Kern
Summary
This role involves verifying email authenticity by checking sender addresses, email headers (SPF/DKIM/DMARC), and links for scams, while educating users on phishing risks. The work focuses on manual email analysis and domain validation techniques.
This is a remote position.
To check whether a received email is genuine:
-
Check the complete sender address
Click the sender’s name. Watch for misspellings likeamaz0n.cominstead ofamazon.com.
-
Check authentication in Gmail
Open the email → three dots → Show original. Look for:
- SPF: PASS
- DKIM: PASS
- DMARC: PASS
Also check that “mailed by” and “signed by” match the company’s real domain. Do not click immediately
- SPF: PASS
-
Hover over links and inspect the destination. Avoid unexpected attachments, shortened links, or requests for passwords, OTPs, bank details, or urgent payments.
-
Verify independently
Visit the company’s official website by typing the address yourself, or call a known contact number. Do not use the phone number or link inside the suspicious email.
- Remember: authentication passing does not guarantee honesty—a scammer may use a genuine but misleading domain or a compromised account.
If you want to check whether an email address exists and belongs to someone, send a verification link or OTP. That is more reliable than email-verification websites.
You may share a screenshot showing the sender address and email content—hide personal or financial information—and I can check the warning signs.