Detection Method: Header analysis

Header analysis inspects the metadata in message headers to find suspicious patterns, anomalies, or inconsistencies that could indicate phishing, spoofing, or other types of malicious activity. It looks at various header fields like routing information, authentication results, and sender verification data to help spot potential threats.
This includes sender authentication headers like SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) results to verify the sender's legitimacy. It also checks how the email traveled through mail servers, looking for any unusual routing that might suggest tampering.
Header analysis can detect:
  • Email spoofing, where attackers forge the sender’s address to appear legitimate
  • Mismatched or inconsistent sender details
  • Suspicious return paths that don’t match the expected sender
  • Unusual routing patterns that stand out from normal email flow
  • Authentication failures that signal potential impersonation attempts
For example, attackers might try to forge email headers to make phishing emails appear as if they’re coming from a trusted source like your bank or your company’s internal email. Header analysis helps you catch these attempts by identifying mismatches between the displayed sender and the actual sending server.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
1d ago
May 29th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
1d ago
May 29th, 2026
Sublime Security
Reconnaissance: Short generic greeting message
1d ago
May 29th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
1d ago
May 29th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
1d ago
May 29th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
1d ago
May 29th, 2026
Sublime Security
Service Abuse: HelloSign share with suspicious sender or document name
2d ago
May 28th, 2026
Sublime Security
Link: Self-sender credential theft with configuration placeholder
3d ago
May 27th, 2026
Sublime Security
Observed IOC: Malicious sender domains
3d ago
May 27th, 2026
Sublime Security
Brand impersonation: DHL
4d ago
May 26th, 2026
Sublime Security
Brand impersonation: Dashlane
4d ago
May 26th, 2026
Sublime Security
Credential phishing: Onedrive impersonation
4d ago
May 26th, 2026
Sublime Security
Brand Impersonation: PayPal
9d ago
May 21st, 2026
Sublime Security
Headers: X-Source-Auth mismatch with mismatched reply-to domain
9d ago
May 21st, 2026
Sublime Security
Impersonation: Legal firm with copyright infringement notice
9d ago
May 21st, 2026
Sublime Security
Brand impersonation: Quickbooks
10d ago
May 20th, 2026
Sublime Security
Extortion / sextortion (untrusted sender)
10d ago
May 20th, 2026
Sublime Security
Brand impersonation: Robinhood
11d ago
May 19th, 2026
Sublime Security
Fake thread with suspicious indicators
11d ago
May 19th, 2026
Sublime Security
Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
12d ago
May 18th, 2026
Sublime Security