XClose

Information Services Division

Home
Menu

Deal with spoofed messages

Find out how to identify a spoofed message.

keep your email secure
Email spoofing is when the headers of an email have been forged so that the email appears to originate from someone or somewhere else entirely. The sender may be trying to trick you into divulging information, opening an infected attachment or clicking on a link to a compromised website. So, how can you identify if the email is legitimate?

 

Check the email header

 

Unfortunately it is very easy to manually change the ‘To’ and ‘From’ fields to give fake information, so it can be easy to catch people out. You should always be aware of this when reading your email, even emails that have come from a trusted sender.

For example, the message below looks like it has come from UCL IT Services desk.

Example of an IT Services spoofed message

But look closely at the address next to the display name 'IT Services'.

  • The From email address does not match the display name.
  • Even though 'UCL' is in the From email address, it is not the legitimate IT Services UCL email address. 
  • You should also hover over the 'click here' link. Does it go to a UCL address (https:///www.ucl.ac.uk/....) or elsewhere?

Check the Return-Path

Another option is to check where the Return-Path goes. The Return-Path identifies where the message originated.

Note: it is possible to forge the Return-Path, but it is not done as often.

How to check the Return-Path

  1. Open the message in a new window by double-clicking on it.
  2. In the new window, click on File and then Properties.
  3. In the Internet headers section of the Properties window, scroll down until you see Return-Path. Look at the address. Is it legitimate?

If you're not sure, do not reply to the message. It is best to contact the supposed sender by phone, Teams or using a new outgoing email message using their real email address to check if the message really came from them.

What to do if you have clicked on a link in a suspicious email

If you have responded to a spoofed email and would like advice please contact ISG via: https://myservices.ucl.ac.uk/.