Back to workflows

Email workflow

Check an email claim or sender context.

A workflow for reading headers, sender alignment, links, and attachments safely.

Passive and safe research workflow

When to use it

You have Email headers and want to check it through safe, legal, source-based research.

What you get

Email triage note, header summary, link context, and recommended response.

Safety boundary

This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.

Simple order

Work through the steps in order.

  1. Preserve the header

    Keep raw headers and observation time.

    Check: The original message is not altered.

  2. Check authentication

    Read SPF, DKIM, DMARC, and alignment.

    Check: Authentication is interpreted with limits.

  3. Review links safely

    Separate domains, redirects, and attachments without entering data.

    Check: No risky click or login is performed.

  4. Write the triage note

    State visible indicators, uncertainty, and user-safe action.

    Check: No malware or bypass instruction is included.

Report language

Email header and link traces show suspicious context, but sender identity and intent require further confirmation.

Move to evidence notes

Sources

Start with these sources.

Open resource archive
  • AlienVault OTX logo

    AlienVault OTX

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source
  • CISA Cyber Hygiene Services logo

    CISA Cyber Hygiene Services

    Data breach checks

    Use for exposure checks and defensive awareness, not for profiling people.

    Open source
  • DNSDumpster logo

    DNSDumpster

    Domain and DNS intelligence

    Use for domain ownership context, DNS records, certificates, and passive web traces.

    Open source
  • DNSViz logo

    DNSViz

    Domain and DNS intelligence

    Use for domain ownership context, DNS records, certificates, and passive web traces.

    Open source
  • Google Password Checkup logo

    Google Password Checkup

    Data breach checks

    Use for exposure checks and defensive awareness, not for profiling people.

    Open source
  • Have I Been Pwned logo

    Have I Been Pwned

    Data breach checks

    Use for exposure checks and defensive awareness, not for profiling people.

    Open source