this post was submitted on 22 Jul 2026
659 points (99.5% liked)

Dull Men's Club

4593 readers
324 users here now

An unofficial chapter of the popular Dull Men's Club.

https://dullmensclub.com/

1. Relevant commentary on your own dull life. Posts should be about your own dull, lived experience. This is our most important rule. Direct questions, random thoughts, comment baiting, advice seeking, many uses of "discuss" rarely comply with this rule.

2. Original, Fresh, Meaningful Content.

3. Avoid repetitive topics.

4. This is not a search engine
Use a search engine, a tradesperson, Reddit, friends, a specialist Facebook group, apps, Wikipedia, an AI chat, a reverse image search etc. to answer simple questions or identify objects. Also see rule 1, “comment baiting”.

There are a number of content specific communities with subject matter experts who can help you.

Some other communities to consider before posting:

5. Keep it dull. If it puts us to sleep, it’s on the right track. Examples of likely not dull: jokes, gross stuff (including toes), politics, religion, royalty, illness or injury, killing things for fun, or promotional content. Feel free to post these elsewhere.

6. No hate speech, sexism, or bullying No sexism, hate speech, degrading or excessively foul language, or other harmful language. No othering or dehumanizing of anyone or negativity towards any gender identity.

7. Proofread before posting. Use good grammar and punctuation. Avoid useless phrases. Some examples: - starting a post with "So" - starting a post with pointless phrases, like "I hope this is allowed" or “this is my first post” Only share good quality, cropped images. Do not share screenshots of images; share the original image.

.

founded 2 years ago
MODERATORS
 

Can’t make the wrong people look bad.

top 50 comments
sorted by: hot top controversial new old
[–] daddycool@lemmy.world 159 points 1 month ago
[–] KickMeElmo@sopuli.xyz 130 points 1 month ago (2 children)

Report the email for phishing attempt.

[–] zr0@lemmy.dbzer0.com 96 points 1 month ago (1 children)

Uhm. It is the phishing attempt. If you click that link it will tell you, you failed the test. And looking at the comments, a lot of people would fail this test.

[–] ColeSloth@discuss.tchncs.de 19 points 1 month ago (2 children)

...... That's why you would report the email as a phishing attempt.

load more comments (2 replies)
[–] EastofEdson@piefed.ca 121 points 1 month ago (8 children)

My company: Don't click on suspicious links.

Also my company: It's employee survey time, click this link to complete the survey http://surveywhale.com/haidn39fk49cmc93mx

I mark them as phishing attempts every damn time.

[–] jj4211@lemmy.world 59 points 1 month ago* (last edited 1 month ago) (8 children)

Heh, an employee at my work got an email saying his anti-malware was failing to update, and to run http://10.3.4.2/xbejdjr.exe and that they need to click allow when the browser warns them that it is rejected, then right click, run as administrator, and they need to click allow in two other places to let it run.

So he reported as phishing, then IT contacted his manager saying he was failing to help IT run a required update, it was evidently totally legit, but just the most scammy looking way they imagined.

[–] Alcoholicorn@mander.xyz 26 points 1 month ago (10 children)

That is so fucking sketchy, I'd have to talk to the IT guy myself or get on a video call to make sure their email or the group chat or whatever wasn't compromised.

load more comments (10 replies)
load more comments (7 replies)
load more comments (7 replies)
[–] hperrin@lemmy.ca 93 points 1 month ago (2 children)

100% success rate if you mark every email as a phishing attempt.

load more comments (2 replies)
[–] isleepinahammock@lemmy.blahaj.zone 74 points 1 month ago (2 children)

I take great pleasure in flagging the training emails from my company's IT contractor as phishing emails. After all, they're unexpected emails with big link that I simply must quickly click on. That sounds like phishing to me!

load more comments (1 replies)
[–] TIEPilot@lemmy.world 65 points 1 month ago (1 children)

I used to report just about any email I got from HR/IT/Executive Management that had a link as spam... I got a lot of interesting replies from IT over the years.

Time to update your benefits SPAM/PHISHING!

Sign up for the holiday "pot luck" SPAM/PHISHING!

Tells us how you feel in thie "anonymous" survey... you guessed it SPAM/PHISHING!

load more comments (1 replies)
[–] stoy@lemmy.zip 52 points 1 month ago (1 children)

IT guy here....

DAMN, that was brilliant!

