Phishing investigation: headers, URLs and attachments
For service desk second line, MSP technicians and junior security analysts who triage messages users report as suspicious and who have the mail-admin or security-portal access their role allows. Prerequisite: 'Recognizing phishing emails and messages'; 'Mail flow, message trace and bounce messages' is useful background. You'll learn to read who really sent a message and how it travelled (RFC 5322 header fields), interpret SPF, DKIM and DMARC results and what a pass doesn't prove, take a link apart to find its real host without visiting it, judge an attachment without opening it, and scope, clean up and write up an investigation. Examples use Microsoft 365 where a product is needed; the header standards apply to any mail system. Your own incident procedure decides who may purge mail, block senders or contact people.
- Level
- Intermediate
- Length
- About 100 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify the author, envelope sender, reply address and relay path of a message from its header fields
- Interpret SPF, DKIM, DMARC and composite authentication results, including alignment, and explain what a pass does not prove
- Analyse a URL safely to find its real host, without visiting it from a workstation
- Assess an attachment's risk from its name, type and delivery context without opening it, and choose a safe analysis route
- Scope and record a phishing investigation: find other recipients with message trace, choose a remediation within your authority, and write up findings with evidence
Course outline
- 1.Identify the author, envelope sender, reply address and relay path from the headerLesson · 20 min
- 2.Interpret SPF, DKIM, DMARC and composite authentication results, and what a pass does not proveLesson · 22 min
- 3.Analyse a URL safely to find its real hostLesson · 18 min
- 4.Assess an attachment's risk without opening it, and choose a safe analysis routeLesson · 17 min
- 5.Scope, remediate and write up a phishing investigationLesson · 15 min
- 6.Phishing investigation: headers, URLs and attachments: knowledge checkKnowledge check · 15 questions
- 7.Phishing investigation: headers, URLs and attachments: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- RFC 5322: Internet Message Format (IETF, 2008)
- RFC 7208: Sender Policy Framework (SPF) (IETF, 2014)
- RFC 6376: DomainKeys Identified Mail (DKIM) Signatures (IETF, 2011)
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) (IETF, 2015)
- RFC 8601: Message Header Field for Indicating Message Authentication Status (IETF, 2019)
- RFC 3986: Uniform Resource Identifier (URI): Generic Syntax (IETF, 2005)
- Microsoft Learn: Anti-spam message headers in cloud organizations
- Microsoft Support: View internet message headers in Outlook
- Microsoft Learn: Message trace in the Exchange admin center in Exchange Online
- Microsoft Learn: Safe Links in Microsoft Defender for Office 365
- Microsoft Learn: Safe Attachments in Microsoft Defender for Office 365
- Microsoft Learn: Remediate malicious email delivered in Office 365
- Microsoft Learn: Use the Submissions page to submit suspected spam, phish, URLs, legitimate email getting blocked, and email attachments to Microsoft
- MITRE ATT&CK T1566.001: Phishing: Spearphishing Attachment
- MITRE ATT&CK T1566.002: Phishing: Spearphishing Link
And 1 more.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.