Skip to content

Phishing investigation: headers, URLs and attachments

For service desk second line, MSP technicians and junior security analysts who triage messages users report as suspicious and who have the mail-admin or security-portal access their role allows. Prerequisite: 'Recognizing phishing emails and messages'; 'Mail flow, message trace and bounce messages' is useful background. You'll learn to read who really sent a message and how it travelled (RFC 5322 header fields), interpret SPF, DKIM and DMARC results and what a pass doesn't prove, take a link apart to find its real host without visiting it, judge an attachment without opening it, and scope, clean up and write up an investigation. Examples use Microsoft 365 where a product is needed; the header standards apply to any mail system. Your own incident procedure decides who may purge mail, block senders or contact people.

Level
Intermediate
Length
About 100 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Identify the author, envelope sender, reply address and relay path of a message from its header fields
  • Interpret SPF, DKIM, DMARC and composite authentication results, including alignment, and explain what a pass does not prove
  • Analyse a URL safely to find its real host, without visiting it from a workstation
  • Assess an attachment's risk from its name, type and delivery context without opening it, and choose a safe analysis route
  • Scope and record a phishing investigation: find other recipients with message trace, choose a remediation within your authority, and write up findings with evidence

Course outline

  1. 1.Identify the author, envelope sender, reply address and relay path from the headerLesson · 20 min
  2. 2.Interpret SPF, DKIM, DMARC and composite authentication results, and what a pass does not proveLesson · 22 min
  3. 3.Analyse a URL safely to find its real hostLesson · 18 min
  4. 4.Assess an attachment's risk without opening it, and choose a safe analysis routeLesson · 17 min
  5. 5.Scope, remediate and write up a phishing investigationLesson · 15 min
  6. 6.Phishing investigation: headers, URLs and attachments: knowledge checkKnowledge check · 15 questions
  7. 7.Phishing investigation: headers, URLs and attachments: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

And 1 more.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.