[–] Acid_Burn@lemmy.dbzer0.com 9 points 1 month ago

Same. I saved it to add to our KnowBe4 templates

[–] swicano@programming.dev 46 points 1 month ago

Seems legit. Click the link

[–] CMDR_Horn@lemmy.world 44 points 1 month ago (2 children)

Ive often suggested to our security team that they send one out spoofing the monthly mandatory training vid

[–] wizardbeard@lemmy.dbzer0.com 60 points 1 month ago (5 children)

The issue is that people's egos get bruised when they fall for it, and they'll very quickly get management on their side that certain ones are unfair, as if phishers give a shit about fair.

What I really love is how my workplace uses some man in the middle crap to replace every link in every email with a new one redirected through our cyber security link scanning product, so now there's no way to check the actual link before you click it since they're all just like garbagesec.com/4a12c89e7f now.

[–] sketchyenchantment@sh.itjust.works 24 points 1 month ago (3 children)

Our IT solution to that was to MITM all the links except for the phishing tests. So anyone savvy enough to realize that always passes.

[–] CMDR_Horn@lemmy.world 16 points 1 month ago

Ours is exactly the same as this lol. The joke is we are an IT firm so everyone except from sales and hr easily detetct it.

[–] Ziglin@lemmy.world 14 points 1 month ago

But real phishing emails will have the same treatment as normal emails making them harder to detect. Sounds like a really bad system that probably doesn't offer any advantages over a pihole.

load more comments (1 replies)
[–] runner_g@piefed.blahaj.zone 10 points 1 month ago

In my experience, its usually upper management that fails the phishing attempts.

load more comments (3 replies)
[–] Bane_Killgrind@lemmy.dbzer0.com 22 points 1 month ago (1 children)

PFF I don't click on any training emails unless my manager is asking about it in person.

If it's not important enough for them to follow up on, it's not important.

load more comments (1 replies)
[–] VitoRobles@lemmy.today 40 points 1 month ago

You can always forward it back to IT saying it's a suspicious link, according to this blog link you found. The blog link... Your own phishing link.

Two can play this game.

[–] Blackmist@feddit.uk 37 points 1 month ago (2 children)

I got a mandatory phishing awareness course that we were signed up to by corporate, and I deleted it because it looked scammy as all fuck.

Don't whine at people for not completing your course on phishing, when you sign them up to courses using scammy looking names without telling us first.

I'm not sure who these courses were even for. I was born in the scams. Moulded by them. I didn't see a genuine banking email until I was already a man. I remember my dad forwarding pyramid schemes to his friends on paper.

[–] Burninator05@lemmy.world 11 points 1 month ago

My org has us do the standard phishing training and then sends out completely legit links that ring all the alarm bells. Lots of survey links coming from whatever random domains they found to host it. Links to official applications that ask for to many permissions and are shady as fuck. Its surprising we don't get got more often.

load more comments (1 replies)
[–] AeonFelis@lemmy.world 31 points 1 month ago (1 children)
load more comments (1 replies)
[–] _lilith@lemmy.world 31 points 1 month ago (4 children)

Fun fact, those fishing emails usually share header information unique to the phishing email test service.

load more comments (4 replies)
[–] acchariya@lemmy.world 23 points 1 month ago

The best defence against phishing I have found is to just utterly ignore my email inbox at work.

You missed our recent phishing email, try to report it next time

No, I was so cautious I avoided my whole inbox because it might contain suspicious messages.

[–] BigBoyShuanzee@aussie.zone 20 points 1 month ago* (last edited 1 month ago) (2 children)

I already know the way to get me to click a phishing link is to send me 5 emails from the same company all 100% legit but have the unsubscribe link be the phishing link.

I would fall for that because I'm unsubscribing from companies emails all the time.

Of course now I've admitted this I'll be avoiding the unsubscribe link for a while too.

load more comments (2 replies)
[–] brax@sh.itjust.works 20 points 1 month ago (2 children)

If IT did the phishing tests nobody would stand a chance lol

[–] zalgotext@sh.itjust.works 19 points 1 month ago (2 children)

I'd always pass because I never look at any of my emails. Checkmate, IT department

load more comments (2 replies)
load more comments (1 replies)
[–] Fribbtastic@lemmy.world 19 points 1 month ago (2 children)

That reminds me of a recent situation.

As someone working in software development, we are required to take part in the security trainings, the usual "don't open things from people you don't know" and "verify that a link is 'known' even if you get something from a person you do know", yada yada. You know the drill.

