this post was submitted on 22 Jul 2026
301 points (100.0% liked)

Dull Men's Club

4436 readers
922 users here now

An unofficial chapter of the popular Dull Men's Club.

https://dullmensclub.com/

1. Relevant commentary on your own dull life. Posts should be about your own dull, lived experience. This is our most important rule. Direct questions, random thoughts, comment baiting, advice seeking, many uses of "discuss" rarely comply with this rule.

2. Original, Fresh, Meaningful Content.

3. Avoid repetitive topics.

4. This is not a search engine
Use a search engine, a tradesperson, Reddit, friends, a specialist Facebook group, apps, Wikipedia, an AI chat, a reverse image search etc. to answer simple questions or identify objects. Also see rule 1, “comment baiting”.

There are a number of content specific communities with subject matter experts who can help you.

Some other communities to consider before posting:

5. Keep it dull. If it puts us to sleep, it’s on the right track. Examples of likely not dull: jokes, gross stuff (including toes), politics, religion, royalty, illness or injury, killing things for fun, or promotional content. Feel free to post these elsewhere.

6. No hate speech, sexism, or bullying No sexism, hate speech, degrading or excessively foul language, or other harmful language. No othering or dehumanizing of anyone or negativity towards any gender identity.

7. Proofread before posting. Use good grammar and punctuation. Avoid useless phrases. Some examples: - starting a post with "So" - starting a post with pointless phrases, like "I hope this is allowed" or “this is my first post” Only share good quality, cropped images. Do not share screenshots of images; share the original image.

.

founded 2 years ago
MODERATORS
 

Can’t make the wrong people look bad.

top 39 comments
sorted by: hot top controversial new old
[–] Landless2029@lemmy.world 1 points 6 minutes ago

I was working IT Support for a company and we got really busy.

At the next all hands the VP mentioned everyone gets doordash giftcards to cover a company lunch remotely and asked for confirmation. First time doing this.

I said I didn't have mine. Why? Sent to spam of course!

Gift card? From my company?? Most he spam!

[–] EastofEdson@piefed.ca 17 points 1 hour ago (1 children)

My company: Don't click on suspicious links.

Also my company: It's employee survey time, click this link to complete the survey http://surveywhale.com/haidn39fk49cmc93mx

I mark them as phishing attempts every damn time.

[–] Evotech@lemmy.world 3 points 54 minutes ago

Do we work in the same company?

[–] Blackmist@feddit.uk 19 points 2 hours ago (2 children)

I got a mandatory phishing awareness course that we were signed up to by corporate, and I deleted it because it looked scammy as all fuck.

Don't whine at people for not completing your course on phishing, when you sign them up to courses using scammy looking names without telling us first.

I'm not sure who these courses were even for. I was born in the scams. Moulded by them. I didn't see a genuine banking email until I was already a man. I remember my dad forwarding pyramid schemes to his friends on paper.

[–] monkeyslikebananas2@lemmy.world 1 points 4 minutes ago

I remember those paper schemes!!! If everyone just sends money around it will multiply and you can make millions! I got one and tracked down some of the people on the list to see how much they got. I was 17 and just heading to college at the time.

[–] Burninator05@lemmy.world 5 points 1 hour ago

My org has us do the standard phishing training and then sends out completely legit links that ring all the alarm bells. Lots of survey links coming from whatever random domains they found to host it. Links to official applications that ask for to many permissions and are shady as fuck. Its surprising we don't get got more often.

[–] acchariya@lemmy.world 9 points 2 hours ago

The best defence against phishing I have found is to just utterly ignore my email inbox at work.

You missed our recent phishing email, try to report it next time

No, I was so cautious I avoided my whole inbox because it might contain suspicious messages.

[–] VitoRobles@lemmy.today 30 points 6 hours ago

You can always forward it back to IT saying it's a suspicious link, according to this blog link you found. The blog link... Your own phishing link.

Two can play this game.

[–] stoy@lemmy.zip 36 points 6 hours ago (1 children)

IT guy here....

DAMN, that was brilliant!

[–] Acid_Burn@lemmy.dbzer0.com 2 points 29 minutes ago

Same. I saved it to add to our KnowBe4 templates

[–] daddycool@lemmy.world 85 points 8 hours ago
[–] isleepinahammock@lemmy.blahaj.zone 47 points 7 hours ago (1 children)

I take great pleasure in flagging the training emails from my company's IT contractor as phishing emails. After all, they're unexpected emails with big link that I simply must quickly click on. That sounds like phishing to me!

[–] Vlyn@lemmy.zip 9 points 2 hours ago

I've genuinely done this once or twice as it really looked like phishing to me. External email, big red button, hey, you have to finish this training until date xy!

Yeah, no, fuck you, report as phishing.

Whoops (:

[–] unemployedclaquer@sopuli.xyz 11 points 6 hours ago (1 children)

Yeah y'all get it, I get it, my relatives don't get it

[–] cobysev@lemmy.world 13 points 5 hours ago

Tell your relatives that this IS the phishing test email. If you click that link, you're gonna get busted by your IT department.

Never click links (or for that matter, ads) in emails. Always verify the sender first. Not the display name, the actual email address that it was sent from.

If you must go to a link, best to find out what website they're sending you to (hover over the link for the URL), then type in the main website manually from a web browser.

