Detection Method: Header analysis

Header analysis inspects the metadata in message headers to find suspicious patterns, anomalies, or inconsistencies that could indicate phishing, spoofing, or other types of malicious activity. It looks at various header fields like routing information, authentication results, and sender verification data to help spot potential threats.
This includes sender authentication headers like SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) results to verify the sender's legitimacy. It also checks how the email traveled through mail servers, looking for any unusual routing that might suggest tampering.
Header analysis can detect:
  • Email spoofing, where attackers forge the sender’s address to appear legitimate
  • Mismatched or inconsistent sender details
  • Suspicious return paths that don’t match the expected sender
  • Unusual routing patterns that stand out from normal email flow
  • Authentication failures that signal potential impersonation attempts
For example, attackers might try to forge email headers to make phishing emails appear as if they’re coming from a trusted source like your bank or your company’s internal email. Header analysis helps you catch these attempts by identifying mismatches between the displayed sender and the actual sending server.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: SoFi
13h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
13h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Amazon
23h ago
Aug 6th, 2026
Sublime Security
BEC: Tax document request
23h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
2d ago
Aug 5th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
2d ago
Aug 5th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
2d ago
Aug 5th, 2026
Sublime Security
AnonymousFox indicators
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
Brand Impersonation: Google (QR Code)
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: Okta
3d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: SiriusXM
3d ago
Aug 4th, 2026
Sublime Security
Credential phishing: Financial lure via ActiveCampaign infrastructure
3d ago
Aug 4th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
4d ago
Aug 3rd, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
4d ago
Aug 3rd, 2026
Sublime Security
Service abuse: SendGrid impersonation via Sendgrid from new sender
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Robinhood
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: LinkedIn
4d ago
Aug 3rd, 2026
Sublime Security
Brand impersonation: Canada Revenue Agency
6d ago
Aug 1st, 2026
Sublime Security