Guide
How to check a suspicious email for phishing
Gut feel is not a process. Use the sender domain, mail routing, and message patterns to decide whether to click, forward, or escalate—then document what you found.
Educational risk-check tool — not a mailbox scanner or a guarantee against phishing.
Research demo
A one-minute walkthrough from an early research build — how a risk check looks end to end. one-minute walkthrough.
Why a structured check beats a quick glance
Lookalike domains, urgent payment asks, and familiar logos are designed to short-circuit judgment. A short checklist—sender, domain evidence, content indicators, and a clear risk call—gives you something you can explain to a colleague or security team.
What to inspect on a suspicious email
1. Sender address and display name
Compare the visible name to the actual address. Brand impersonation often uses a trusted display name with a lookalike or unrelated domain.
2. Domain and mail infrastructure
Check how the domain is set up to send mail (MX), what it resolves to, and whether registration or hosting looks new or mismatched for the claimed brand.
3. Message pressure and links
Urgency, secrecy, credential asks, and links that do not match the claimed destination are classic phishing indicators—even when the prose looks polished.
4. A decision you can hand off
Record risk level, why you think so, and what you recommend (delete, quarantine, notify IT, or report). Risk|Tracker can generate audience-ready write-ups when you need them.
How to run this check in Risk|Tracker
- 01
Open a risk check
Go to the Email risk check workspace and start a new check.
- 02
Enter the sender address
Paste the From address. Optionally add the email body or a screenshot.
- 03
Review the domain canvas
Inspect DNS-related nodes and follow-up questions on the interactive map.
- 04
Read the risk call
Use the risk level, confidence, and phishing indicators to decide what to do next—and generate a report if you need to escalate.
Common questions
How do I check if a suspicious email is phishing?
Start with the sender address and domain. Look up how mail routes (MX), what hosts the domain resolves to, and whether the message shows common phishing indicators such as urgency, lookalike brands, or mismatched links. Risk|Tracker turns that into a structured risk check with a risk level you can explain.
What does Risk|Tracker analyze?
Risk|Tracker maps the sender domain on an interactive canvas, enriches DNS and related signals, surfaces phishing indicators, and can produce audience-ready reports. It is an educational risk-check tool—not a mailbox scanner.
Is Risk|Tracker a guarantee that an email is safe or malicious?
No. Phishing detection is probabilistic. Use the risk call as decision support alongside your organization’s policies—not as a sole authority.
Do I need to install software or connect my inbox?
No. Open the app, enter a sender address, and optionally paste the message body or upload a screenshot. Nothing connects to your mailbox.
When should I save a check to the Threat catalog?
Save high or critical risk checks so shared infrastructure fingerprints (such as MX or IP signals) can help spot related lookalikes later.