Bỏ qua đến nội dung chính
Back to home
Tech 2 min read

FedEx Criticized for Sending Legitimate Emails That Look Like Phishing Scams ✉️

Security expert Troy Hunt warns that FedEx's habit of sending emails from unusual domains is inadvertently 'training' users to fall for real phishing campaigns.

Tier 2 · sources 51% confidence Reviewed
Sources troyhunt.com

Security expert Troy Hunt recently criticized global courier FedEx over its confirmation and survey email practices. According to Hunt, when a major enterprise repeatedly uses unofficial domains to contact customers, it undermines global cybersecurity awareness efforts. This behavior makes it impossible for users to distinguish between legitimate notifications and online phishing traps.

Background & Context

The story began when Troy Hunt received a service survey email from FedEx after a delivery. Instead of using the familiar primary domain 'fedex.com', the email came from a strange address and contained complex tracking links. According to Hunt's post on Hacker News, this is not an isolated incident but a standard procedure widely used by FedEx for online customer outreach. This lack of consistency creates a major vulnerability that threat actors can exploit by registering similar-looking domains to trick users.

Technical Analysis & Technology

Technically, utilizing third-party services for marketing or survey emails is very common. However, security experts emphasize that companies must properly configure SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and especially DMARC (Domain-based Message Authentication, Reporting, and Conformance) records on their official domains. By redirecting users to tracking URLs not directly managed under their root domain, FedEx weakens the effectiveness of spam filters. Average users are taught to check the address bar before clicking, yet FedEx's legitimate emails run completely counter to this basic security rule.

Expert Opinions & Insights

Troy Hunt pointed out that this practice by giant corporations like FedEx is 'training' customers to click on any suspicious link they receive. The security community on Hacker News strongly echoed Hunt's concerns. Many experts noted that as long as global brands remain careless about establishing unified, secure email systems, security awareness training for employees and end-users will remain useless because the companies themselves are contradicting what they teach.

Impact & Future Outlook

This incident serves as a wake-up call for IT and marketing departments at large corporations, including those in Vietnam, where using external email services to send notifications is still widespread. In the future, to defend against increasingly sophisticated, AI-driven phishing attacks, companies must standardize their digital communication channels. Consistently using a single primary domain for all customer interactions not only protects brand reputation but also secures the personal data of millions of consumers.