Info

Info

EmailIntel's info section explains how email messages work, how phishing and spoofing show up in practice, and why the analyzer flags certain senders, links, routes, and authentication results.

What You Will Find Here

Use these pages when you want the plain-language version of a technical term, a phishing pattern, or a message clue that showed up during analysis.

The library covers the basics of email, sender identity, routing, authentication, phishing tactics, link and attachment risks, and the reasoning behind EmailIntel's rule hits.

Start Here

If you are new to email analysis, do not start with the deepest edge case. Start with the broader pages first, then use the topic pages to drill into one term at a time.

Email Basics

Start here if you want the plain-language version of what a raw message is, what headers do, what an IP address is, and how email normally moves.

Routing

Use this when you want to understand origin systems, recipient gateways, internal relays, and how to read route hops without over-weighting noise.

P1 / P2 Senders

Use this when you want the plain-language explanation of visible senders, envelope senders, reply paths, and why they do not always match.

Rules Explained

Use this when you want to understand how EmailIntel scores messages and why rule hits should be interpreted as evidence rather than magic truth.

Phishing

Use this when you want the user-facing safety guide: fake logins, QR phishing, sender tricks, link tricks, and what to check before acting.

Authentication

These guides explain what email authentication checks do, what they do not do, and why pass does not automatically mean safe.

Evidence and Intel

These guides explain how concrete artifacts become searchable evidence and how enrichment adds outside context.

What Hashes Are

how file and message fingerprints support hunting and matching

False Positives and Context

These guides explain why some noisy messages are still legitimate and how to weigh context carefully.

Files and Attachments

These guides explain how attachments work, why file handling matters, and what kinds of mismatches raise suspicion.

Foundations

These are the grounding guides. They explain what an email actually is before you even start deciding whether it is safe or dangerous.

Identity

These guides explain how one message can carry several sender identities at the same time, and why attackers abuse that gap.

Infrastructure

These guides focus on how mail actually moves between systems and which route clues matter most during analysis.

What IPv4 Means

how dotted decimal addresses still dominate reputation workflows

What IPv6 Means

how modern providers route mail over newer long-form addresses

What SMTP Is

how the transport protocol carries sender and route identities

Links and Web Tricks

These guides focus on where the email is trying to send the user and how redirects, tracking, and deception affect that journey.

What a URL Is

how the full address matters more than the label people see

Names and Addresses

These guides explain domains, subdomains, hosts, and naming tricks that can make something look familiar while still being wrong.

Phishing and Fraud

These guides focus on the lure itself: urgency, fake workflows, trust abuse, login theft, and impersonation.

Rule Explanations

These guides explain why rule-based detections exist and how to interpret them instead of overreacting to a single signal.