Skip to main content
< All Topics

Phishing Email Investigation

Objective

I analyze suspicious emails to determine whether they are legitimate, phishing attempts, or potentially malicious, and provide clear, actionable insights.

What I Analyze

WhatHow I AnalyzeWhy It Matters
EML Source AnalysisInspect raw email structure and metadataReveals hidden indicators not visible in standard email view
Header CheckAnalyze email headers (Received chain, SPF, DKIM, DMARC)Helps verify sender authenticity and detect spoofing
Link AnalysisExamine embedded URLs and redirectionsIdentifies phishing links or malicious destinations
Domain ReputationCheck sender domains against threat intelligence sourcesDetects known malicious or recently registered domains
DNS AuthenticityValidate domain configuration and DNS recordsEnsures the domain is legitimate and not manipulated
Attachment AnalysisReview attachments for suspicious patterns or indicatorsIdentifies potential malware or harmful payloads

Scope & Options

Analysis can be performed on:

✔️ Forwarded emails (including .eml files or screenshots)

✔️ Extracted email data from client systems

ottolukacs.com - Documenting Cybersecurity Through Custom Labs
by u/ottolukacs in u_ottolukacs

Table of Contents