I finally stopped phishing attacks with the 2-hour delay rule
Our office in Austin got hit twice last quarter with fake invoice emails, and I almost clicked the second one because it looked so real. A buddy who works in IT told me to set up a rule where any email from outside the company goes to a separate folder for 2 hours before I even look at it. That delay gives me time to check the sender domain or call the person directly, and it's caught 3 fakes in the last month alone. The trick is you have to actually verify before you move anything to your main inbox, not just glance at the subject line. I also added a filter for emails with the word 'urgent' from unknown senders, which is where most of the bad ones hide. Has anyone else tried a time-delay approach, or do you use something like DKIM checks in Outlook? It feels cheap but it's been more useful than the $500 training we bought.