Spam Wipe field note
Anti Spam Techniques
Anti-spam techniques reduce unwanted messages and help you handle deceptive ones safely. No filter catches everything. A manageable inbox depends on…

Anti-spam techniques reduce unwanted messages and help you handle deceptive ones safely. No filter catches everything. A manageable inbox depends on filtering routine junk, checking unusual requests outside the message, and protecting the account if something slips through.
Separate unwanted mail from suspected fraud. A newsletter you remember joining may call for an unsubscribe. A message asking for a password, verification code, or payment details calls for independent verification. Both can appear in the same inbox, but they need different responses.
Make your inbox filter useful
Check the spam or junk controls in your email service before adding personal rules. When unwanted mail reaches the inbox, use report spam or mark as junk. If expected mail lands in junk, correct the classification. Review that folder when a reply or account notice has not arrived; filters can make mistakes in either direction. The FTC’s guidance on getting less spam covers filtering, reporting and checking for legitimate mail caught by mistake.
Use a personal rule for a narrow, recurring need, such as moving a recognised newsletter into a folder. Check what it matches before letting it delete mail automatically. A broad rule can hide a real message along with the junk. Revisit rules when a sender changes address or your priorities change. If a rule acts on words in a subject line, test it against recent legitimate mail: ordinary account notices may use the same words as spam.
Blocking helps when the same address repeatedly contacts you. It does not stop a sender who switches addresses, and it may be separate from reporting. Read the action shown by your mail service so you know whether you blocked an address, reported a message, moved it, or did more than one of those things.
Share your address with some care. Use it where you need a reply, receipt, or account recovery, and think before posting it on a public page. For lower-priority sign-ups, a separate address or an alias can help you identify where unwanted mail is arriving and keep important correspondence easier to find. An alias is useful only if you can still receive messages needed for that account. Do not abandon an address while it remains a recovery route for services you use.
Choose between unsubscribe and report
If you recognise a newsletter you joined and no longer want, use a trustworthy unsubscribe control or change preferences through the organisation’s site. This reduces mail you no longer read. Check that the message fits your existing relationship before using a link inside it. If you are unsure, visit the site through a saved address instead.
For an unfamiliar promotion or a deceptive message, report it through the mail service rather than testing its links. Do not reply merely to tell the sender to stop; that does not establish who sent it. Use the phishing option when a message appears designed to obtain information or access through deception. If it claims an account needs urgent attention, open that account through a known app or address and check there.
Check suspicious requests independently
Filtering reduces clutter but cannot decide whether a request is safe. Pause when a message unexpectedly asks you to sign in, share a code, open an attachment, change payment details, or send sensitive information. A familiar display name, logo, or polished wording does not prove who sent it. Examine the full sender address and the action requested, but do not treat either as conclusive.
Verify the request outside the message. Use an app, bookmark, or contact route you already trust. Do not call a number supplied in the suspicious message to verify that same message. If it appears to come from a colleague or known contact, ask through an established channel, especially when the request is unusual. Even a genuine account can be misused.
Do not wait for obvious mistakes in spelling or design. Careful wording can still carry a deceptive request, and a genuine message can be urgent. Slow down when the requested action would give someone money, data, or access. If you cannot verify it, leave the link or attachment unopened and report the message through the channel available to you.
If you clicked a link but did not enter anything, close the page and avoid further interaction. If you supplied a password, change it using your usual route to the account; if you supplied a code, payment information, or other sensitive details, contact the relevant service through a known channel. Tell a workplace contact promptly if the message involved a work account or device. Record what you did and when so the person handling the report can judge the next steps without guessing.
Protect the account behind the inbox
Email often receives password resets, sign-in notices, and private correspondence. Give the account a unique password and enable multifactor authentication where available. Keep recovery details current and under your control. If you suspect someone accessed the account, review unfamiliar sign-ins, forwarding settings, and connected applications as well as the password.
Keep your browser, operating system, and security software updated. Avoid opening an unexpected attachment just to see what it contains. If you entered a password on a suspicious page, change it through the real service and change it anywhere else you reused it. If you downloaded or ran something suspicious on a work device, use your organisation’s reporting process promptly and describe what happened.
Workplaces should make reporting straightforward. People need to know where to send a suspicious message and how to disclose an accidental click. The layered phishing guidance brings together filtering, reporting, account protection, device protection, and incident response. Training helps people notice questionable requests, but it cannot make every deceptive message obvious.
Check the sending domain if you manage email
A team that manages its own email domain can make it harder for others to send mail falsely appearing to come from that domain. Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC) are domain authentication mechanisms described in NIST’s Trustworthy Email guidance. They need accurate configuration for each service authorised to send mail on the organisation’s behalf.
Inventory those senders before tightening a domain policy. Include employee mail and services that send receipts, notices, or newsletters. Review authentication results and reports with whoever runs the mail system, then check that legitimate messages still arrive. An incomplete sender list can disrupt delivery; publishing a record alone does not prove that the configuration works.
Keep the scope of authentication clear. The DMARC specification concerns domain authentication, not whether a message’s request is honest. A message can pass technical checks and still ask for something fraudulent. Independently verify unusual payments, access changes, and requests for sensitive information, even when the message appears to come from an authenticated domain.
Keep a simple routine
Confirm filtering is active, report clear examples of junk, and correct legitimate mail caught in the junk folder. Unsubscribe from recognised mail you no longer want. Review rules that hide or delete messages. Secure the email account with a unique password and an available second factor.
When a message demands action, ask whether you expected the request, how you can verify it through a separate route, and what would happen if you complied. If those answers remain unclear, leave its links and attachments alone. Use the mail service’s reporting control or your workplace’s established channel.
