Web U-M ITSS only
ITSS logo
Home students Faculty & Staff IT Security Community

Online Best Practices For Requesting Personal and Identifiable Information

Surveys and E-mail

  • Be clear about where you are sending the reader and why. Avoid the use of hyperlinked words, for example: "click here for survey" or "University of Michigan Alumni Survey." Instead: "To participate, visit engineering.umich.edu/survey.com." By directing users to an actual site, you establish an expectation about where the user is  going to land, as well as providing an address to compare against the site where they arrive.
  • Avoid asking users to click on an image leading to a site that is requesting personal information. Images can be used to camouflage malicious Web addresses.
  • Include an official university phone number or physical address in addition to an e-mail address for users to contact or visit for more information.
  • Send a copy of the message to itss.inform@umich.edu to be included on the safecomputing.umich.edu "white list."