Investigation guide
A repeatable process for investigating reported phishing emails safely — from headers and authentication results to scoping and response.
Updated October 2026 · About 7 minutes to read
Phishing is one of the most common alerts a SOC analyst handles — often reported by a user who “isn’t sure about this email”. This guide shows a repeatable process for analyzing a suspicious email safely and deciding what to do about it.
Safety first: never open attachments or click links from a suspicious email on your normal workstation. Use your organization’s sandbox, isolated analysis tools or reputation services instead.
Start with what the user saw. Note the subject, display name, claimed sender, the action the email asks for and how urgent it sounds. Common lures include password expiry notices, shared documents, invoices, delivery notifications and messages that appear to come from senior leaders.
Ask: does this request make sense for this sender and this recipient? A finance invoice sent to a developer, or an “IT” message from an external domain, is already a warning sign.
Headers show where the message really came from. The key fields are:
Look at the Authentication-Results header. SPF checks the sending server, DKIM checks the message signature, and DMARC checks that the visible From domain aligns with them. A failure on a message claiming to be from a well-known company is a strong indicator of spoofing.
But a pass does not make the email safe. Attackers routinely register look-alike domains — such as rnicrosoft-support.com — with perfectly valid authentication. Always read the domain carefully.
invoice.pdf.exe.One reported email usually means others received it too. Search your mail logs for the same sender, subject, URLs or attachment hash. Then find out who interacted with it: did anyone click the link, open the attachment, reply or enter credentials? Proxy, identity and endpoint logs help answer this.
Reported email “Your mailbox storage is full” from it-support@mail-quota-alerts[.]com. SPF and DKIM pass for the attacker-controlled domain; DMARC not applicable. Link leads to a fake Microsoft 365 login page. 14 recipients; 1 user clicked and submitted credentials at 10:12. Messages purged, domain and URL blocked, user password reset and sessions revoked. No suspicious sign-ins observed after reset. Classified as true positive, severity Medium.
Keep a copy of the phishing checklist handy for your next investigation.
FAQ
Report it to your IT or security team straight away. If you entered a password, change it immediately and tell them, so they can revoke sessions and check for misuse.
They help stop direct spoofing of a domain, but they do not stop attackers using look-alike or compromised domains. Analysts still need to check the actual sender and content.
Email security consoles and message traces, header analysers, URL and file reputation services, sandboxes, and tools like CyberChef for decoding. See our cybersecurity tools guide.
Try it yourself
Practice header analysis, scoping and response decisions in a safe simulated environment.
Start free. No experience required.