That reminds me of a recent situation.
As someone working in software development, we are required to take part in the security trainings, the usual "don't open things from people you don't know" and "verify that a link is 'known' even if you get something from a person you do know", yada yada. You know the drill.
Recently, I got an email from our Boss saying something about "Here is something that you need to click on so that you are being authorised to do this stuff". Here was my thought process:
- This is from the boss's Email. But this cannot be trusted since it can be faked
- This is about something we/our software can do. But I don't know why I have to do this, since this isn't really something I am part of or even know anything about
- It looks like a legit email
- I hovered over the link, which had some weird target location that I didn't know
So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: "Got an email that tells me that I should open this link, but I don't know this link. What should I do?". The response was simple: Mark as Phishing and delete the Mail, done.
2 hours later, I got a message on Teams from IT which said: "Well, apparently that mail you marked as phishing was actually from us (was legit)". Great. Mail is gone now, don't know where Outlook put it, and frankly, I don't care.
If you train your people to "question everything" and not open links they don't know where they are going, then don't use some idiotic "middle man" or referer links in your official emails either. Even better, announce things before sending something out. I don't know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.

