Labs · Cyber Security
Lab: Spot the Phish: Check the Sender, Links and Headers of 5 Sample Emails and Report One Correctly
Course: Cyber Security · Chapter 27: Social Engineering Awareness
Chapter 27 explains social engineering; this lab trains your eyes on the email clues that give phishing away.
Chala mitrano! Most attacks still start with one email and one click. The good news: phishing emails leave clues, and once you know where to look, you will spot them in seconds. Today we read 5 sample emails like a SOC analyst: sender, reply-to, headers, links, and the feeling of urgency. Chala, detective banuya!
चला मित्रांनो! बहुतेक attacks अजूनही एका email आणि एका click ने सुरू होतात. चांगली बातमी: phishing emails clues सोडतात, आणि कुठे बघायचं हे कळलं की तुम्ही ते काही सेकंदात ओळखाल. आज आपण 5 sample emails SOC analyst सारखे वाचणार: sender, reply-to, headers, links, आणि घाईची भावना. चला, detective बनूया!
चलो दोस्तों! ज़्यादातर attacks आज भी एक email और एक click से शुरू होते हैं। अच्छी ख़बर: phishing emails clues छोड़ते हैं, और कहाँ देखना है ये समझ आ गया तो आप उन्हें सेकंडों में पहचान लोगे। आज हम 5 sample emails SOC analyst की तरह पढ़ेंगे: sender, reply-to, headers, links, और जल्दबाज़ी का एहसास। चलो, detective बनते हैं!
Suppose we are…
Suppose we have joined the security awareness team at Wipro. Employees forward suspicious emails to us every day. Some are real phishing, some are genuine notices that just look odd. We practise on 5 sample emails that imitate common Indian scams (KYC, delivery fee, CEO gift cards, tax refund) plus one genuine IT notice. All addresses use reserved .example domains, so nothing in the file is real.
Goal of this lab
By the end you will be able to:
- Read the From, Reply-To, Return-Path and Authentication-Results (SPF, DKIM, DMARC) lines of an email.
- Spot mismatched link targets, urgency and requests for money, OTPs or gift cards.
- Mark each email Safe or Phish with a reason, and know how to report a phish correctly.
What you need (all free)
- The sample file below, opened in Notepad or TextEdit.
- Your own Gmail or Outlook account (only to find the menus, not to send anything).
- About 30 minutes.
Safety and ethics
Do not visit any link in the samples, and never click links in real suspicious emails. Do not forward phishing emails to friends "as a joke", and never send a phishing test to anyone without written permission from your organisation.
Steps
- Open
phish_samples.txt. Make a table with columns Email, From (display name + address), Reply-To, SPF/DKIM/DMARC, Link target, Pressure or request, Verdict, Reason. -
Email 1. Compare the From address with the Return-Path and Reply-To.
What you should see: From says
alerts@sbi.co.in, but Reply-To and Return-Path aresbi-kyc-update.example, anddmarc=failforheader.from=sbi.co.in. The real domain did not send it. -
Look at the link text vs its real target (shown in
< >). "Update KYC" points tohttp://sbi-kyc-update.example/..., not the bank's site, and uses plain HTTP. Add "account blocked within 24 hours" as pressure. -
Email 2. Check the same lines.
What you should see: SPF, DKIM and DMARC all
passfor the company's own domain, the link stays on the company intranet, and it asks for no action, no password and no money. Verdict: Safe. -
Email 3. Notice that SPF and DKIM pass, but for
amazon-in-delivery.example, a look-alike domain the scammer owns. Passing checks only prove who sent it, not that the sender is honest. The small "Rs 25 fee" is the hook to collect card details. - Email 4. No link at all. Read the request: gift cards, urgency, secrecy, a personal webmail address for a "CEO". This is business email compromise (BEC). Verdict: Phish, verify by calling the person on a known number.
- Email 5. From claims
incometax.gov.inbutdmarc=failandspf=softfail; it has an.htmlattachment that asks for net-banking details and an OTP. The real department never asks for an OTP. -
Fill in the Verdict column for all five, then compare with the answer below.
Check your answer
1 Phish (spoofed bank, DMARC fail, look-alike link, urgency). 2 Safe (all checks pass for the real domain, no request). 3 Phish (look-alike domain, small fee to steal card details). 4 Phish (BEC: gift cards, secrecy, webmail "CEO"). 5 Phish (spoofed government domain, DMARC fail, HTML attachment asking for OTP).
-
Learn how to see these headers in a real email (do this on any email in your own inbox): Gmail → open the email → ⋮ (More) → Show original. Outlook.com → … → View → View message source.
What you should see: the same
Authentication-Resultsline withspf=,dkim=anddmarc=values. -
Learn how to report correctly (find the menu, do not click on a real email unless it really is phishing): Gmail → ⋮ → Report phishing. Outlook → Report → Report phishing. At work, use the "Report phish" button or forward as an attachment to your security team. If money was lost in India, call 1930 immediately (Chapter 34).
Ravindra Bagale's Tip
Remember "SLAP": Sender, Links, Attachments, Pressure. If any one of these feels wrong, stop and verify through another channel: the official app, the number on your card, a call to your manager. Ek phone call, khup paise vachavto!
Ravindra Bagale's Tip – मराठी
"SLAP" लक्षात ठेवा: Sender, Links, Attachments, Pressure. यातलं काहीही चुकीचं वाटलं तर थांबा आणि दुसऱ्या मार्गाने verify करा: official app, card वरचा number, manager ला call. एक phone call, खूप पैसे वाचवतो!
Ravindra Bagale's Tip – हिंदी
"SLAP" याद रखो: Sender, Links, Attachments, Pressure। इनमें से कुछ भी गलत लगे तो रुको और दूसरे रास्ते से verify करो: official app, card पर लिखा number, manager को call। एक phone call, बहुत पैसे बचाता है!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Trusting the display name ("SBI KYC Team") | Anyone can type any display name | Read the actual address and domain |
| Thinking "SPF pass" means safe | Scammers pass SPF for their own look-alike domains | Check which domain passed |
| Hovering on mobile is impossible, so clicking to "check" | You land on the phishing page | Long-press to preview the link, or don't open it at all |
| Replying to ask "is this real?" | The reply goes to the scammer (Reply-To) | Verify through an official channel |
| Deleting a work phish without reporting | Colleagues get the same email | Use Report phishing so the team can block it |
Self-check checklist
0 of 5 done
Try-at-home challenge
Open Show original on a genuine email from your bank or an online shop in your own inbox. Which domain do SPF, DKIM and DMARC pass for, and does it match the From address?
Check your answer
For a genuine email you should see spf=pass, dkim=pass and dmarc=pass, with header.from= equal to the company's real domain (the part after @ in From). The DKIM header.d= may be the company or its mail provider, but DMARC passing for the From domain is the key signal.
Samjla ka? Sender, Links, Attachments, Pressure, then verify and report. Aata pudhe jaauya: Chapter 28 collects evidence like a forensic analyst.