That's not always going to work. The internet email standard is built such that anyone can spoof anything.
Just live by this rule... NEVER EVER send out sensitive information in these emails. Most companies try to protect against this by having a policy that says they will never ask for your information this way.
|