Tips to Investigate Suspicious Emails

2- Open downloaded e-mail using any text editor:

At these screenshots, we will obfuscate some of the information for the sake of privacy and cover some high level ones but essentially any detail regarding this email, can be just found in this text editor and you can easily try this with any email that you have.

On above screenshot, we can easily spot the following:

  • Sender’s IP address; we can check details of it using AbuseIPDB.
  • DKIM and SPF Results; which we will discuss what this means in the next section.
  • Email server’s IP address which this email is sent from.
  • Date, sender’s email, receiver’s email, and subject of the email.
  • On this screenshot we observe the body of the email.
  • We are also observing URL which was in the email. Pay attention how this URL is shortened which we will also cover in a moment.

URL Shorteners:

URL Expanders: