G DATA Phishing Simulation

Prevent automatic image download by email clients

Because emails may also load images from external links (remote sources), automatic image download should be disabled in every email client for security reasons. In most email programs (e.g., Outlook), this is already disabled by default.

For some users—especially those who frequently receive images for work—this additional effort may be too much. They may then consider enabling automatic image download again. You should verify before the campaign whether this has occurred within your organization.

Our servers for phishing simulation campaigns cannot distinguish whether the image was downloaded automatically or manually by the user.

If, after the campaign, you determine in the campaign report that a very large number of phishing emails were opened, this may be because this blocking setting was not enabled. In any case, this should be checked before starting the campaign.