Cyber Security Labs (Beginner → Advanced)

Lesson 2 of 6

Lab 2 — Phishing Forensics

Read raw email headers, unpick lookalike domains and score a suspicious message like a SOC analyst.

🟢 Beginner 80 XP

Learn it

Phishing is a fake message designed to make you click, log in, or pay — fast, before you think.

Almost every phish leaks clues: an odd sender address, a link that does not match the words on screen, urgency and threats.

Hovering a link (or long-pressing on mobile) shows where it really goes. The bit just before the first single slash is the real domain.

Key terms

SPF
Sender Policy Framework — a DNS record listing which mail servers may send for a domain.
DKIM
DomainKeys Identified Mail — a cryptographic signature proving the message was not altered and came from the domain.
DMARC
A policy telling receivers to quarantine or reject mail that fails SPF and DKIM alignment.
Homoglyph
A character from another alphabet that looks identical to a Latin letter, used to fake domains.
Spear phishing
A targeted phish using real details about you, your school or your role.

Analyse a real-looking header

Work top to bottom through the evidence in this message and give it a risk score.

  1. 11. From: From: "IT Helpdesk" <it-support@sch00l-portal-secure.com> — the display name is friendly, the domain is not the school's.
  2. 22. Return-Path: Return-Path: bounce@mailer-73.ru — bounces go somewhere completely different. Alignment failure.
  3. 33. Authentication-Results: spf=fail dkim=none dmarc=fail — the domain owner never authorised this server.
  4. 44. The link: The text says https://portal.school.edu but the href is https://sch00l-portal-secure.com/login?u=tmurphy — the real domain is before the first single slash.
  5. 55. The pressure: 'Your account will be deleted within 4 hours.' Urgency plus a deadline is the classic social-engineering lever.
  6. 66. Verdict: Six indicators. Report it, do not click, and warn colleagues — spear phishing arrives in waves.

Extracting the true domain from a URL

pythonfrom urllib.parse import urlparse

links = [
    "https://portal.school.edu.sch00l-portal-secure.com/login",
    "https://school.edu/login",
    "http://192.168.44.9/portal/login",
]

for url in links:
    host = urlparse(url).hostname or ""
    registrable = ".".join(host.split(".")[-2:])
    print(host, "->", registrable)

Only the last two labels of the hostname matter. Everything to the left can be faked by the attacker.

Sandbox lab

Practise the real technique in a fully simulated environment — no live systems, no real data, nothing leaves your browser.

AI phishing simulator

Pick a difficulty. Harder lures are worth more XP per correct call.

Safe simulation

Try it

Analyst triage: genuine message, or phish?

From: no-reply@accounts.google.com — 'A new sign-in on Windows. If this was you, no action is needed.' No link required to act.

From: Netflix <billing@netflix-account-verify.net> — 'Payment failed. Update your card in 24 hours or lose your account.'

From: your headteacher's real address — 'Hi, I'm in a meeting. Can you buy 4 × £50 gift cards and send me the codes? I'll reimburse you.'

From: security@paypal.com with the link text paypal.com pointing to https://paypal.com.secure-id.co/login

From: noreply@github.com — 'A new SSH key was added to your account', listing the fingerprint and the account settings page.

Challenge

Write a one-page phishing triage report for the fake IT Helpdesk email in the Explore section. List each indicator, the evidence for it, and a risk score out of 10. Finish with three actions the school should take in the next hour.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/7 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.
  4. Clue 4 locked — reveal it only if you get stuck.
  5. Clue 5 locked — reveal it only if you get stuck.
  6. Clue 6 locked — reveal it only if you get stuck.
  7. Clue 7 locked — reveal it only if you get stuck.

Each clue costs 4 XP (never below 20 XP). You'd earn 40 XP right now.

Extension: Write the 60-word warning message you would send to all staff — without naming the person who was targeted.

Quiz time

Question 1 of 4Score 0

What does DMARC actually do?