Week 03 · lesson
Read the Message Before You Trust the Message
Suspicious email is a reasoning problem before it is a clicking problem.
A message that says URGENT is not automatically malicious. A message with a familiar logo is not automatically legitimate. One clue changes probability; it rarely proves identity by itself.
Use evidence categories
Inspect a message through several independent questions:
- Sender evidence — Does the displayed sender and domain fit the organization that supposedly sent it?
- Context evidence — Was this message expected? Does the request fit the relationship?
- Language evidence — Does it use unusual urgency, threats, secrecy, or pressure?
- Link/attachment evidence — Is there a reason this workflow needs a link or attachment at all?
- Requested action — Is the message asking for credentials, money, private information, or an unusual change?
- Independent verification — Can the claim be checked through a known school site, saved contact, or separate trusted channel?
Do not open suspicious links or attachments for this lesson. Use the supplied fictional examples and visible evidence only.
Worked analysis
Fictional message:
From: School Support <support@school-help.example>
Subject: URGENT: Account expires today
Your mailbox will be disabled in 30 minutes.
Confirm your password immediately at the link below.
The evidence table might look like:
| Observation | Fact or interpretation? | Why it matters |
|---|---|---|
| message requests a password | fact | legitimate support should not need a password by email |
domain is school-help.example | fact | must be compared with known official domain |
| “30 minutes” creates pressure | fact | pressure can reduce careful checking |
| therefore sender is a criminal | unsupported claim | evidence does not establish the person's identity |
A defensible conclusion is narrower:
The message should not be trusted or acted on without independent verification because it requests a password, uses an unverified domain, and creates artificial urgency.
That conclusion is strong without pretending we know who sent it.
Analyze three fictional messages
For each teacher-supplied or course-safe message, complete a Message Trust Evidence Table:
| Message | Observable evidence | Safe next step | What remains unknown? |
|---|---|---|---|
| A | |||
| B | |||
| C |
A safe next step might be opening the school's known portal manually, contacting the sender through a saved/official channel, or reporting the message according to school procedure.
Failure mode: “bad grammar means phishing”
Real organizations make typos. Attackers can write polished prose. Grammar can be one clue, but it is weak evidence of identity.
The stronger habit is verification through an independent path.
Exit claim
Choose one analyzed message and write a three-sentence judgment:
- what you directly observed;
- what action you would take;
- what you still cannot prove.
Do not include a live malicious URL in the submission. The point is to reason safely, not to collect dangerous examples.