{"id":398,"date":"2025-10-22T22:22:41","date_gmt":"2025-10-22T22:22:41","guid":{"rendered":"https:\/\/blog.asambe.ai\/index.php\/2025\/10\/22\/fix-email-settings-to-block-phishing-monthly-prep-guide\/"},"modified":"2025-10-22T22:22:43","modified_gmt":"2025-10-22T22:22:43","slug":"fix-email-settings-to-block-phishing-monthly-prep-guide","status":"publish","type":"post","link":"https:\/\/blog.asambe.ai\/index.php\/2025\/10\/22\/fix-email-settings-to-block-phishing-monthly-prep-guide\/","title":{"rendered":"Fix Email Settings to Block Phishing Monthly Prep Guide"},"content":{"rendered":"<p>Phishing emails try to trick you into clicking bad links or sharing passwords. In this guide, you will adjust simple email settings to block more phishing attempts and practice safe habits before your monthly drill. You will learn quick fixes, deeper checks, and a safe way to test your setup on Windows, macOS, iOS, and Android.<\/p>\n<h2 id=\"table-of-contents\">Table of Contents<\/h2>\n<ul>\n<li><a href=\"#table-of-contents\">Table of Contents<\/a><\/li>\n<li><a href=\"#before-you-start\">Before You Start<\/a><\/li>\n<li><a href=\"#quick-fix-steps\">Quick Fix Steps<\/a><\/li>\n<li><a href=\"#deeper-diagnosis\">Deeper Diagnosis<\/a><\/li>\n<li><a href=\"#test-your-settings\">Test Your Settings Before the Drill<\/a><\/li>\n<li><a href=\"#preventive-care\">Preventive Care<\/a><\/li>\n<li><a href=\"#when-to-seek-help\">When to Seek Help<\/a><\/li>\n<li><a href=\"#frequently-asked-questions\">Frequently Asked Questions<\/a><\/li>\n<\/ul>\n<h2 id=\"before-you-start\">Before You Start<\/h2>\n<p>Goal: make your email app and account safer without breaking normal mail. This takes about 30\u201345 minutes. Difficulty: Easy to Medium.<\/p>\n<ul>\n<li>What you need: your email password, access to your email in a web browser, and your phone or computer.<\/li>\n<li>Helpful: a second device (so you can still sign in if one gets locked).<\/li>\n<\/ul>\n<p><strong>Warning:<\/strong> Do not download random \u201canti-phishing toolbars\u201d or run installers from unknown sites. Avoid registry edits or factory resets; they are risky and not needed here.<\/p>\n<p><strong>What can go wrong:<\/strong> Filters set too strict can send good email to Junk. Two-step verification (2SV) can lock you out if you lose your phone. Keep your recovery methods up to date before you start.<\/p>\n<h2 id=\"quick-fix-steps\">Quick Fix Steps<\/h2>\n<ol>\n<li><strong>Update your devices and email app.<\/strong> Updates patch security holes. On each device, install OS updates and app updates before changing settings.<\/li>\n<li><strong>Turn on junk\/spam filtering in your email app.<\/strong> Look for an option like <code>Settings &gt; Mail &gt; Junk\/Spam<\/code> and enable filtering. If you see a choice of strength (low\/medium\/high), start with Medium.<\/li>\n<li><strong>Block automatic image downloads.<\/strong> Remote images can track you. Find a toggle like <code>Load Remote Images<\/code> or <code>External images<\/code> and turn it off.<\/li>\n<li><strong>Show full sender addresses.<\/strong> Enable settings that show the full email address, not just the display name. This helps you spot lookalikes (e.g., <em>support@paypa1.com<\/em> with a number 1).<\/li>\n<li><strong>Train your spam filter.<\/strong> Open your Inbox, select recent spammy messages, and click <em>Mark as Junk\/Spam<\/em>. Then check your Junk folder and click <em>Not Junk<\/em> on any real messages.<\/li>\n<li><strong>Enable two-step verification (2SV).<\/strong> In your email account\u2019s web settings, turn on 2SV so a thief needs your password and a code. Set up at least two methods (authenticator app and backup codes).<\/li>\n<li><strong>Create a \u201csuspicious link\u201d habit.<\/strong> Never click a link to test it. Right-click (or long-press) a link, choose <em>Copy Link<\/em>, paste it into a note, and read it carefully before deciding. The real domain is the part right before the last dot and the top-level domain (e.g., <em>example.com<\/em> in <code>https:\/\/login.example.com\/reset<\/code>).<\/li>\n<\/ol>\n<h3>Windows (built-in mail apps)<\/h3>\n<ul>\n<li>Look for mail app settings: <code>Settings &gt; Junk email<\/code> or <code>Security<\/code>. Turn on junk filtering and disable external images if available.<\/li>\n<li>System-wide: in your browser, turn on <code>Privacy\/Security &gt; Block trackers<\/code> for webmail use.<\/li>\n<\/ul>\n<h3>macOS (Mail app)<\/h3>\n<ul>\n<li>Mail &gt; Settings &gt; <code>Junk Mail<\/code>: Enable junk filtering and choose \u201cMark as junk mail, but leave it in my Inbox\u201d while you test. You can tighten later.