Email is weaker because it is easy for a fraudster to create a plausible account in minutes, and the address itself may not reveal whether the sender is legitimate. Phone calls create a more interactive test, especially when paired with a simple order-specific question and basic phone-number checks that expose VoIP or other higher-risk lines.
Why phone creates a better fraud check than email
Email is a weak verification channel because it is easy to create, easy to spoof socially, and often disconnected from the person who actually placed the order. A phone call adds friction for an attacker, forces live interaction, and lets staff test whether the requester can answer order-specific questions without hesitation.
That difference matters most when the order is unusual, time-sensitive, or high value. Email can be routed through compromised mailboxes, disposable accounts, or a convincing lookalike address, while a call can expose whether the supposed buyer can respond coherently to details that were already agreed during the transaction.
For organisations that want a stronger control baseline, treat phone verification as a step-up check rather than a replacement for all other controls. It works best when the person calling is required to prove knowledge of context, and when the business has already captured a known-good number from an earlier trusted interaction or account record.
What makes email easy to abuse
Email is asynchronous, which gives the attacker time to craft a plausible message, replay existing language, or slowly build trust. It also tells you very little about whether the sender controls the real business relationship behind the order, because the mailbox itself may be newly created, compromised, or simply controlled by someone impersonating the customer.
In practice, email is also weaker because it is harder to distinguish a legitimate request from a forwarded message, a mailbox takeover, or a social-engineering pretext. If the order verification step relies only on text in the inbox, the control is vulnerable to whichever account has the best appearance rather than the best proof of legitimacy.
By contrast, phone is not “secure” by default, but it does create a more interactive challenge. A caller must remain consistent under questioning, and that gives staff a chance to ask for a detail that is specific to the order and not easily guessed from public data or a copied message thread.
What a stronger verification call should test
A good call is not just “Did you send this email?” It is a short, focused authenticity check that tests both access to the correct contact path and knowledge of the transaction. The practical goal is to reduce the chance that a fraudster can pass by using a stolen inbox or a convincing scripted reply.
- Confirm the callback number against a previously trusted record, not the number supplied in the suspicious message.
- Ask one order-specific question that is hard to guess from the email alone.
- Watch for pressure to avoid the call, change the number, or move the discussion back to email.
- Escalate if the request involves urgency, payment changes, destination changes, or unusual delivery instructions.
Where organisations already use trusted contact data, the strongest practice is to pair the call with basic number validation and a separate internal approval path for high-risk changes. That way, the phone call becomes one layer in a broader verification workflow rather than the only gate.
Risk and Threat Considerations
Fraudsters prefer email because it scales cheaply, supports impersonation, and can be used to push orders through before anyone notices inconsistencies. The main risk is not only a fake address, but also the ease with which a compromised mailbox can make a suspicious request look routine.
Failure mechanism: The attacker exploits asynchronous communication, sender ambiguity, and weak contact verification to submit or modify an order without proving real-world control of the customer relationship.
Impact: The result can be unauthorised shipment, payment diversion, account takeover follow-through, or a business email compromise pattern that is harder to unwind once fulfilment has started.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST Zero Trust (SP 800-207), CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | 3 — Zero Trust Tenet: Never Trust, Always Verify | Live verification reduces trust in the message channel alone. |
| Recommendation — Require explicit verification of high-risk order changes before approval. | ||
| CIS Controls v8 | 6 — Access Control Management | Order checks depend on validating the requesting contact path and approval step. |
| Recommendation — Restrict high-risk order changes to verified, approved workflows. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication, and Access Control | Suspicious-order verification is an access-trust control for transaction changes. |
| Recommendation — Verify requester identity through a stronger channel before fulfilling exceptions. | ||
Practitioner Guidance
What to prioritise: Use phone verification first on orders where the loss impact is high or where the request changes payment, delivery, or account details. If the order is ordinary and low-risk, a lighter check may be sufficient; if the order is unusual, treat the call as mandatory.
What to verify: Verify the callback path independently, then ask one question that depends on shared transaction context rather than inbox contents. If the answer sounds coached, inconsistent, or overly eager to move back to email, treat that as a warning sign.
Practitioner takeaway: Email can confirm that a message arrived, but phone verification can better test whether the requester can actually sustain the identity behind the request under live scrutiny.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on email as the main approval channel?
- How should teams reduce the risk of BEC when email is still a core business channel?
- How do IAM teams reduce risk when email becomes a trust channel?
- How should security teams investigate suspicious email attachments without losing context?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org