← All posts post

How I Work a Phishing Case

PhishingOctober 2026 · 1 min read

21 seconds.

That's the median time between someone opening a phishing email and clicking the link, in the simulation data behind Verizon's 2024 DBIR. Another 28 seconds and they've entered their data.

Under a minute for the user. Hours or days for the investigation. Here's how I actually work a phishing case:

  1. Read the headers like witness statements. Return-Path vs. From: who the envelope says sent it vs. who the message claims sent it. Then SPF, DKIM, DMARC and composite auth: which checks passed, which failed, and whether the domains actually align.
  2. Walk the path hop by hop. Received headers, bottom to top. Where it entered, what touched it, and where something doesn't add up.
  3. Pull the message trace. Who else got it. What the filter decided. What happened at delivery.
  4. Follow the click. Sign-in logs. New inbox rules. New app consents. Sessions from places that make no sense. This is where "a phishing email" becomes "a compromised account."
  5. Answer the question nobody wants to ask: why did our controls let it through?

Step 5 is where the real work lives. Anyone can say an email was bad. The job is proving exactly how it got in.

Sources

  1. Verizon 2024 Data Breach Investigations Report (PDF)