Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Spot the Phish: Check the Sender, Links and Headers of 5 Sample Emails and Report One Correctly

Beginner30 minText editor (Notepad or TextEdit) · Gmail or Outlook (your own account) · Sample file phish_samples.txt

Course: Cyber Security · Chapter 27: Social Engineering Awareness

Chapter 27 explains social engineering; this lab trains your eyes on the email clues that give phishing away.

Download phish_samples.txt (5 sample emails)

Chala mitrano! Most attacks still start with one email and one click. The good news: phishing emails leave clues, and once you know where to look, you will spot them in seconds. Today we read 5 sample emails like a SOC analyst: sender, reply-to, headers, links, and the feeling of urgency. Chala, detective banuya!

Suppose we are…

Suppose we have joined the security awareness team at Wipro. Employees forward suspicious emails to us every day. Some are real phishing, some are genuine notices that just look odd. We practise on 5 sample emails that imitate common Indian scams (KYC, delivery fee, CEO gift cards, tax refund) plus one genuine IT notice. All addresses use reserved .example domains, so nothing in the file is real.

Goal of this lab

By the end you will be able to:

  • Read the From, Reply-To, Return-Path and Authentication-Results (SPF, DKIM, DMARC) lines of an email.
  • Spot mismatched link targets, urgency and requests for money, OTPs or gift cards.
  • Mark each email Safe or Phish with a reason, and know how to report a phish correctly.

What you need (all free)

  • The sample file below, opened in Notepad or TextEdit.
  • Your own Gmail or Outlook account (only to find the menus, not to send anything).
  • About 30 minutes.

Download phish_samples.txt

Safety and ethics

Do not visit any link in the samples, and never click links in real suspicious emails. Do not forward phishing emails to friends "as a joke", and never send a phishing test to anyone without written permission from your organisation.

Steps

  1. Open phish_samples.txt. Make a table with columns Email, From (display name + address), Reply-To, SPF/DKIM/DMARC, Link target, Pressure or request, Verdict, Reason.
  2. Email 1. Compare the From address with the Return-Path and Reply-To.

    What you should see: From says alerts@sbi.co.in, but Reply-To and Return-Path are sbi-kyc-update.example, and dmarc=fail for header.from=sbi.co.in. The real domain did not send it.

  3. Look at the link text vs its real target (shown in < >). "Update KYC" points to http://sbi-kyc-update.example/..., not the bank's site, and uses plain HTTP. Add "account blocked within 24 hours" as pressure.

  4. Email 2. Check the same lines.

    What you should see: SPF, DKIM and DMARC all pass for the company's own domain, the link stays on the company intranet, and it asks for no action, no password and no money. Verdict: Safe.

  5. Email 3. Notice that SPF and DKIM pass, but for amazon-in-delivery.example, a look-alike domain the scammer owns. Passing checks only prove who sent it, not that the sender is honest. The small "Rs 25 fee" is the hook to collect card details.

  6. Email 4. No link at all. Read the request: gift cards, urgency, secrecy, a personal webmail address for a "CEO". This is business email compromise (BEC). Verdict: Phish, verify by calling the person on a known number.
  7. Email 5. From claims incometax.gov.in but dmarc=fail and spf=softfail; it has an .html attachment that asks for net-banking details and an OTP. The real department never asks for an OTP.
  8. Fill in the Verdict column for all five, then compare with the answer below.

    Check your answer

    1 Phish (spoofed bank, DMARC fail, look-alike link, urgency). 2 Safe (all checks pass for the real domain, no request). 3 Phish (look-alike domain, small fee to steal card details). 4 Phish (BEC: gift cards, secrecy, webmail "CEO"). 5 Phish (spoofed government domain, DMARC fail, HTML attachment asking for OTP).

  9. Learn how to see these headers in a real email (do this on any email in your own inbox): Gmail → open the email → ⋮ (More) → Show original. Outlook.com → … → View → View message source.

    What you should see: the same Authentication-Results line with spf=, dkim= and dmarc= values.

  10. Learn how to report correctly (find the menu, do not click on a real email unless it really is phishing): Gmail → ⋮ → Report phishing. Outlook → Report → Report phishing. At work, use the "Report phish" button or forward as an attachment to your security team. If money was lost in India, call 1930 immediately (Chapter 34).

Ravindra Bagale's Tip

Remember "SLAP": Sender, Links, Attachments, Pressure. If any one of these feels wrong, stop and verify through another channel: the official app, the number on your card, a call to your manager. Ek phone call, khup paise vachavto!

Common mistakes

Mistake What happens Fix
Trusting the display name ("SBI KYC Team") Anyone can type any display name Read the actual address and domain
Thinking "SPF pass" means safe Scammers pass SPF for their own look-alike domains Check which domain passed
Hovering on mobile is impossible, so clicking to "check" You land on the phishing page Long-press to preview the link, or don't open it at all
Replying to ask "is this real?" The reply goes to the scammer (Reply-To) Verify through an official channel
Deleting a work phish without reporting Colleagues get the same email Use Report phishing so the team can block it

Self-check checklist

0 of 5 done

Try-at-home challenge

Open Show original on a genuine email from your bank or an online shop in your own inbox. Which domain do SPF, DKIM and DMARC pass for, and does it match the From address?

Check your answer

For a genuine email you should see spf=pass, dkim=pass and dmarc=pass, with header.from= equal to the company's real domain (the part after @ in From). The DKIM header.d= may be the company or its mail provider, but DMARC passing for the From domain is the key signal.

Samjla ka? Sender, Links, Attachments, Pressure, then verify and report. Aata pudhe jaauya: Chapter 28 collects evidence like a forensic analyst.