Back to workflows

Phishing workflow

Review a suspicious phishing domain defensively.

A workflow for checking a link without opening it in a risky way or entering data.

Passive and safe research workflow

When to use it

You received a suspicious link or email. You want to check passive traces without opening risky content.

What you get

Phishing assessment note, confidence level, sources, and suggested defensive action.

Safety boundary

This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.

Simple order

Work through the steps in order.

  1. Break down the link

    Record domain, path, parameters, and redirects without signing in.

    Check: No credentials or sensitive data are entered.

  2. Check email context

    Read SPF, DKIM, DMARC, sender alignment, and header anomalies.

    Check: Header results are not treated as the only proof.

  3. Read domain age and traces

    Check RDAP, DNS, certificates, archives, and reputation sources.

    Check: New registration or lookalike signals are dated.

  4. Write a defensive note

    Add confidence, false-positive limits, and a safe response option.

    Check: No live exploitation or bypass step is included.

Report language

The URL shows phishing-like signals in passive sources; it should be handled as a defensive triage finding, not as a final attribution.

Move to evidence notes

Sources

Start with these sources.

Open resource archive
  • Access Now Digital Security Helpline logo

    Access Now Digital Security Helpline

    OPSEC and researcher safety

    Use to protect the researcher, reduce exposure, and avoid unnecessary collection.

    Open source
  • AlienVault OTX logo

    AlienVault OTX

    Threat intelligence

    Use for IOC context, reputation checks, and defensive security notes.

    Open source
  • CISA Cybersecurity Best Practices logo

    CISA Cybersecurity Best Practices

    OPSEC and researcher safety

    Use to protect the researcher, reduce exposure, and avoid unnecessary collection.

    Open source
  • DNSDumpster logo

    DNSDumpster

    Domain and DNS intelligence

    Use for domain ownership context, DNS records, certificates, and passive web traces.

    Open source
  • DNSViz logo

    DNSViz

    Domain and DNS intelligence

    Use for domain ownership context, DNS records, certificates, and passive web traces.

    Open source
  • EFF Surveillance Self-Defense logo

    EFF Surveillance Self-Defense

    OPSEC and researcher safety

    Use to protect the researcher, reduce exposure, and avoid unnecessary collection.

    Open source