SPAM email inboxes catch countless fake alerts each day.   SANS ISC shares excellent awareness of dangers — from things that are often done as standard procedures.  However,  one must verify before they trust.  Best practices are to always use best practices of human-to-human contact (by calling or verifying outside the email process in trusted manner).

Over the past week, I have noticed several phishing emails linked to Salesforce asking to confirm the recipient’s email address. The body of the email is quite simple. Reviewing the email View Message URL by hovering over the URL or changing email to text mode and comparing it against the correct Salesforce website URL, it clearly shows the client is getting phished.