I'm checking my "deflected" incoming mail to see if anything that
>*should* have been allowed through was mistakenly diverted
>(false positive).
>
>I see a fair number of phishing attempts on my "public" accounts.
>But, all are trivially identified as such.
>
>So, how is it that folks (organizations) are so often deceived
>by these things? Are users just lazy? Would it be more helpful
>to have mail clients make it HARDER to activate an embedded
>URL or "potentially compromised" attachment?
>
>Or, will the stupidity of users adapt, accordingly?
Outlook will apparently send anything through, even obvious phishing ploys.