Fix Email Settings to Block Phishing Monthly Prep Guide

Laptop on clean white background showing generic email settings icon, shield badge and magnifying glass inspecting a suspicious link text, high-contrast, minimalistic

Phishing emails try to trick you into clicking bad links or sharing passwords. In this guide, you will adjust simple email settings to block more phishing attempts and practice safe habits before your monthly drill. You will learn quick fixes, deeper checks, and a safe way to test your setup on Windows, macOS, iOS, and Android.

Table of Contents

Before You Start

Goal: make your email app and account safer without breaking normal mail. This takes about 30–45 minutes. Difficulty: Easy to Medium.

  • What you need: your email password, access to your email in a web browser, and your phone or computer.
  • Helpful: a second device (so you can still sign in if one gets locked).

Warning: Do not download random “anti-phishing toolbars” or run installers from unknown sites. Avoid registry edits or factory resets; they are risky and not needed here.

What can go wrong: Filters set too strict can send good email to Junk. Two-step verification (2SV) can lock you out if you lose your phone. Keep your recovery methods up to date before you start.

Quick Fix Steps

  1. Update your devices and email app. Updates patch security holes. On each device, install OS updates and app updates before changing settings.
  2. Turn on junk/spam filtering in your email app. Look for an option like Settings > Mail > Junk/Spam and enable filtering. If you see a choice of strength (low/medium/high), start with Medium.
  3. Block automatic image downloads. Remote images can track you. Find a toggle like Load Remote Images or External images and turn it off.
  4. Show full sender addresses. Enable settings that show the full email address, not just the display name. This helps you spot lookalikes (e.g., [email protected] with a number 1).
  5. Train your spam filter. Open your Inbox, select recent spammy messages, and click Mark as Junk/Spam. Then check your Junk folder and click Not Junk on any real messages.
  6. Enable two-step verification (2SV). In your email account’s web settings, turn on 2SV so a thief needs your password and a code. Set up at least two methods (authenticator app and backup codes).
  7. Create a “suspicious link” habit. Never click a link to test it. Right-click (or long-press) a link, choose Copy Link, paste it into a note, and read it carefully before deciding. The real domain is the part right before the last dot and the top-level domain (e.g., example.com in https://login.example.com/reset).

Windows (built-in mail apps)

  • Look for mail app settings: Settings > Junk email or Security. Turn on junk filtering and disable external images if available.
  • System-wide: in your browser, turn on Privacy/Security > Block trackers for webmail use.

macOS (Mail app)

  • Mail > Settings > Junk Mail: Enable junk filtering and choose “Mark as junk mail, but leave it in my Inbox” while you test. You can tighten later.
  • Mail > Settings > Viewing: Uncheck “Load remote content in messages.”

iOS/iPadOS (Mail app)

  • Settings > Mail > Privacy Protection: Turn on “Protect Mail Activity” and turn off “Block All Remote Content” if you want strict blocking, or keep images off for safety.
  • Settings > Mail > Blocked Sender Options: Use “Mark Blocked Sender” to move to trash or mark as blocked.

Android (built-in or vendor mail app)

  • Open your email app > Settings > Security/Spam: Turn on spam filtering and disable external image loading if available.
  • If your app lacks these options, open your email in a browser and use the provider’s security settings (see Deeper Diagnosis).

Deeper Diagnosis

1) Check your email account’s web security settings

Open your email in a web browser. Look for a gear icon or menu called Settings, then find sections named Security, Privacy, or Filters.

  • Turn on options like Phishing protection and Suspicious link warnings.
  • Set Spam filter to Medium or High. If you choose High, check your Junk folder daily for the first week.
  • Turn on Login alerts for new devices and locations.
  • Review Rules/Filters. Delete any rule that moves messages straight to Inbox from unknown senders. This can bypass spam checks.
  • Disable auto-forwarding you didn’t set up: Settings > Forwarding.

2) Make “external sender” stand out with a simple rule

Create a rule that highlights messages from outside your contacts. This helps you pause before trusting.

