Alignment: LO1 / A1 Objective: Inspect a simulated phishing message without opening its link or attachment.
Use only the simulated data supplied in this folder. Do not test live suspicious links, accounts, phone numbers or payment routes.
- Work only from the supplied offline email sample and URL text file.
- Compare the display name with the From and Reply-To domains.
- Read Received hops from bottom to top and identify the first untrusted handoff.
- Check SPF, DKIM and DMARC results recorded in Authentication-Results.
- Decompose the URL into scheme, host, registrable domain, path and query.
- Flag punycode, look-alike characters, subdomain deception and redirect parameters.
- Write an independent verification route using a known bookmark or official directory.
- Capture the findings in the evidence template and assign a disposition.
Annotated header and URL decomposition with disposition.
The registrable domain and authentication result are stated correctly and no live suspect link is opened.
Which observable fact most changed your decision, and which uncertainty remains?