Module 7

Web and Email Security

Reduce risk from malicious sites, spoofed emails and unsafe downloads with practical verification habits.

Learning Objectives

  • Understand HTTPS and certificate indicators.
  • Recognise malicious website and domain warning signs.
  • Explain email spoofing concepts and safe verification.
  • Apply secure website account and update practices.

Why This Matters

Web and email channels are common attack delivery mechanisms.

Small verification steps can prevent major compromise.

Plain-Language Explanation

HTTPS encrypts traffic between browser and server, but it does not guarantee site trustworthiness by itself. Domain awareness matters: attackers often use lookalike names. Email spoofing can make messages appear legitimate. Treat unexpected links, attachments and credential prompts with caution.

Practical Examples

  • Checking URL spelling before entering credentials.
  • Validating urgent email requests via known phone numbers.
  • Keeping website plugins/themes updated to reduce exposure.

Common Mistakes

  • Trusting any site that shows a padlock.
  • Using weak admin accounts for website logins.
  • Downloading software from unverified mirrors.

Security Checklist

Module checklist progress0%

Short Knowledge Check

Question 1: Does HTTPS alone prove a website is safe?

No. It protects transport encryption but does not validate business legitimacy.

Question 2: What is a key defence against spoofed requests?

Out-of-band verification using trusted contact channels.

Question 3: Why are website updates important?

They often patch security vulnerabilities and reduce exploit risk.

Key Takeaways

  • Verify before trust, especially for identity and payment actions.
  • Domain awareness and update hygiene are high-value controls.
  • Email and web safety are shared responsibilities.
← PreviousModule 7 of 10Next →