Watch Your Domain Extensions (Who does that email REALLY come from?)
Privacy, Cyber & AI Decoded Alert | 2 min read
Apr 18, 2019
Risk Management Question
How can you tell if an email—which appears to be from within a firm's own messaging system, advising the recipient that his or her information has expired or needs to be updated, and directing the recipient to click on a link to update their information—is genuine?
The Issue
Recently, several lawyers and secretaries of a law firm received an email purportedly from the firm's own "Messaging System" claiming that the recipient's email was out of date and instructing the recipient to click on a box to update his or her email.
The email was malicious. A few tell-tale signs that the message was bogus included the fact that the firm's email addresses do not go out of date. Only passwords can expire, and the firm's system was set up to alert attorneys and employees of the firm that their password was set to expire several weeks before expiration occurred. Further, the firm did not have a "Messaging System" and the email was designated as an "External email" by the firm's server.
But the real give-away was the domain extension of the sender of the email. The sender of the email in this case was located in Germany. You could tell this by looking at the sender's domain extension—in this case, .de is the domain extension used in Germany.
Risk Management Solutions
- Always check the domain extension of the sender of an email. If you move too fast you may think the extension is .com when it's really .cn which indicates the email originates in China. Be wary of anything that doesn't end in .com, .gov, .us, .law or a state domain extension like .az (for Arizona) for instance. Here is a list of foreign domain extensions to check if you ever don't recognize an extension: https://www.webopedia.com/quick_ref/topleveldomains/countrycodeA-E.asp
- Set up your email system so that email coming from outside of the firm is tagged as "External email" and instruct employees to be cautious of all external email. In the example above, if the email had actually come from an internal "Messaging System" it would not have been designated as "External email."
- Send suspicious emails to your firm's breach inbox to have them evaluated and have the sender(s) blocked firm wide.
- As always, if you receive an email out of the blue, never click on a link or attachment. Also, if you receive an email from someone you know, but it includes an attachment you were not expecting to receive, call the sender to confirm it came from the sender and not a hacker.
Remember, let's be careful out there.
Related People
Related Capabilities
Featured Insights

Event
Apr 23, 2026
Driving Ahead: Insights from Industry Leaders Auto Finance Seminar

Consumer Crossroads: Where Financial Services and Litigation Intersect
Mar 13, 2026
DOJ Settlement with Car Retailer Highlights SCRA Repossession Risks

Privacy, Cyber & AI Decoded Alert
Mar 11, 2026
Compliance Considerations for GDPR Consent in Biotech Clinical Research

Press Release
Mar 4, 2026
Marcia Mueller Named the 2026 Mentorship Award Winner by YWCA Northwestern Illinois

Press Release
Mar 3, 2026
Hinshaw Announces New Administrative Leadership Appointments

In The News
Feb 27, 2026
Hinshaw Partners Examine Implications for Nursing Homes of New Illinois Aid-in-Dying Law

In The News
Feb 24, 2026
Lucy Wang Authors Law360 “Expert Analysis” on Why Attorney Civility Means More in 2026

Press Release
Feb 13, 2026
Hinshaw Team Wins Appeal in Criminal Indictment of Waukegan City Clerk Janet Kilkelly

Press Release
Feb 10, 2026
Hinshaw Trial Team Secures $0 Defense Verdict in $15 Million Auto Accident Trial

Press Release
Feb 5, 2026
Hinshaw Legal Team Secures Directed Verdict in Florida Equine Fraud Case

Press Release
Feb 4, 2026
Hinshaw Celebrates 17 Consecutive Years of Being Named an Equality 100 Award Winner

![[Video] New Regulatory Priorities Under Mayor Mamdani’s NYC Department of Consumer and Worker Protection](/a/web/oHiTWa7kRy3Ht1brq6k4BT/bkMx39/new-york-city-skyline.jpg)
