It looks like a mail from the agriculture association, but it might as well be phishing


21 dec 2011 // web / do your best / transparency
If I buy something on, say, sales.com, the response mail should come from sales.com and all links within the mail should be to sales.com. Anything else looks as a phishing attempt, and it might as well be.

People who have been exposed to phishing or other scams on the Internet often wonder that the page they visited looked very professional and reliable. Because scammers and fraudsters are fully capable of creating a professional and credible appearance on their web pages. It is difficult to discern, difficult to understand, also because a lot of the ‘good’ pages do the same: they make use of alternative urls and external web services such as payment and surveys, where it is not clear that you are transfered to another web domain.
Similarly are companies, organizations and ... yes, almost everybody ... sending huge amounts of emails that are auto-generated on one of their servers or through one of the many mail service providers. It may be newsletters, receipts, instructions, etc., and all these mail have in common that they are confusingly similar to phishing mails. In the same way as emails apparently coming from Barclays or eBay actually may link to pages like www.barclays.­co.uk.­brccontrol.­taskstart.­nastyphishingscam.us

Half of the mail has non matching urls

A quick look at the news and service mails in the last two weeks shows that more than half of the mails are linking to web sites other sites than the sender. All of these may well be completely fine. And I have not experienced any irregularities. And some of them links are to widely used newsmail service providers.
The point is, however, there’s no chance that I’d be able to check if it is reliable, I am supposed to magically know. But how could I know, when senders never bother to told me, that I would get emails from other domains.
Here’s some examples:
version2.dk: ing.us2.list-manage.com
uni-c.dk: www.e-survey.dk
theoryandpractice.dk: theoryandpractice.ru
a2-type.co.uk: r20.rs6.net
houseind.com: houseindustries.createsend5.com
busymac.com: busymac.cmail1.com
enfocus.com: tools.emailgarage.com
Basically, there is no excuse, except that it is a little harder to make correspondence between the sender of newsletters and links within it. The good part of the story is that approximately half of the emails I get (the other half), seem to care about this issue.
Torben Wilhelmsen
Details of various importance on graphics, web and communication

twitter facebook email phone
Cookies on torbenwil.dk
We use two cookies on this web site: xierpa_sid is the session id that refers to the data with choices in forms and language. We put the width and and height of the browser window into the wilscreen cookie, so we can serve the optimum size of the graphics and styles. No cookie data is stored. You can avoid the cookies in your browser’s anonymity/private settings.

Statistics on torbenwil.dk
We collect anonymous data of clicked links within the domain in order to serve the right and most useful links to other pages. And we use Google Analytics to get statistics.

Blog posts


Blog categories

Public space (12) / Typography (9) / Design (9) / Web (8) / Mobile web (5) / Illustration (5) / Random (4) / Ipad (4) / Danish railways (4) / Advertising (4) / Music (3) / Do your best (3) / Berlin (3) / Automated layout (3) / Animation (3) / Web apps (2) / Transparency (2) / Responsive layout (2) / Mobilism (2) / Magazine (2) / Logo (2) / Don’t make me feel stupid (2) / Atypi (2) / Apps (2) /