VOL. 1 • ISSUE NO. 5 DIXIELAND CONSULTING — PENSACOLA, FL 10¢

THE PATRIOT KID

“The Email That Wasn't From Your Bank”
★ THE EMAIL SECURITY ISSUE ★ IT WISDOM — WITH HUMOR
PANEL 1 — TUESDAY, 4:47 PM
😱📧💳
THE BANK LOCKED OUR ACCOUNT!
THEY SENT AN EMAIL!
I HAVE TO VERIFY OUR
LOGIN IN 30 MINUTES
OR THEY CLOSE IT!!
PANEL 2 — THE PATRIOT KID ARRIVES
🥷📧
THE PATRIOT KID ARRIVES
HOLD ON, CITIZEN.
WHO ACTUALLY
SENT IT?
"...support@secure-firstbank-verify.com"
PANEL 3 — READING THE HEADERS
🔍🎣
Message Analysis:
Shows as: First Bank
Real sender: firstbank-verify.com
Domain age: 3 days
SPF check: FAIL
DMARC: none
Link goes to: a fake login page
PANEL 4 — THE HARD TRUTH
💡⚠
URGENCY IS
THE WEAPON.
Your bank never asks you to
“verify” your login by email link.
The countdown exists so you
panic and click before you think.
Real threats don't have
a 30-minute timer.
PANEL 5 — THE PATRIOT KID'S FIX
⚡📧⚡
BEFORE YOU CLICK:
✓ Stop — urgency is the tell
✓ Check the real sender domain
✓ Never click; go to the site yourself
✓ Call the number on your card
And lock down your OWN domain
with SPF, DKIM & DMARC.
PANEL 6 — PHISH FOREMAN FOILED!
🎉📧✅
I DIDN'T CLICK!
I CALLED THE BANK —
THE ACCOUNT WAS FINE!
I REPORTED THE EMAIL!
🥷
Good. Now let's set up
DMARC so the fakes
using YOUR name bounce.
★ PATRIOT KID TECH CORNER — THE REAL STORY ON PHISHING ★

🎣 How Phishing Actually Works

Phishing doesn't beat your firewall — it beats you. An email impersonates someone you trust (your bank, Microsoft, a vendor, even your own boss) and manufactures urgency so you act before you think.

The tricks are almost always the same:

  • A lookalike domain: firstbank-verify.com instead of the real one
  • A countdown or threat — “account will be closed”
  • A link to a login page that looks identical to the real one
  • A display name that hides the real sender address

Over 90% of business breaches start with a phishing email. It's cheap, it scales, and it only has to work once.

🔒 SPF, DKIM & DMARC: Protect Your Own Name

Attackers don't just phish you — they impersonate your business to phish your customers. Three DNS records stop that:

  • SPF — lists who's allowed to send mail as your domain
  • DKIM — cryptographically signs your mail so it can't be forged
  • DMARC — tells inboxes to reject anything that fails, and reports who's trying

Without them, anyone can send email that looks like it came from you — and your real mail is far more likely to land in spam. With them, spoofed messages bounce.

⏳ The 5-Second Test

Before you click anything in an email that creates urgency:

  • Hover the link — does the address match the real company?
  • Check the sender's actual domain, not the display name
  • When in doubt, don't reply — open a new tab and type the address yourself
  • Verify by phone using a number you already have

Want your domain checked and locked down? Chuck will run your SPF, DKIM & DMARC and fix what's missing.

★ NEXT ISSUE — “WHERE ARE THE BACKUPS?!” READ ISSUE #6 →

Got an IT problem worthy of a comic? Tell Chuck about it.

An unhandled error has occurred. Reload