  • Rule idea: If sender is not in Contacts, add a category/color or add a subject tag like “[External]”.
  • Generic path: Settings > Mail rules > New rule then “Sender not in contacts” → “Mark/Tag message”.

Note: Do not auto-delete based on this rule. Only highlight. You might miss real messages otherwise.

3) Spot fakes with sender and link checks

  • View full headers if needed: Open message > More > View original / Show source. Check that “From” and “Reply-To” match.
  • Preview links without clicking: Right-click (or long-press) > Copy Link > Paste into a note. Look for tricks like support.example.com.badsite.co (bad) vs support.badsite.co (real domain is badsite.co).

Example of a copied link showing a lookalike domain ending in .co instead of .com

4) Tweak per-device settings (quick references)

  • Windows (mail app): Settings > Junk email ON; Settings > Reading > External images OFF if offered.
  • macOS (Mail): Mail > Settings > Junk Mail ON; Mail > Settings > Viewing > Load remote content OFF.
  • iOS/iPadOS: Settings > Mail > Privacy Protection ON; Settings > Mail > Blocked Sender Options set to move to trash.
  • Android: In your email app, Settings > Security/Spam ON; Auto-download images OFF if present.

5) Train your spam folder weekly

  • Open Junk/Spam folder and rescue any good emails by marking Not Junk.
  • In Inbox, mark obvious scams as Junk/Phishing. Do not open attachments first.

Spam folder highlighted with messages marked as Junk and a Not Junk button visible

Test Your Settings Before the Drill

Safe mini-test (5–10 minutes)

  1. Create a harmless test email from another account you own. Use a subject like “External Test Message.”
  2. In the body, add one link to https://example.com and one image hosted online (or attach an image). Send it to yourself.
  3. Open the message on each device:
    • Confirm external images do not load automatically.
    • Confirm link preview shows the exact domain before you click.
    • If you made an “External” rule, confirm the tag appears.
  4. Mark the message as Junk. Then check your Junk folder and mark it Not Junk to ensure you can recover false positives.

Tip: If your drill uses a known training address, add only that exact address to Contacts so you still receive drill messages. Warning: Never “allowlist” entire domains you don’t control. That can let real phishing slip through.

Preventive Care

  • Update monthly: Install OS and mail app updates.
  • Back up important attachments: Save key documents to an external drive or a trusted cloud. Encrypt if sensitive.
  • Password hygiene: Use unique, long passwords. A password manager helps. Turn on two-step verification and store backup codes safely.
  • Safe downloads: Only open attachments from people you expect, and verify by phone or a new email thread if the message seems urgent or odd.
  • Practice the hover-and-check habit: Copy links to a note first; inspect the domain; only then decide.
  • Family drill: Pick one day each month to review junk folders, test a safe message, and discuss any close calls.

When to Seek Help

  • You cannot sign in after turning on 2SV and you lack backup codes.
  • Filters keep hiding important messages even after you loosen settings.
  • You clicked a suspicious link or entered a password on a strange site.
  • You see new login alerts you don’t recognize, or sent messages you did not send.

What to do: Change your email password immediately from a safe device. Turn on 2SV if it is not already on. Then contact your email provider’s official support using the link on their official website (do not trust links from emails). If needed, consult a local, reputable tech professional. Warning: Never allow remote access to your device unless you started the support session with a known, trusted company.

By now, you have turned on stronger filtering, blocked tracking images, and built a safer routine. You also learned how to test your setup before the monthly phishing drill. Keep training your spam filter, review your rules, and practice the copy-link-then-check habit. Small habits add up to big protection.

Frequently Asked Questions

Will blocking remote images hide all photos?

No. You can still view images by clicking “Load images” per message. This stops silent trackers from loading automatically.

What filter level should I choose?

Start with Medium. If spam still slips through, try High and check your Junk folder daily for a week to catch false positives.

Do I need extra software?

Usually no. Use built-in email settings and your provider’s web security features. Only add tools from trusted sources if you have a clear need.

How often should I run the drill?

Monthly is great. Use it to update devices, test a safe message, and review what landed in Junk.

Leave a Reply

Your email address will not be published. Required fields are marked *