Week 03 · lesson

Read the Message Before You Trust the Message

Suspicious email is a reasoning problem before it is a clicking problem.

A message that says URGENT is not automatically malicious. A message with a familiar logo is not automatically legitimate. One clue changes probability; it rarely proves identity by itself.

Use evidence categories

Inspect a message through several independent questions:

  1. Sender evidence — Does the displayed sender and domain fit the organization that supposedly sent it?
  2. Context evidence — Was this message expected? Does the request fit the relationship?
  3. Language evidence — Does it use unusual urgency, threats, secrecy, or pressure?
  4. Link/attachment evidence — Is there a reason this workflow needs a link or attachment at all?
  5. Requested action — Is the message asking for credentials, money, private information, or an unusual change?
  6. Independent verification — Can the claim be checked through a known school site, saved contact, or separate trusted channel?

Do not open suspicious links or attachments for this lesson. Use the supplied fictional examples and visible evidence only.

Worked analysis

Fictional message:

From: School Support <support@school-help.example>
Subject: URGENT: Account expires today

Your mailbox will be disabled in 30 minutes.
Confirm your password immediately at the link below.

The evidence table might look like:

ObservationFact or interpretation?Why it matters
message requests a passwordfactlegitimate support should not need a password by email
domain is school-help.examplefactmust be compared with known official domain
“30 minutes” creates pressurefactpressure can reduce careful checking
therefore sender is a criminalunsupported claimevidence does not establish the person's identity

A defensible conclusion is narrower:

The message should not be trusted or acted on without independent verification because it requests a password, uses an unverified domain, and creates artificial urgency.

That conclusion is strong without pretending we know who sent it.

Analyze three fictional messages

For each teacher-supplied or course-safe message, complete a Message Trust Evidence Table:

MessageObservable evidenceSafe next stepWhat remains unknown?
A
B
C

A safe next step might be opening the school's known portal manually, contacting the sender through a saved/official channel, or reporting the message according to school procedure.

Failure mode: “bad grammar means phishing”

Real organizations make typos. Attackers can write polished prose. Grammar can be one clue, but it is weak evidence of identity.

The stronger habit is verification through an independent path.

Exit claim

Choose one analyzed message and write a three-sentence judgment:

  1. what you directly observed;
  2. what action you would take;
  3. what you still cannot prove.

Do not include a live malicious URL in the submission. The point is to reason safely, not to collect dangerous examples.