They all pass DKIM, SPF, etc. Some of them are very convincing. I got dinged for clicking on a convincing one that I was curious about and was 50/50 on it being legit (login from a different IP).
After that, I added an auto delete rule for all the emails that have headers for our phish testing as a service provider.
Comments
I hate the InfoSec generated phishing tests.
They all pass DKIM, SPF, etc. Some of them are very convincing. I got dinged for clicking on a convincing one that I was curious about and was 50/50 on it being legit (login from a different IP).
After that, I added an auto delete rule for all the emails that have headers for our phish testing as a service provider.
Did you report phishing before you clicked? If not, you deserve to be dinged.