Detection Method: Header analysis

Header analysis inspects the metadata in message headers to find suspicious patterns, anomalies, or inconsistencies that could indicate phishing, spoofing, or other types of malicious activity. It looks at various header fields like routing information, authentication results, and sender verification data to help spot potential threats.
This includes sender authentication headers like SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) results to verify the sender's legitimacy. It also checks how the email traveled through mail servers, looking for any unusual routing that might suggest tampering.
Header analysis can detect:
  • Email spoofing, where attackers forge the sender’s address to appear legitimate
  • Mismatched or inconsistent sender details
  • Suspicious return paths that don’t match the expected sender
  • Unusual routing patterns that stand out from normal email flow
  • Authentication failures that signal potential impersonation attempts
For example, attackers might try to forge email headers to make phishing emails appear as if they’re coming from a trusted source like your bank or your company’s internal email. Header analysis helps you catch these attempts by identifying mismatches between the displayed sender and the actual sending server.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Robinhood
19m ago
Aug 27th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
19m ago
Aug 27th, 2026
Sublime Security
Attachment: ICS invite meeting lure
1h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: McAfee
1h ago
Aug 27th, 2026
Sublime Security
Link: Microsoft protected message with suspicious recipient patterns
2h ago
Aug 27th, 2026
Sublime Security
Service abuse: Kagoya.net-hosted domains sending English business lures
2h ago
Aug 27th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
2h ago
Aug 27th, 2026
Sublime Security
Brand impersonation: Microsoft with low reputation links
3h ago
Aug 27th, 2026
Sublime Security
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
1d ago
Aug 26th, 2026
Sublime Security
Link: Self-sender with sender org in subject and credential theft indicator
2d ago
Aug 25th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
2d ago
Aug 25th, 2026
Sublime Security
Attachment: Risk assessment PDF with inline image
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Automobile assistance associations
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Sedgwick Claims
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: AARP
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
2d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: United States Patent and Trademark Office
2d ago
Aug 25th, 2026
Sublime Security
Credential Phishing: Bitcoin portfolio confirmation
3d ago
Aug 24th, 2026
Sublime Security
VIP impersonation: Payment handoff with VIP display name authored fake threads
3d ago
Aug 24th, 2026
Sublime Security
Link: Credential phishing link with undisclosed recipients
3d ago
Aug 24th, 2026
Sublime Security