N0N0AH CYBER

FIELD MANUAL

READ THE EVIDENCE

A fast reference for the signals used throughout SAFE or SCAM. One clue rarely proves everything—combine identity, context, request, and route.
01

IDENTITY

Read the exact sender address, not only the display name. Look-alike domains can authenticate perfectly for the attacker.

02

CONTEXT

Ask whether you expected the message and whether it matches something you actually did.

03

REQUEST

Credentials, payment changes, gift cards, secrets, administrator access, and unusual urgency require independent verification.

04

ROUTE

Open the official app or saved website yourself. A familiar brand name inside a long hostname does not make the destination legitimate.

05

AUTHENTICATION

SPF, DKIM, and DMARC identify the sending domain. They do not prove that the domain represents the brand you trust or that the request is safe.

06

PROCESS

Real accounts can be compromised. High-impact changes should still follow an approved process and a separate trusted channel.

ENTER THE INBOX →