---
title: Email Security Best Practices
description: Some helpful best practices for email security as provided by our partners and security awareness experts, KnowBe4.
image: https://blog.intinc.com/hubfs/Email-Security-Best-Practices-page-001-1.jpg
---

![](https://blog.intinc.com/hubfs/Email-Security-Best-Practices-page-001-1.jpg)

# Email Security Best Practices

 Published by [ Holden Metz ](https://blog.intinc.com/author/holden-metz) on  Sep 17, 2021 3:01:53 PM

We wanted to provide some helpful best practices for email security as provided by our partners and security awareness experts, KnowBe4.  

ALWAYS:

- Check the email 'From' field to validate the sender. This 'From' address may be spoofed.
- Check for so-called 'double-extended' scam attachments. A text file named 'safe.txt' is safe, but a file called 'safe.text.exe.' is not.
- Report all suspicious emails to your IT help desk.
- Note that [www.microsoft.com](http://www.microsoft.com) and [www.support.microsoft.software.com](http://www.support.microsoft.software.com) are two different domains (and only the first is real).

NEVER:

- Open any email attachments that end with: .exe., .scr, .bat, .com, or other executable files you do not recognize.
- "Unsubscribe." It is easier to delete the e-mail than to deal with the security risks.  
- Ever click embedded links in messages without hovering your mouse over them first to check the URL. 
- Respond or reply to spam in any way. Use the delete button.

Tags: [Cybersecurity](https://blog.intinc.com/tag/cybersecurity)

[Back to Blog](https://blog.intinc.com)

## Related Articles

<https://blog.intinc.com/why-your-business-needs-a-written-information-security-plan>

## [Why Your Business Needs a Written Information Security Plan](https://blog.intinc.com/why-your-business-needs-a-written-information-security-plan)

 Data breaches aren’t just a “big business problem.” Small and mid-sized organizations are...

[Read More ](https://blog.intinc.com/why-your-business-needs-a-written-information-security-plan)

<https://blog.intinc.com/how-to-manage-the-ongoing-problem-of-social-engineering>

## [How to Manage the Ongoing Problem of Social Engineering](https://blog.intinc.com/how-to-manage-the-ongoing-problem-of-social-engineering)

 Employees are the weak link in an organization’s network security. They are frequently exposed to...

[Read More ](https://blog.intinc.com/how-to-manage-the-ongoing-problem-of-social-engineering)

<https://blog.intinc.com/complex-password-guide>

## [Complex Password Guide](https://blog.intinc.com/complex-password-guide)

 We wanted to provide some helpful best practices for keeping your passwords strong and secure as...

[Read More ](https://blog.intinc.com/complex-password-guide)