Comment Re:That's because the workplace counter-trains peo (Score 1) 151
Most often, if an external service is being used (e.g. for employee surveys), you first get a mail from internal address (that is also signed with corporate cert) that says something to the effect of "You'll be getting a mail over the next few days from SurveyPartner. The e-mail originates from @domain.com and it has a link to https://surveybox.something/ou... [surveybox.something] something".
This is the kind of content that should actually be in most phishing trainings.