Back to Blog

Email Analysis: Dissecting a Phishing Email.

September 1, 2026 · Yomal Praveen
Email AnalysisPhishingSOCDFIR

Email remains the most common initial access vector, and analyzing a suspicious email properly is one of the core skills of a SOC analyst. In this post I'll walk through my process for dissecting a phishing email — from headers to indicators of compromise.

1. Header Analysis

The headers tell the real story of where an email came from. Key fields to examine include Return-Path, Received chains, Reply-To, and the originating IP address.

2. Authentication Results (SPF, DKIM, DMARC)

Checking Authentication-Results reveals whether the sending domain is spoofed. A failed SPF or DKIM check on a message claiming to be from a trusted brand is a strong signal.

3. Body & URL Analysis

Hover, don't click. Extract and defang URLs, check redirect chains, and look for lookalike domains and urgency-driven language in the body.

4. Attachment Analysis

Hash any attachments and check them against threat intelligence sources before ever opening them — and only ever detonate in a sandbox.

5. Verdict & Response

Pulling the indicators together: making the call, blocking the sender and IOCs, searching for other recipients, and documenting the incident.