Recently, I got an email from our Boss saying something about "Here is something that you need to click on so that you are being authorised to do this stuff". Here was my thought process:

  1. This is from the boss's Email. But this cannot be trusted since it can be faked
  2. This is about something we/our software can do. But I don't know why I have to do this, since this isn't really something I am part of or even know anything about
  3. It looks like a legit email
  4. I hovered over the link, which had some weird target location that I didn't know

So, as a good boy, I opened a new Support ticket on IT with a screenshot of the link and said: "Got an email that tells me that I should open this link, but I don't know this link. What should I do?". The response was simple: Mark as Phishing and delete the Mail, done.

2 hours later, I got a message on Teams from IT which said: "Well, apparently that mail you marked as phishing was actually from us (was legit)". Great. Mail is gone now, don't know where Outlook put it, and frankly, I don't care.

If you train your people to "question everything" and not open links they don't know where they are going, then don't use some idiotic "middle man" or referer links in your official emails either. Even better, announce things before sending something out. I don't know how many emails I have gotten over the years where I would question the content and ignore it only for it to be something more important that nobody felt the need to announce first that something like this is coming our way.

load more comments (2 replies)
[–] Botzo@lemmy.world 19 points 1 month ago (1 children)

I have a rule that searches the email headers for the test emails and just deletes them.

[–] emmanuel_car@fedia.io 15 points 1 month ago (1 children)

Depending on what they’re testing for, you may still be a fail in the statistics. For example in my company we have a button to report phishing attempts, if you fail to report the email you fail.

[–] Botzo@lemmy.world 13 points 1 month ago

Of course.

Easy enough to dump them in a folder and spend a few minutes a week playing cyber security theater.

[–] iconic_admin@lemmy.world 18 points 1 month ago

Don’t fall for it.

[–] rockSlayer@lemmy.blahaj.zone 17 points 1 month ago

Link is sus, phishing

[–] NABDad@lemmy.world 13 points 1 month ago

I have gotten texts from our Cybersecurity warning me not to open links in texts...and they include a link to a web page for more information.

[–] MeowerMisfit817@lemmy.world 13 points 1 month ago (3 children)

I'm out of the loop, what happened here?

[–] stingpie@lemmy.world 40 points 1 month ago (1 children)

This email is the phishing attempt test itself. It says you are exempt from the phishing testing, but then tells you to put your account information on a random website.

load more comments (1 replies)
[–] Mic_Check_One_Two@reddthat.com 11 points 1 month ago

The email is a phishing test, and clicking the link automatically enrolls you in mandatory rudimentary cybersecurity awareness training.

[–] chortle_tortle@mander.xyz 10 points 1 month ago

I think the implication is that this is the fishing attempt they sent this to the higher ups / IT staff and got bites.

[–] unemployedclaquer@sopuli.xyz 11 points 1 month ago (1 children)

Yeah y'all get it, I get it, my relatives don't get it

[–] cobysev@lemmy.world 19 points 1 month ago* (last edited 4 weeks ago)

Tell your relatives that this IS the phishing test email. If you click that link, you're gonna get busted by your IT department.

Never click links (or for that matter, ads) in emails. Always verify the sender first. Not the display name, the actual email address that it was sent from.

If you must go to a link, best to find out what website they're sending you to (hover over the link for the URL), then type in the main website manually from a web browser.

For example, if you get an email from US Bank (assuming you use them), type "usbank.com" (minus quotation marks) in your browser, then login to your personal bank account on their official website. Don't trust a link to a bank's website without typing it yourself. Don't just copy/paste the full URL from your email either.

Some links, even to legitimate websites, can have tracking data in the URL that gives a lot of info about you, where in the world you're browsing from, what web browser you're using, what website, app, or program you clicked the link from, etc. Basically, remove the "&" and everything after it in URLs before loading them in your browser.

These are just a few basics to protect yourself from malicious links. Basically, don't click any link you don't recognize and verify with people who send you links. And even then, protect yourself from idiots who forward links without doing their own spot checks. Even your best friends can send you viruses and malware. Heck, that's how a lot of it spreads across the Internet.

And especially don't trust your own IT department when they ask you to click links in their emails.

Sincerely,

~A former IT guy

[–] Taleya@aussie.zone 9 points 1 month ago

I just delete all emails, i've never felt more productive

load more comments
view more: next ›