Guides authorized email security review: phishing analysis, SPF/DKIM/DMARC header authentication, BEC patterns and mailbox token abuse.
- What it does
- Provides a structured workflow for reviewing suspicious email, covering full raw header inspection, Received chain and From/Return-Path consistency, SPF/DKIM/DMARC alignment, URL and attachment checks, and brand impersonation and reply-address differences. It also covers tenant-side controls such as anti-phishing policies, external tagging, MFA and OAuth app consent, and points to a bundled email authentication checklist reference. Outputs are analysis conclusions and detection-ready indicators rather than files.
- When to use it
- Use it when performing an authorized email security review, such as dissecting a phishing sample, assessing SPF/DKIM/DMARC configuration, investigating business email compromise patterns, or examining OAuth app phishing and mailbox token abuse. It assumes authorization for the sample or tenant being reviewed.
- Requirements
- Instructions only; no scripts are shipped. It references a bundled checklist file and expects access to raw email headers, DNS lookup tools such as dig or nslookup, URL and attachment sandboxing services, and a tenant management console for policy review.