iCoreHosting Knowledge Note
Why Anti-Spam Systems Cannot Block All Scam Emails
Anti-spam is a filter, not a perfect wall. Scam emails keep changing sender, wording, link, attachment and timing.
Quick Idea
Spam filter blocks many bad emails, but some scam emails look normal enough to pass. Human checking is still needed.
Security Note: Do not click unknown links. Do not open unexpected attachments. Do not send passwords, OTP, banking details or admin login details by email.
1
Scammers Keep Changing Pattern
Risk: New scam wording may not match old spam rules.
Prevention: Update filter rules, keep domain security records active, and review suspicious emails.
Alternative Solution: Use layered protection: spam filter, antivirus scan, user awareness and manual review.
- Same scam, different words.
- Same link style, different domain.
- Same fake invoice, different sender name.
2
Legitimate Email Can Look Similar
Risk: Over-blocking may stop real customer, supplier or billing emails.
Prevention: Avoid very aggressive rules unless you are ready to check quarantine often.
Alternative Solution: Use allow list carefully for trusted senders. Do not allow list unknown domains.
- Invoices can look like scam.
- Marketing emails can look noisy.
- Password reset emails can trigger filters.
3
Some Scam Emails Pass Authentication
Risk: SPF, DKIM or DMARC pass does not always mean the message is safe.
Prevention: Check sender domain, reply-to address, link destination and message intent.
Alternative Solution: Treat authentication as one signal only. Combine it with content and behaviour checks.
- A real domain can be abused.
- A mailbox can be compromised.
- A clean email can contain a risky link.
4
Links Change After Delivery
Risk: A link may look safe during scanning, then redirect to a scam page later.
Prevention: Hover and inspect links. Open only trusted portals directly from browser bookmarks.
Alternative Solution: Use web protection, browser warnings and DNS filtering where suitable.
- Short links hide the real address.
- Redirect chains are hard to judge.
- Fake login pages may look familiar.
5
Attachments Are Not Always Easy To Detect
Risk: Some files are new, encrypted, compressed or designed to avoid detection.
Prevention: Do not open unexpected files. Confirm with sender through another channel.
Alternative Solution: Scan files with endpoint security and keep operating systems updated.
- ZIP files need extra caution.
- Macro documents are risky.
- Fake PDF names can mislead users.
6
Human Judgement Still Matters
Risk: Scam emails often use urgency, fear, fake authority or payment pressure.
Prevention: Slow down. Verify request, sender and action before clicking or replying.
Alternative Solution: Create internal rules for payment change, password reset and admin access requests.
- Urgent request needs checking.
- Payment change needs approval.
- Login request needs confirmation.
Fast Memory Notes
SSL + HTTPS: protects connection, not email truth.
SPF DKIM DMARC: useful, but not a full scam detector.
Plugin Risk: website compromise may send spam.
Monitor + Scan: check logs, mailbox and devices.
Recommended User Habit
- Use strong password and enable 2FA where available.
- Do not reuse email password for other websites.
- Check junk and quarantine folder regularly.
- Report suspicious emails to your IT team or hosting support.
- For iCoreHosting related support, use the official support channel only: https://www.icore.com.my/support
Bottom Flow
Step1
Receive Email
Receive Email
→
Step2
Filter Scan
Filter Scan
→
Step3
User Check
User Check
→
Step4
Verify Source
Verify Source
→
Step5
Report Risk
Report Risk
Anti-spam reduces risk, but no system should be treated as perfect. Safe email usage needs filtering, monitoring, updates and careful human review.
