarrassment.
MFA prompts you did not request
If your phone shows a sign-in approval you did not trigger, someone likely has your password and is trying to get past the second lock. Tap Deny, do not approve it “to make it stop,” change that password from the password manager, and report it. Repeated prompts are a known attacker tactic called MFA fatigue — they are counting on you giving in. Denying and telling us is always the right move.
Attachment rules
- Expected attachment from a known sender: fine.
- Unexpected attachment, even from a known sender: verify by phone or chat first — their account may be compromised.
- Never enable macros or click “Enable Content” in a document because the document asks you to. Legitimate files do not need it.
- Be extra wary of ZIP files, password-protected attachments, and files pretending to be voicemails, faxes, or missed-delivery notices.
Links and login pages
Hover before you click and look at the real address. If an email links you to a login page, close it and go to the site the way you normally would — typed address or bookmark. Real urgency is rare; manufactured urgency (“your account closes in 24 hours”) is the oldest trick in the book.
Requests to move money or buy gift cards
Any emailed request to change bank details, pay an unexpected invoice, or buy gift cards gets verified by voice on a number you already have — not a number from the email. This one habit defeats the most expensive scam in small business.
What happens after you report
We check the message, pull it from other inboxes if it went to more than one person, block the sender and any lookalike domains, and check whether anyone interacted with it. You will get a short follow-up telling you what it was and whether anything else is needed from you.
The 10-second checklist
- Was I expecting this?
- Does the sender address actually match who it claims to be?
- Is it pushing urgency, secrecy, or money?
- Would I bet a paycheck this is real? If not — report it.