
We had this, and I created the same rule, but they have since switched to AI generated phishing emails that use information about you (your manager etc) to make a fairly convincing email. If someone gets a lot of email from outside sources, I can totally see them clicking on a link if they’re in a hurry.
The main things that raise my suspicion are:
- telling me it’s urgent
- telling me there will be dire consequences if I fail to comply
- asking me to log in (with a direct link)
- it’s from an external source
- it’s not related to my job (eg, asking me to sign off on a PO)
- telling me to download a file
- including an attachment
I usually just err on the side of reporting it. I’ve only had one false positive so far.

Yep lol. They have a second system that rewrites all links in emails to go through a scanner, but as a side effect that obfuscates them as well.