<\/li>\n<li>Mail &gt; Settings &gt; <code>Viewing<\/code>: Uncheck \u201cLoad remote content in messages.\u201d<\/li>\n<\/ul>\n<h3>iOS\/iPadOS (Mail app)<\/h3>\n<ul>\n<li>Settings &gt; Mail &gt; <code>Privacy Protection<\/code>: Turn on \u201cProtect Mail Activity\u201d and turn off \u201cBlock All Remote Content\u201d if you want strict blocking, or keep images off for safety.<\/li>\n<li>Settings &gt; Mail &gt; <code>Blocked Sender Options<\/code>: Use \u201cMark Blocked Sender\u201d to move to trash or mark as blocked.<\/li>\n<\/ul>\n<h3>Android (built-in or vendor mail app)<\/h3>\n<ul>\n<li>Open your email app &gt; <code>Settings &gt; Security\/Spam<\/code>: Turn on spam filtering and disable external image loading if available.<\/li>\n<li>If your app lacks these options, open your email in a browser and use the provider\u2019s security settings (see Deeper Diagnosis).<\/li>\n<\/ul>\n<h2 id=\"deeper-diagnosis\">Deeper Diagnosis<\/h2>\n<h3>1) Check your email account\u2019s web security settings<\/h3>\n<p>Open your email in a web browser. Look for a gear icon or menu called <code>Settings<\/code>, then find sections named <code>Security<\/code>, <code>Privacy<\/code>, or <code>Filters<\/code>.<\/p>\n<ul>\n<li>Turn on options like <strong>Phishing protection<\/strong> and <strong>Suspicious link warnings<\/strong>.<\/li>\n<li>Set Spam filter to Medium or High. If you choose High, check your Junk folder daily for the first week.<\/li>\n<li>Turn on <strong>Login alerts<\/strong> for new devices and locations.<\/li>\n<li>Review <code>Rules\/Filters<\/code>. Delete any rule that moves messages straight to Inbox from unknown senders. This can bypass spam checks.<\/li>\n<li>Disable auto-forwarding you didn\u2019t set up: <code>Settings &gt; Forwarding<\/code>.<\/li>\n<\/ul>\n<h3>2) Make \u201cexternal sender\u201d stand out with a simple rule<\/h3>\n<p>Create a rule that highlights messages from outside your contacts. This helps you pause before trusting.<\/p>\n<ul>\n<li>Rule idea: If sender is <em>not<\/em> in Contacts, add a category\/color or add a subject tag like \u201c[External]\u201d.<\/li>\n<li>Generic path: <code>Settings &gt; Mail rules &gt; New rule<\/code> then \u201cSender not in contacts\u201d &rarr; \u201cMark\/Tag message\u201d.<\/li>\n<\/ul>\n<p><strong>Note:<\/strong> Do not auto-delete based on this rule. Only highlight. You might miss real messages otherwise.<\/p>\n<h3>3) Spot fakes with sender and link checks<\/h3>\n<ul>\n<li>View full headers if needed: <code>Open message &gt; More &gt; View original \/ Show source<\/code>. Check that \u201cFrom\u201d and \u201cReply-To\u201d match.<\/li>\n<li>Preview links without clicking: Right-click (or long-press) &gt; Copy Link &gt; Paste into a note. Look for tricks like <code>support.example.com.badsite.co<\/code> (bad) vs <code>support.badsite.co<\/code> (real domain is <em>badsite.co<\/em>).<\/li>\n<\/ul>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/example.com\/phishing-link-preview.png?ssl=1\" alt=\"Example of a copied link showing a lookalike domain ending in .co instead of .com\"><\/p>\n<h3>4) Tweak per-device settings (quick references)<\/h3>\n<ul>\n<li>Windows (mail app): <code>Settings &gt; Junk email<\/code> ON; <code>Settings &gt; Reading &gt; External images<\/code> OFF if offered.<\/li>\n<li>macOS (Mail): <code>Mail &gt; Settings &gt; Junk Mail<\/code> ON; <code>Mail &gt; Settings &gt; Viewing &gt; Load remote content<\/code> OFF.<\/li>\n<li>iOS\/iPadOS: <code>Settings &gt; Mail &gt; Privacy Protection<\/code> ON; <code>Settings &gt; Mail &gt; Blocked Sender Options<\/code> set to move to trash.<\/li>\n<li>Android: In your email app, <code>Settings &gt; Security\/Spam<\/code> ON; <code>Auto-download images<\/code> OFF if present.<\/li>\n<\/ul>\n<h3>5) Train your spam folder weekly<\/h3>\n<ul>\n<li>Open Junk\/Spam folder and rescue any good emails by marking <em>Not Junk<\/em>.<\/li>\n<li>In Inbox, mark obvious scams as <em>Junk\/Phishing<\/em>. Do not open attachments first.<\/li>\n<\/ul>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/example.com\/spam-folder.png?ssl=1\" alt=\"Spam folder highlighted with messages marked as Junk and a Not Junk button visible\"><\/p>\n<h2 id=\"test-your-settings\">Test Your Settings Before the Drill<\/h2>\n<h3>Safe mini-test (5\u201310 minutes)<\/h3>\n<ol>\n<li>Create a harmless test email from another account you own. Use a subject like \u201cExternal Test Message.\u201d<\/li>\n<li>In the body, add one link to <code>https:\/\/example.com<\/code> and one image hosted online (or attach an image). Send it to yourself.<\/li>\n<li>Open the message on each device:\n<ul>\n<li>Confirm external images do not load automatically.