Back to workflows

Phishing workflow

Review a suspicious phishing domain defensively.

A workflow for checking a link without opening it in a risky way or entering data.

Passive and safe research workflow

When I use this

You received a suspicious link or email. You want to check passive traces without opening risky content.

What you get

Phishing assessment note, confidence level, sources, and suggested defensive action.

What I would be careful with here

The order I follow

Work through the steps in order.

  1. Break down the link

    Record domain, path, parameters, and redirects without signing in.

    No credentials or sensitive data are entered.

  2. Check email context

    Read SPF, DKIM, DMARC, sender alignment, and header anomalies.

    Header results are not treated as the only proof.

  3. Read domain age and traces

    Check RDAP, DNS, certificates, archives, and reputation sources.

    New registration or lookalike signals are dated.

  4. Write a defensive note

    Add confidence, false-positive limits, and a safe response option.

    No live exploitation or bypass step is included.

What I can and cannot say

The URL shows phishing-like signals in passive sources; it should be handled as a defensive triage finding, not as a final attribution.

Move to evidence notes

Sources

Start with these sources.

Open resource archive
  • Access Now Digital Security Helpline logo

    Access Now Digital Security Helpline

    OPSEC and researcher safety

    Digital security assistance resource for civil society and at-risk users.

    Open source
  • AlienVault OTX logo

    AlienVault OTX

    Threat intelligence

    Open threat exchange for pulses, indicators, and community threat intelligence.

    Open source
  • Awesome Threat Intelligence logo

    Awesome Threat Intelligence

    Threat intelligence

    A broad GitHub list of threat-intelligence datasets, tools, platforms, and learning resources.

    Open source
  • CISA Cybersecurity Best Practices logo

    CISA Cybersecurity Best Practices

    OPSEC and researcher safety

    US government cybersecurity best-practice guidance.

    Open source
  • Dmarcian DMARC Inspector logo

    Dmarcian DMARC Inspector

    Email research

    DMARC record lookup and explanation tool for email authentication posture.

    Open source
  • DNSChecker SPF Record Checker logo

    DNSChecker SPF Record Checker

    Email research

    Web checker for SPF records and syntax across DNS resolvers.

    Open source