๐Ÿ”’
Workbook Access Required
Enter the access code to unlock this workbook.
Incorrect access code. Please try again.
Delight Cybersecurity Workbook Series
Delight Cybersecurity Workbook Series
Email Header Analysis Lab
Training mode
Parse headers
Load a sample scenario or paste raw email headers to begin analysis
Authentication checks
SPF, DKIM, DMARC results and threat indicators
Parse headers first to see authentication results
Hop trace
Trace the full mail delivery path from originating server to inbox
Parse headers first to trace the mail path
Verification platforms
External tools for investigating email authenticity โ€” click any card to open
Recommended investigation workflow
1
Extract the sender IP from the first untrusted Received: header โ†’ check on IPinfo + AbuseIPDB
2
Validate authentication (SPF / DKIM / DMARC) using MXToolbox or dmarcian
3
Check the sending domain with WHOIS โ€” domains registered under 30 days ago are a red flag
4
Scan URLs, IPs, and attachments in VirusTotal
5
Full .eml analysis in PhishTool for comprehensive automated IOC extraction
Analyst investigation checklist
Work through each item when analyzing a suspicious email