What is Phishing and Why Should It Be Taken Seriously?
Phishing is one of the most common and dangerous methods of cyber attack in which an attacker, by impersonating a trusted entity, tricks the user into providing sensitive information such as passwords, bank card numbers, or login credentials. Unlike complex attacks that require high technical knowledge, phishing relies more on social engineering and human weakness; for this reason, millions of users worldwide fall victim to it every year.
In Iran, with the growth of online services, online shopping, and electronic banking, phishing attacks have increased dramatically. Attackers usually impersonate banks, web hosting providers, email companies, or even government organizations. The important point is that no reputable service provider — including ServerNet — will ever ask you for your password or confidential information via email or SMS. If you receive such a request, you can consider it a phishing attack with high confidence.
In this article, you will learn practically and step by step how to identify signs of phishing in email and domain, what tools to use, and what actions to take to prevent these attacks.
Signs of Phishing in Email; From Sender to Content
Phishing emails usually follow repetitive patterns that can be identified by paying close attention to details. In the following, we examine the most important signs.
Checking the Sender Address; The First Line of Defense
The first thing you should do is carefully check the sender's email address. Attackers often use addresses that closely resemble the original address but differ in details. For example:
support@servernet-cloud.com(fake address with an extra hyphen)support@servernet.co.ir(original address)admin@servernet-support.com(different domain)
For a thorough check, click on the sender's name and view the full email address. In services like Gmail, hover your mouse over the sender's name to display the actual address. In desktop clients like Outlook, you can also use the View Source or View Message Source option.
Common mistake: Many users only pay attention to the sender's display name. Remember that the display name can be easily forged and has no security value. Always check the full email address.
Checking the Email Domain; Where Attackers Make Mistakes
The next part is the email domain. If you receive an email from a reputable company, its domain should match the company's official domain. For example, if you receive an email from ServerNet, the domain should be servernet.co.ir, not anything else. Also pay attention to the domain extension; .co.ir is different from .ir or .com.
Also pay attention to strange domains like servernet.ir.verify-account.com. In this case, the main domain is verify-account.com and servernet.ir is just a subdomain created by the attacker. This is a common phishing trick.
Email Content and Tone; Fake Warnings and Urgency
Phishing emails typically use techniques to create urgency and fear to make you act without thinking. Common phrases include:
- "Your account will be blocked due to suspicious activity"
- "To avoid suspension, verify your information within 24 hours"
- "You have won a prize; click the link to claim it"
- "Unpaid invoice; please check the attached file"
The important point is that reputable companies never use these methods. If your account really has a problem, they will contact you through official methods such as SMS to your registered number or a phone call. Threatening emails with short deadlines are almost always phishing.
Also pay attention to spelling and grammatical errors. Official emails are usually fluent in language, but phishing emails often contain grammatical mistakes or machine translations.
Links and Attachments; The Most Dangerous Part of an Email
Before clicking on any link, hover your mouse over it (without clicking) to see the destination address at the bottom of the browser or next to the cursor. Compare the destination address with the official address of the site. If the address contains strange characters, random numbers, or unfamiliar domains, do not click on it under any circumstances.
Email attachments are also very dangerous. Executable files (.exe), scripts (.js), compressed files (.zip), and even Office documents with active macros can contain malware. If you are not expecting a file, do not open the attachment. Even if you received it from a familiar sender, first contact them through another method and confirm.
Identifying Phishing in Domain; Attackers' Tricks and Countermeasures
Phishing attacks are not limited to email. Attackers often create fake websites that resemble legitimate sites and direct users to them. Identifying these fake domains requires attention and the use of appropriate tools.
Similar Domains and Typosquatting
Typosquatting is a technique in which the attacker registers a domain similar to a well-known domain, with the difference that a letter is transposed, removed, or added. Common examples:
servernet.co.ir→servernet.co.ir(letter s instead of n)servernet.co.ir→servernet.ir(removal of co)servernet.co.ir→servernet.co.ir(letter i instead of e)
To check whether the domain you have been redirected to is real or not, pay attention to the browser address bar. If the address has a slight difference from what you expect, leave the site and type the address manually in the browser.
