Faciotech Issues Guidance on Spotting Spoofed and Phishing Emails
Faciotech will never ask for your password by email. This advisory explains how spoofed and phishing email reaches you and the six checks that catch it.
ACCRA, Ghana, 18 May 2022. Faciotech has published guidance for customers on identifying phishing email, including messages that forge the Faciotech name. The advisory covers how attackers get spoofed mail past spam filters, the signals that give a fraudulent message away, and what to do if you have already clicked a link or entered a password.
Why a convincing phishing email still reaches you
Email was designed without any requirement that a sender prove who they are. The name in the “From” line is simply text the sender chose; anti-spoofing measures are checks bolted on afterwards, not a lock on the front door. Attackers exploit that four ways. They spoof the display name, so a phone shows “Faciotech Support” while the address underneath is a free webmail account. They register lookalike domains differing by a character or a hyphen. They send through legitimate bulk-mail platforms whose sending reputation is good, so the message slips past filters. And they use compromised mailboxes, so a fraudulent message arrives inside an existing thread from someone you trust.
“I would rather a customer forwarded us twenty harmless emails than lost one account to a convincing forgery. Faciotech will never ask you for your password, so any message that does is fraudulent no matter how well it is written, and checking with us first costs you nothing.”
Urbanus Azupogo, Founder, Faciotech
What Faciotech will and will not do
Knowing the boundaries of legitimate contact removes the guesswork.
- Faciotech will never ask for your password, card number or a one-time code by email, chat or phone. No member of staff needs your password.
- Faciotech will never pressure you to act within minutes, threaten immediate deletion of your data, or move the conversation to a personal email address or messaging app.
- Genuine invoices, renewal notices and account alerts are always visible inside your account. Confirm any of them by typing the address into your browser and signing in, never via a link in the message.
- Faciotech will not send an unexpected attachment asking you to enable macros, disable antivirus, or run a file to “verify” an invoice.
Six checks before you click a link in an email
- Read the full sender address, not the display name. Expand it on mobile. A friendly name proves nothing; the domain after the @ must be one you recognise exactly.
- Hover over links before clicking. On a computer the destination appears in the status bar; on a phone, press and hold to preview it. If the visible text and the real URL disagree, stop.
- Treat urgency as a warning sign. “Your account will be suspended today” exists to stop you thinking. Real deadlines are also visible in your account when you sign in yourself.
- Be suspicious of unexpected attachments. Invoices you did not request, delivery notices for parcels you did not order, and documents asking you to enable content are the commonest malware carriers.
- Notice small wrongness. A generic greeting where your name should be, an odd turn of phrase, a low-resolution logo, or a reply-to address that differs from the sender.
- Verify out of band. If a message seems even slightly off, contact the sender on a number or address you already had, never one printed inside the message.
SPF and DMARC help, but they are not a guarantee
Faciotech publishes SPF and DMARC records for faciotech.com, so receiving mail providers can check whether a message claiming to come from the domain really was sent by an authorised server, and so failures are reported back. That makes straightforward forgery of faciotech.com considerably harder.
They are not a complete defence, and it would be misleading to present them as one. Not every provider enforces these checks strictly, display-name spoofing does not forge the domain at all, and a lookalike domain can publish perfectly valid records of its own. Sender authentication raises the cost of an attack; your own habits stop what gets through.
What to do if you have already clicked a phishing link
Act quickly. From a device you trust, change the password on the affected account and on every other account sharing it. Start with the mailbox your Faciotech account is registered to, because whoever controls that can reset everything else. Then enable two-factor authentication. Check your mailbox for forwarding rules or filters you did not create; quietly copying your mail elsewhere is a standard follow-up step for an attacker. Then open a support ticket so the team can review the account with you.
Reporting a suspicious or phishing email to Faciotech
If an email claiming to be from Faciotech does not look right, forward it to support@faciotech.com and then delete it. Forwarding rather than describing it preserves the headers that show where it really came from. Do not reply, and do not click anything in it first. Faciotech's wider security practices are published in the security policy, and the support centre would rather answer a false alarm than clean up after a real one.
About Faciotech
Faciotech is a technology company that builds and runs the digital infrastructure behind growing businesses: web hosting, domains, professional email, cloud servers, custom software, AI automation and hands-on technical support, delivered through one connected service model. Faciotech serves customers across Ghana, Canada and global markets, and publishes a live system status page anyone can check. Browse every product in the Faciotech apps directory.