For example, if you get an email from US Bank (assuming you use them), type "usbank.com" (minus quotation marks) in your browser, then login to your personal bank account on their official website. Don't trust a link to a bank's website without typing it yourself. Don't just copy/paste the full URL from your email either.

Some links, even to legitimate websites, can have tracking data in the URL that gives a lot of info about you, where in the world you're browsing from, what web browser you're using, what website, app, or program you clicked the link from, etc. Basically, remove the ? and everything after it in URLs before loading them in your browser.

These are just a few basics to protect yourself from malicious links. Basically, don't click any link you don't recognize and verify with people who send you links. And even then, protect yourself from idiots who forward links without doing their own spot checks. Even your best friends can send you viruses and malware. Heck, that's how a lot of it spreads across the Internet.

And especially don't trust your own IT department when they ask you to click links in their emails.

Sincerely,

~A former IT guy

[–] TIEPilot@lemmy.world 50 points 9 hours ago

I used to report just about any email I got from HR/IT/Executive Management that had a link as spam... I got a lot of interesting replies from IT over the years.

Time to update your benefits SPAM/PHISHING!

Sign up for the holiday "pot luck" SPAM/PHISHING!

Tells us how you feel in thie "anonymous" survey... you guessed it SPAM/PHISHING!

[–] hperrin@lemmy.ca 68 points 10 hours ago

100% success rate if you mark every email as a phishing attempt.

[–] KickMeElmo@sopuli.xyz 76 points 10 hours ago (2 children)

Report the email for phishing attempt.

[–] zr0@lemmy.dbzer0.com 45 points 5 hours ago (2 children)

Uhm. It is the phishing attempt. If you click that link it will tell you, you failed the test. And looking at the comments, a lot of people would fail this test.

[–] ColeSloth@discuss.tchncs.de 3 points 1 hour ago (1 children)

...... That's why you would report the email as a phishing attempt.

[–] zr0@lemmy.dbzer0.com 2 points 49 minutes ago

I was maybe just reading the top comment differently, as if they thought the e-mail was legit and now jokingly said to report it, because reporting a legit e-mail about the topic phishing is ironic.

[–] kuiskaaja@lemmy.ml 4 points 5 hours ago

if this was reddit it would look a lot different, as everybody knows, you need a really high iq to use reddit

[–] Racoonwithbenefits@lemmy.zip 16 points 8 hours ago (1 children)
[–] tetris11@feddit.uk 2 points 5 hours ago

You wouldn't download a car

[–] Botzo@lemmy.world 17 points 8 hours ago (1 children)

I have a rule that searches the email headers for the test emails and just deletes them.

[–] emmanuel_car@fedia.io 13 points 5 hours ago (1 children)

Depending on what they’re testing for, you may still be a fail in the statistics. For example in my company we have a button to report phishing attempts, if you fail to report the email you fail.

[–] Botzo@lemmy.world 11 points 4 hours ago

Of course.

Easy enough to dump them in a folder and spend a few minutes a week playing cyber security theater.

[–] swicano@programming.dev 46 points 10 hours ago

Seems legit. Click the link

[–] CMDR_Horn@lemmy.world 38 points 11 hours ago (2 children)

Ive often suggested to our security team that they send one out spoofing the monthly mandatory training vid

[–] wizardbeard@lemmy.dbzer0.com 51 points 11 hours ago (2 children)

The issue is that people's egos get bruised when they fall for it, and they'll very quickly get management on their side that certain ones are unfair, as if phishers give a shit about fair.

What I really love is how my workplace uses some man in the middle crap to replace every link in every email with a new one redirected through our cyber security link scanning product, so now there's no way to check the actual link before you click it since they're all just like garbagesec.com/4a12c89e7f now.

[–] runner_g@piefed.blahaj.zone 8 points 8 hours ago

In my experience, its usually upper management that fails the phishing attempts.

[–] sketchyenchantment@sh.itjust.works 21 points 10 hours ago (3 children)

Our IT solution to that was to MITM all the links except for the phishing tests. So anyone savvy enough to realize that always passes.

[–] Ziglin@lemmy.world 10 points 7 hours ago

But real phishing emails will have the same treatment as normal emails making them harder to detect. Sounds like a really bad system that probably doesn't offer any advantages over a pihole.

[–] CMDR_Horn@lemmy.world 14 points 10 hours ago

Ours is exactly the same as this lol. The joke is we are an IT firm so everyone except from sales and hr easily detetct it.

[–] dendie@piefed.social 4 points 7 hours ago

Ours seems to set a header like X-Phishing-Test on the email so it's trivially easy to get them right every time

[–] Bane_Killgrind@lemmy.dbzer0.com 22 points 10 hours ago (1 children)

PFF I don't click on any training emails unless my manager is asking about it in person.

If it's not important enough for them to follow up on, it's not important.

[–] hemko@lemmy.dbzer0.com 4 points 8 hours ago

Yeah I created a rule that checks for a specific header in the mail from the phishing test platform, and junks those emails. Luckily, also the monthly security training emails also have the same X header

[–] rockSlayer@lemmy.blahaj.zone 17 points 10 hours ago

Link is sus, phishing

[–] iconic_admin@lemmy.world 19 points 10 hours ago

Don’t fall for it.