{"id":1431,"date":"2026-05-22T11:42:09","date_gmt":"2026-05-22T11:42:09","guid":{"rendered":"https:\/\/fappelo.net\/news\/?p=1431"},"modified":"2026-05-22T11:46:38","modified_gmt":"2026-05-22T11:46:38","slug":"is-it-really-from-the-ceo-the-art-of-inspecting-email-sender-addresses","status":"publish","type":"post","link":"https:\/\/fappelo.net\/news\/2026\/05\/22\/is-it-really-from-the-ceo-the-art-of-inspecting-email-sender-addresses\/","title":{"rendered":"Is It Really From The CEO? The Art Of Inspecting Email Sender Addresses"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Phishing is one of the most common types of cyber attacks targeting businesses worldwide as recent data indicates that cybercriminals send over <\/span><a href=\"http:\/\/www.afcea.org\/signal-media\/cyber-edge\/escalating-war-against-email-based-espionage-and-fraud\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">3.4 billion phishing emails per day<\/span><\/a><span style=\"font-weight: 400;\">. Many employees are fooled into clicking or interacting with these messages as the emails appear as though they came from higher ups or reliable sources. This results in massive financial losses for companies, and the FBI estimates that scams using business emails have cost over $43 billion since 2016.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When it comes to this type of scam, no business is safe. Whether it&#8217;s a mega conglomerate or a small enterprise, any venture or organization in any part of the globe can become a victim of a phishing attack. If you&#8217;re running a business, protect your brand and customers <\/span><a href=\"http:\/\/fappelo.net\/managed-cyber-security-services-for-businesses\/\"><span style=\"font-weight: 400;\">by implementing cybersecurity measures<\/span><\/a><span style=\"font-weight: 400;\">, and train non-technical staff to properly inspect email sender addresses. Learning to recognize threats can be an effective strategy to prevent data breaches and financial losses, and maintain business reputation and customer trust.\u00a0<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Why is Sender Inspection Training Essential?<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Companies frequently become victims of phishing scams through impersonation wherein attackers pose as CEOs, vendors, clients, or trusted brands to steal funds or sensitive data. Even tech giants aren&#8217;t immune to this as both <\/span><a href=\"http:\/\/www.cnbc.com\/2019\/03\/27\/phishing-email-scam-stole-100-million-from-facebook-and-google.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Google and Facebook became victims<\/span><\/a><span style=\"font-weight: 400;\"> of a phishing attack between 2013 to 2015. According to reports, a Lithuanian scammer named Evaldas Rimasauskas fabricated a business that posed as another company, Qantas Computers, which actually does business with both Facebook and Google. Rimasauskas and his co-conspirators sent emails with fake invoices to employees of both companies, which led to Facebook losing $99 million while Google lost $23 million. The scam was discovered later, and authorities were able to recover nearly $50 million of the stolen money.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Training employees to inspect email sender information is a must since it enables staff to act as a first line of defense against advanced cyber attacks like Business Email Compromise (BEC). Once cybercriminals gain initial access through phishing, <\/span><span style=\"font-weight: 400;\">the BEC attack chain<\/span><span style=\"font-weight: 400;\"> begins to play out as they access emails and contact lists, delete responses or move them to other folders, and hide alerts to orchestrate financial crimes. Training can reduce the number of employees falling for such scams, and it also teaches them to stop and analyze instead of responding quickly to fabricated requests. Proper training can also reduce the likelihood of employees opening infected attachments, clicking malicious links, or sharing sensitive information.\u00a0<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Key Training Concepts for Training\u00a0<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Your staff doesn&#8217;t need to be well-versed in IT to defend your company against cybercriminals. When it comes to guarding against phishing, all it takes are some simple, practical steps that they can follow whenever they&#8217;re checking or responding to emails. First, teach employees that the display name can be easily faked. They may think that they&#8217;re responding to James Williams CEO, but clicking or hovering over the name will reveal the sender&#8217;s real email address. They should also be taught to be on the lookout for lookalike domains since scammers can create website names that look similar to the real ones. Look for misspellings, such as blue@cornpany instead of blue@company, or substitutions like using zero instead of the letter O. Staff should also be trained to inspect the domain extension since there&#8217;s a clear difference between an email address that uses \u2018.net\u2019 from one that uses \u2018.com.\u2019\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Next, train employees on suspicious requests. Sometimes, an attacker may use a legitimate looking email address, but they&#8217;ll require people to send replies or information to a different email. They should also be wary if they get an unexpected, urgent request from management, executives, or IT to send credentials or transfer money, even if the name and email address seem correct. If an email seems slightly suspicious, instruct staff to verify by calling the sender or sending an SMS message before taking action.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Also, train employees to slow down and not be pressured by urgent or persistent requests. If they get an email urging them to send credentials or money quickly, this should be considered as a potential red flag, and the email should be reported right away to IT staff. After training, run regular phishing simulations to see if staff have learned all the key concepts, and follow up with immediate, short training sessions if any of them clicked on a fake link.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Train your staff to be your company&#8217;s first line of defense against phishing attacks. Instruct them on the proper ways to inspect email sender addresses, and build a culture of cybersecurity <\/span><span style=\"font-weight: 400;\">awareness to protect<\/span><span style=\"font-weight: 400;\"> your business.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing is one of the most common types of cyber attacks targeting businesses worldwide as recent data indicates that cybercriminals send over 3.4 billion phishing emails per day. Many employees are fooled into clicking or interacting with these messages as the emails appear as though they came from higher ups or reliable sources. This results &#8230; <a title=\"Is It Really From The CEO? The Art Of Inspecting Email Sender Addresses\" class=\"read-more\" href=\"https:\/\/fappelo.net\/news\/2026\/05\/22\/is-it-really-from-the-ceo-the-art-of-inspecting-email-sender-addresses\/\" aria-label=\"Read more about Is It Really From The CEO? The Art Of Inspecting Email Sender Addresses\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":1432,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-1431","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business"],"_links":{"self":[{"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/posts\/1431","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/comments?post=1431"}],"version-history":[{"count":1,"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/posts\/1431\/revisions"}],"predecessor-version":[{"id":1433,"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/posts\/1431\/revisions\/1433"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/media\/1432"}],"wp:attachment":[{"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/media?parent=1431"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/categories?post=1431"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fappelo.net\/news\/wp-json\/wp\/v2\/tags?post=1431"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}