Some rules of conduct for dealing with e-mails:
- Mail address: Unfortunately, sender addresses are very easy to forge. You should be suspicious of any e-mail if its sender does not belong to the institution from which it claims to originate. It should be obvious that the email address of ÖAW colleagues will never end in “.be”.
- Mail content: How credible is the content? Poor German/English, illogical argumentation, unusual requests are always an indication that something is wrong. If in doubt, ask - but never use contact data from the e-mail, instead use an alternative source (telephone book, own e-mail contacts, web).
- Web Links: If the suspicious email contains a link, never open it before verifying its authenticity – just move your mouse over it to view the URL: If the URL points to a domain that does not match the alleged sender, it is a very strong sign of wrongdoing. Please note that attackers sometimes try to make the URL look almost like the original domain of the supposed sender.
- SSL certificate: If the URL starts with https:// it is an encrypted connection. Never give sensitive data to any website that is not using HTTPS. Modern web browsers will indicate proper encryption with a lock icon.
- Do not follow URLs (links) directly in an e-mail.
- Do not let yourself be pressured by an e-mail and be tempted to act quickly without thinking.
- In the case of requests and inquiries via e-mail, first check the sender and, if in doubt, contact them via another communication channel (e.g.: telephone). Again, do not let yourself be pressured by the e-mail.
If you have any questions or concerns, you can always contact the ARZ.