Email Basics
Start here if you want the plain-language version of what a raw message is, what headers do, what an IP address is, and how email normally moves.
Info
EmailIntel's info section explains how email messages work, how phishing and spoofing show up in practice, and why the analyzer flags certain senders, links, routes, and authentication results.
Use these pages when you want the plain-language version of a technical term, a phishing pattern, or a message clue that showed up during analysis.
The library covers the basics of email, sender identity, routing, authentication, phishing tactics, link and attachment risks, and the reasoning behind EmailIntel's rule hits.
If you are new to email analysis, do not start with the deepest edge case. Start with the broader pages first, then use the topic pages to drill into one term at a time.
Start here if you want the plain-language version of what a raw message is, what headers do, what an IP address is, and how email normally moves.
Use this when you want to understand origin systems, recipient gateways, internal relays, and how to read route hops without over-weighting noise.
Use this when you want the plain-language explanation of visible senders, envelope senders, reply paths, and why they do not always match.
Use this when you want to understand how EmailIntel scores messages and why rule hits should be interpreted as evidence rather than magic truth.
Use this when you want the user-facing safety guide: fake logins, QR phishing, sender tricks, link tricks, and what to check before acting.
These guides explain what email authentication checks do, what they do not do, and why pass does not automatically mean safe.
how SPF or DKIM must line up with the visible sender
how pass, fail, none, and unknown should be read in context
how signatures prove domain control and message integrity
how visible-sender alignment is enforced
how sender IP authorization works for the envelope sender
These guides explain how concrete artifacts become searchable evidence and how enrichment adds outside context.
how file and message fingerprints support hunting and matching
how curated indicators differ from raw observables
how IPs, domains, URLs, and hashes become pivot points
how outside context strengthens or weakens a finding
These guides explain why some noisy messages are still legitimate and how to weigh context carefully.
how bulk-mail behavior can look noisy without being malicious
how over-triggering rules burns trust and hides the real risk
These guides explain how attachments work, why file handling matters, and what kinds of mismatches raise suspicion.
how declared content types influence handling and trust
how payloads hide in archives, documents, or scripts
how content-type mismatches reveal disguise or error
how files can be risky even when they do not look executable
These are the grounding guides. They explain what an email actually is before you even start deciding whether it is safe or dangerous.
how metadata explains sender claims, route details, and auth results
why raw message files preserve the evidence investigators need
how unique message identifiers help with search, correlation, and triage
what the message actually contains beyond the inbox preview
how raw source reveals HTML, MIME structure, and hidden links
These guides explain how one message can carry several sender identities at the same time, and why attackers abuse that gap.
how replies can be routed somewhere different from the visible sender
how bounce paths expose the transport sender identity
how attackers abuse friendly names to survive a glance test
how the envelope-level sender differs from the visible author
how the visible author identity differs from the transport path
how the transport sender drives SPF and bounce handling
how the display sender shapes trust but can be misleading
These guides focus on how mail actually moves between systems and which route clues matter most during analysis.
how presented hostnames expose the sending system
how numeric network addresses support route and intel analysis
how dotted decimal addresses still dominate reputation workflows
how modern providers route mail over newer long-form addresses
how recipient-side relays add context but not attacker control
how receiving infrastructure is published for a domain
how each handoff tells part of the delivery story
how the transport protocol carries sender and route identities
how recipient-side providers shape the later route hops
how inbound filtering marks the receiver-side boundary
how to read the short version without confusing origin and relay noise
how the public sending IP anchors route and blacklist logic
These guides focus on where the email is trying to send the user and how redirects, tracking, and deception affect that journey.
how first-click domains can hide the real destination
how click-tracking links add context and confusion
how remote images record opens and campaign activity
how parameters hide redirects, tokens, and tracking data
how the full address matters more than the label people see
how the real target matters more than the visible sender story
These guides explain domains, subdomains, hosts, and naming tricks that can make something look familiar while still being wrong.
how domains anchor sender and link analysis
how full hostnames expose specific systems or services
how ownership-level comparison reduces false positives
how long hostnames can hide the real ownership boundary
how a domain ending adds context but not a verdict by itself
These guides focus on the lure itself: urgency, fake workflows, trust abuse, login theft, and impersonation.
how a phone scan replaces the suspicious click
how polished sign-in pages still steal credentials
how stolen credentials become long-term access
how a familiar company name is used as a trust shortcut
how payment and authority fraud often works without malware
how parcel lures create low-friction urgency
how deceptive characters make one domain resemble another
how fake billing workflows push attachments and payments
how near-brand domains abuse fast reading
how fear, trust, urgency, and authority drive bad decisions
These guides explain why rule-based detections exist and how to interpret them instead of overreacting to a single signal.
how reputation listings add context but still need judgment
how several medium clues together can outweigh one isolated clue