Investigation guide

How to analyze a phishing email: a step-by-step SOC guide

A repeatable process for investigating reported phishing emails safely — from headers and authentication results to scoping and response.

Updated October 2026 · About 7 minutes to read

Phishing is one of the most common alerts a SOC analyst handles — often reported by a user who “isn’t sure about this email”. This guide shows a repeatable process for analyzing a suspicious email safely and deciding what to do about it.

Safety first: never open attachments or click links from a suspicious email on your normal workstation. Use your organization’s sandbox, isolated analysis tools or reputation services instead.

Step 1: Read the email in context

Start with what the user saw. Note the subject, display name, claimed sender, the action the email asks for and how urgent it sounds. Common lures include password expiry notices, shared documents, invoices, delivery notifications and messages that appear to come from senior leaders.

Ask: does this request make sense for this sender and this recipient? A finance invoice sent to a developer, or an “IT” message from an external domain, is already a warning sign.

Step 2: Inspect the email headers

Headers show where the message really came from. The key fields are:

  • From — the address shown to the user. Easily spoofed or look-alike.
  • Reply-To — where replies go. A different domain from the From address is suspicious, especially in payment requests.
  • Return-Path — the envelope sender used for SPF checks.
  • Received — the servers the message passed through, read from bottom (origin) to top.
  • Message-ID — often reveals the real sending platform.

Step 3: Check SPF, DKIM and DMARC

Look at the Authentication-Results header. SPF checks the sending server, DKIM checks the message signature, and DMARC checks that the visible From domain aligns with them. A failure on a message claiming to be from a well-known company is a strong indicator of spoofing.

But a pass does not make the email safe. Attackers routinely register look-alike domains — such as rnicrosoft-support.com — with perfectly valid authentication. Always read the domain carefully.

Step 4: Analyze the links

  • Extract the real URLs from the message source rather than trusting the visible text.
  • Check for look-alike domains, URL shorteners, unusual top-level domains and newly registered domains.
  • Check reputation with a URL scanning or threat intelligence service.
  • If the link leads to a login page, it is likely credential phishing — note the brand being impersonated.

Step 5: Analyze attachments

  • Note the file name, type and size, and calculate the file hash (for example SHA-256).
  • Check the hash against reputation services.
  • Be wary of HTML attachments, archives (ZIP, ISO, IMG), Office documents with macros, and files with double extensions such as invoice.pdf.exe.
  • Use a sandbox to observe behavior if your organization provides one.

Step 6: Find the scope

One reported email usually means others received it too. Search your mail logs for the same sender, subject, URLs or attachment hash. Then find out who interacted with it: did anyone click the link, open the attachment, reply or enter credentials? Proxy, identity and endpoint logs help answer this.

Step 7: Respond and document

  • Remove the email from all mailboxes.
  • Block the sender, domains, URLs and hashes.
  • If credentials were entered, reset the password, revoke active sessions and review sign-in activity — see how to investigate a suspicious login.
  • If an attachment was opened, investigate the endpoint and consider isolating it.
  • Document what you found, what you did and the indicators, and thank the user for reporting.

Example investigation notes

Reported email “Your mailbox storage is full” from it-support@mail-quota-alerts[.]com. SPF and DKIM pass for the attacker-controlled domain; DMARC not applicable. Link leads to a fake Microsoft 365 login page. 14 recipients; 1 user clicked and submitted credentials at 10:12. Messages purged, domain and URL blocked, user password reset and sessions revoked. No suspicious sign-ins observed after reset. Classified as true positive, severity Medium.

Keep a copy of the phishing checklist handy for your next investigation.

FAQ

Phishing questions

What should I do if I clicked a phishing link?

Report it to your IT or security team straight away. If you entered a password, change it immediately and tell them, so they can revoke sessions and check for misuse.

Can SPF, DKIM and DMARC stop phishing?

They help stop direct spoofing of a domain, but they do not stop attackers using look-alike or compromised domains. Analysts still need to check the actual sender and content.

What tools do analysts use for phishing analysis?

Email security consoles and message traces, header analysers, URL and file reputation services, sandboxes, and tools like CyberChef for decoding. See our cybersecurity tools guide.

Try it yourself

Investigate a realistic phishing report.

Practice header analysis, scoping and response decisions in a safe simulated environment.

Start free. No experience required.