Checking SSL Certificate and HTTPS Protocol
The presence of a green padlock and the HTTPS protocol in the site address is a sign that the site is secure, but it is not sufficient on its own. Attackers can also obtain free SSL certificates. For a more detailed check, click on the green padlock and view the certificate information. Make sure the certificate is issued for the same domain you see in the address bar, not another domain.
You can also use online tools like sslshopper.com or sslchecker.com to check the validity of the certificate. These tools provide complete information about the certificate issuer, expiration date, and covered domains.
Using Domain Security Check Services
There are numerous online tools that can help you identify malicious domains. Some of the most well-known ones include:
urlscan.io— Full analysis of a URL's content and reporting suspicious behaviorsvirustotal.com— Checking URLs and files with multiple antivirus enginesphishtank.com— Database of domains reported as phishinggoogle.com/safebrowsing— Checking the security status of a URL in Google's database
Before entering sensitive information on any site, check its address in one of these tools. This only takes a few seconds but can prevent major disasters.
Why Does No Provider Ask for Your Password?
This is a key question — if you know the answer, you will be safe against most phishing attacks. No reputable company — whether a web hosting provider, a bank, or an email service — will ever ask you for your password, card number, or two-factor authentication code via email, SMS, or phone call. The reasons for this are completely technical and security-related:
- Security responsibility is on you: If your password is compromised, the responsibility is yours. Companies do not want to accept this responsibility.
- Passwords must remain confidential: Even support staff do not have access to your password. They can reset it, but they cannot view it.
- Requesting a password is a security violation: If a company asks for your password, it means their system is not properly designed.
Therefore, if you receive an email asking you to "verify" your password or "enter your login information to avoid being blocked," consider it a phishing attack without hesitation. Even if the email looks exactly like the company's official emails, it is still fake.
Preventive Measures and Best Security Practices
Prevention is always better than cure. By following a few simple habits, you can significantly reduce the risk of falling victim to phishing attacks.
Enabling Two-Factor Authentication (2FA)
Two-factor authentication is one of the most effective methods of protecting user accounts. Even if your password is compromised, the attacker cannot access the account without the second code. To enable 2FA on various services, applications like Google Authenticator or SMS services are usually used. It is recommended to enable this feature for all your important accounts.
Regularly Checking Domain Security Reports
If you own a domain, periodically review its security reports. Services like DNSSEC and SPF, DKIM, and DMARC help you prevent your domain from being spoofed. These protocols allow email recipients to verify that the email was actually sent from your domain, not from a fake one.
To check the status of these protocols, you can use online tools like mxtoolbox.com. If these records are not properly configured, attackers can send emails in the name of your domain and damage your credibility.
Education and Awareness; The Most Important Defense Tool
Phishing is a human attack, and the best defense against it is education and awareness. Teach yourself and your colleagues to always think before clicking. There is a simple rule: If an email invites you to take immediate action, pause and think. Attackers rely precisely on these fake urgencies.
It is also recommended to periodically participate in phishing simulation tests. Many organizations conduct these tests for their employees to measure their awareness level and identify weaknesses.
Summary and Final Action
Phishing attacks are a serious but preventable threat. By following the points below, you can protect yourself and your organization:
- Always check the full email address of the sender, not just the display name.
- Before clicking on any link, check the destination address with the mouse cursor.
- Never enter sensitive information on sites whose addresses you have not manually verified.
- Remember that no reputable provider asks for your password.
- Use domain security check tools like VirusTotal and PhishTank.
- Enable two-factor authentication for all important accounts.
If you receive a suspicious email, report it to the relevant company's security team and then delete it. In case of doubt, always contact the company through official channels (main website, support phone) and confirm the matter. ServerNet, as a web hosting service provider, always prioritizes the security of its users and recommends reporting any suspicious email to the official support address. Your awareness is the best shield against cyber attackers.
Comments 0
No comments yet — be the first!