When I use this
You have Email headers and want to check it through safe, legal, source-based research.
Email workflow
A workflow for reading headers, sender alignment, links, and attachments safely.
Passive and safe research workflow
When I use this
You have Email headers and want to check it through safe, legal, source-based research.
What you get
Email triage note, header summary, link context, and recommended response.
What I would be careful with here
The order I follow
Keep raw headers and observation time.
The original message is not altered.
Read SPF, DKIM, DMARC, and alignment.
Authentication is interpreted with limits.
Separate domains, redirects, and attachments without entering data.
No risky click or login is performed.
State visible indicators, uncertainty, and user-safe action.
No malware or bypass instruction is included.
Sources I open
What I can and cannot say
Email header and link traces show suspicious context, but sender identity and intent require further confirmation.
Move to evidence notesSources
AlienVault OTX
Threat intelligence
Open threat exchange for pulses, indicators, and community threat intelligence.
Open sourceAwesome Threat Intelligence
Threat intelligence
A broad GitHub list of threat-intelligence datasets, tools, platforms, and learning resources.
Open sourceBitwarden Vault Health Reports
Data breach checks
Bitwarden documentation for vault health reports, including data breach and exposed password checks.
Open sourceCISA Cyber Hygiene Services
Data breach checks
US government vulnerability and exposure scanning services for eligible organizations.
Open sourceDmarcian DMARC Inspector
Email research
DMARC record lookup and explanation tool for email authentication posture.
Open sourceDNSChecker SPF Record Checker
Email research
Web checker for SPF records and syntax across DNS resolvers.
Open source