Course

Phishing Email Triage: From Message Evidence to Containment

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Intermediate
Modules 3
Lessons 6
Time 4 hr 35 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
Phishing Email TriageAn evidence path connects message preservation, authentication, content analysis, scoping, and containment.PRACTICAL SECURITY OPERATIONSPhishing Email TriageMessageIdentityContentScopeEVIDENCE → REASONING → DEFENSIBLE ACTION

About this course

Built for service-desk responders, SOC analysts, and security generalists who handle suspicious messages, this course teaches a repeatable investigation that starts with preserved evidence and ends with proportionate action. Learners examine sender identities, Received fields, SPF, DKIM, DMARC, URLs, attachments, delivery scope, and user interaction without treating any single signal as a verdict. The course emphasizes safe handling, evidence limits, escalation boundaries, and concise case notes. Completion means the learner can triage a reported message, explain what the evidence proves and does not prove, identify affected recipients and interactions, and recommend containment without live-clicking attacker content or overstating confidence.

What you'll learn

  • ✓ Preserve and inspect a suspicious message without activating links, attachments, or remote content.
  • ✓ Interpret routing, identity, SPF, DKIM, and DMARC evidence without confusing authentication with harmlessness.
  • ✓ Evaluate URLs and attachments using controlled analysis boundaries and corroborating evidence.
  • ✓ Scope recipients and interactions, select a defensible disposition, and document proportionate containment.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic email and security operations familiarity — Learners should recognize common email fields and understand that security tools produce signals that require analyst interpretation. Administrative access to a mail platform is helpful but not required.

Course content

Keep building