Paul, apply this logic to this type of mail:
1 - does Microsoft know SPECIFICALLY who I am, and my SPECIFIC email address?
2 - why would they not just point me to their update site, rather than wasting bandwidth and time mailing me something?
3 - why is this mail from "microsoft security" but the headers show some chinese or korean address?
There is no reason for microsoft to mail you, I doubt they know you, they don't have your address, and they aren't going to mail an attachment.
My rule #1: anything with an attachment is toast.
Alex
|