EMAIL · PHISHING · AUTHENTICATION
How to analyse a suspicious email: a guide to spotting phishing
Email is a common channel for workplace phishing. Despite filtering, deceptive messages can reach inboxes. When faced with a transfer request or security alert, visual appearance alone is not enough.
Learn how to analyse a suspicious email by checking the sender, context and technical signals before acting.
1. Examine the sender: display name versus reality
A display name can imitate a bank, colleague or internal service without proving where the message came from. Expand the sender details to read the full address.
Compare the domain
In this fictional example, “Microsoft Support” paired with “support@secure-login-365.example” calls for independent verification. Compare the address with the organisation’s usual address; a similar-looking domain is not enough.
Check Reply-To
Check the reply address in message details or headers. A different domain can be legitimate, but an unexplained difference deserves investigation. Do not send a reply to test the address.
2. Examine the content and pressure tactics
Social engineering aims to bypass normal checks. The following signs are common, but their absence does not guarantee a trustworthy message.
Urgency or threats
“Your account will be suspended within 24 hours”, “Unpaid invoice”: the aim is to make you act before checking. Even a plausible deadline does not justify bypassing procedures.
Unexpected rewards
An unexpected bonus, refund or supplier credit deserves confirmation. Do not provide bank details or credentials based solely on the message.
Unexpected attachments
A name such as “Invoice_1092.pdf.exe” may disguise an executable. A ZIP archive is not necessarily malicious but can contain a dangerous file. Do not open an unexpected attachment before confirming its context and source.
3. Inspect technical signals and headers
An email analyser can help interpret headers from the original message. An .eml or .msg file may contain this information, depending on its export; copied text or a screenshot generally does not preserve it. Content alone cannot verify every protocol.
SPF
SPF checks whether the sending server’s IP address is authorised for the envelope sender’s domain, usually visible in Return-Path. It does not by itself validate the From address displayed to the user.
DKIM
DKIM associates a signature with a domain and checks the integrity of the message parts covered by that signature. A valid signature does not prove the content is honest or safe.
DMARC
DMARC checks alignment between the From domain and a domain authenticated through SPF or DKIM. The domain also publishes a policy for failures. A policy may be monitoring-only: DMARC does not always mean blocking.
Distinguish results reported in headers from independent verification. An Authentication-Results field is trustworthy only when it comes from a trusted receiving server. Even successful checks do not make content safe: a genuine mailbox can be compromised.
4. Three steps when doubts remain
Do not click or open attachments
Do not use buttons in the message, including a fake unsubscribe link. Some links also track recipient activity. Keep the evidence needed for reporting.
Confirm through a known channel
For requests from an executive or supplier, call a number already saved in your directory. Do not use the number in the suspicious message or reply to ask whether it is genuine.
Report to IT
Use your organisation’s reporting button or channel. Preserve the original message and headers where possible: a screenshot alone can lose evidence useful to IT or security teams.
If you have already entered credentials, opened a file or approved a request, alert IT promptly and follow the appropriate response steps.
I clicked: what should I do?Make checking emails a daily habit.
An online email scan can make signals easier to understand and help decide when to escalate. Do not submit passwords, MFA codes or confidential information. Automated analysis reduces some uncertainty without eliminating all risk.
Analyse a suspicious emailUsing your account’s free credits, within the available allowance.
Request a discussion about a pilot
Pilot terms and pricing are agreed before it starts.