I had an email from a company which was an invoice. In the email it said 'click here to view the invoice'. Although I do use services of the company, the domain sending the email wasn't the companies domain. I think it is a legit invoice, but it could easily not be. Scammers send similar emails, I've got several similar emails which probably link to malware. Is there any best practice for comapnies sending invoices. eg should the email itself contain the invoice, so you don't have to click on anything. Or should it be sent as a PDF