When I use this
You received a suspicious link or email. You want to check passive traces without opening risky content.
Phishing workflow
A workflow for checking a link without opening it in a risky way or entering data.
Passive and safe research workflow
When I use this
You received a suspicious link or email. You want to check passive traces without opening risky content.
What you get
Phishing assessment note, confidence level, sources, and suggested defensive action.
What I would be careful with here
The order I follow
Record domain, path, parameters, and redirects without signing in.
No credentials or sensitive data are entered.
Read SPF, DKIM, DMARC, sender alignment, and header anomalies.
Header results are not treated as the only proof.
Check RDAP, DNS, certificates, archives, and reputation sources.
New registration or lookalike signals are dated.
Add confidence, false-positive limits, and a safe response option.
No live exploitation or bypass step is included.
Sources I open
What I can and cannot say
The URL shows phishing-like signals in passive sources; it should be handled as a defensive triage finding, not as a final attribution.
Move to evidence notesSources
Access Now Digital Security Helpline
OPSEC and researcher safety
Digital security assistance resource for civil society and at-risk users.
Open sourceAlienVault OTX
Threat intelligence
Open threat exchange for pulses, indicators, and community threat intelligence.
Open sourceAwesome Threat Intelligence
Threat intelligence
A broad GitHub list of threat-intelligence datasets, tools, platforms, and learning resources.
Open sourceCISA Cybersecurity Best Practices
OPSEC and researcher safety
US government cybersecurity best-practice guidance.
Open sourceDmarcian DMARC Inspector
Email research
DMARC record lookup and explanation tool for email authentication posture.
Open sourceDNSChecker SPF Record Checker
Email research
Web checker for SPF records and syntax across DNS resolvers.
Open source