<\/li>\n<li>Confirm link preview shows the exact domain before you click.<\/li>\n<li>If you made an \u201cExternal\u201d rule, confirm the tag appears.<\/li>\n<\/ul>\n<\/li>\n<li>Mark the message as Junk. Then check your Junk folder and mark it Not Junk to ensure you can recover false positives.<\/li>\n<\/ol>\n<p><strong>Tip:<\/strong> If your drill uses a known training address, add only that exact address to Contacts so you still receive drill messages. <strong>Warning:<\/strong> Never \u201callowlist\u201d entire domains you don\u2019t control. That can let real phishing slip through.<\/p>\n<h2 id=\"preventive-care\">Preventive Care<\/h2>\n<ul>\n<li><strong>Update monthly:<\/strong> Install OS and mail app updates.<\/li>\n<li><strong>Back up important attachments:<\/strong> Save key documents to an external drive or a trusted cloud. Encrypt if sensitive.<\/li>\n<li><strong>Password hygiene:<\/strong> Use unique, long passwords. A password manager helps. Turn on two-step verification and store backup codes safely.<\/li>\n<li><strong>Safe downloads:<\/strong> Only open attachments from people you expect, and verify by phone or a new email thread if the message seems urgent or odd.<\/li>\n<li><strong>Practice the hover-and-check habit:<\/strong> Copy links to a note first; inspect the domain; only then decide.<\/li>\n<li><strong>Family drill:<\/strong> Pick one day each month to review junk folders, test a safe message, and discuss any close calls.<\/li>\n<\/ul>\n<h2 id=\"when-to-seek-help\">When to Seek Help<\/h2>\n<ul>\n<li>You cannot sign in after turning on 2SV and you lack backup codes.<\/li>\n<li>Filters keep hiding important messages even after you loosen settings.<\/li>\n<li>You clicked a suspicious link or entered a password on a strange site.<\/li>\n<li>You see new login alerts you don\u2019t recognize, or sent messages you did not send.<\/li>\n<\/ul>\n<p><strong>What to do:<\/strong> Change your email password immediately from a safe device. Turn on 2SV if it is not already on. Then contact your email provider\u2019s official support using the link on their official website (do not trust links from emails). If needed, consult a local, reputable tech professional. <strong>Warning:<\/strong> Never allow remote access to your device unless you started the support session with a known, trusted company.<\/p>\n<p>By now, you have turned on stronger filtering, blocked tracking images, and built a safer routine. You also learned how to test your setup before the monthly phishing drill. Keep training your spam filter, review your rules, and practice the copy-link-then-check habit. Small habits add up to big protection.<\/p>\n<h2 id=\"frequently-asked-questions\">Frequently Asked Questions<\/h2>\n<h3>Will blocking remote images hide all photos?<\/h3>\n<p>No. You can still view images by clicking \u201cLoad images\u201d per message. This stops silent trackers from loading automatically.<\/p>\n<h3>What filter level should I choose?<\/h3>\n<p>Start with Medium. If spam still slips through, try High and check your Junk folder daily for a week to catch false positives.<\/p>\n<h3>Do I need extra software?<\/h3>\n<p>Usually no. Use built-in email settings and your provider\u2019s web security features. Only add tools from trusted sources if you have a clear need.<\/p>\n<h3>How often should I run the drill?<\/h3>\n<p>Monthly is great. Use it to update devices, test a safe message, and review what landed in Junk.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Adjust email settings to block phishing before your monthly drill. Step-by-step, safe instructions for Windows, macOS, iOS, and Android. Update, test, and stay secure.<\/p>\n","protected":false},"author":1,"featured_media":397,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[9],"tags":[],"class_list":["post-398","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-docs"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blog.asambe.ai\/wp-content\/uploads\/2025\/10\/2025-10-22-22-22-33-data.png?fit=1024%2C1024&ssl=1","_links":{"self":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/comments?post=398"}],"version-history":[{"count":1,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/398\/revisions"}],"predecessor-version":[{"id":399,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/398\/revisions\/399"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/media\/397"}],"wp:attachment":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/media?parent=398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/categories?post=398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/tags?post=398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}