The goal of this task is to analyze a suspicious email and identify phishing characteristics such as spoofed addresses, malicious links, and social engineering tactics.
support@secure-bank.com
support@secure-bank-login.xyz
Received from
IP, failed SPF/DKIM checks.https://secure-bank.com/login
http://malicious-site.ru/verify
This is a phishing email designed to trick users into giving away credentials and potentially installing malware.
β Recommended Actions:
Q1. What is phishing?
Fraudulent attempt to obtain sensitive data by pretending to be a trusted entity.
Q2. How to identify a phishing email?
Look for spoofed addresses, mismatched URLs, grammar errors, urgency, and suspicious attachments.
Q3. What is email spoofing?
Forging the senderβs email address to look like a trusted source.
Q4. Why are phishing emails dangerous?
They steal data, spread malware, and cause financial loss.
Q5. How can you verify sender authenticity?
Check headers, SPF/DKIM records, and confirm through official channels.
Q6. What tools can analyze email headers?
Google Header Analyzer, MXToolbox, Microsoft Message Analyzer.
Q7. What actions should be taken on suspected phishing emails?
Report to IT/security team, block sender, delete the email.
Q8. How do attackers use social engineering in phishing?
They exploit fear, urgency, or curiosity to manipulate users.
π Phishing-Email-Analysis
β£ π README.md β This report
β£ π screenshots β (Optional: include email sample/header screenshots)
β π phishing-report.pdf (Optional formatted report)