Detection Method: Header analysis

Header analysis inspects the metadata in message headers to find suspicious patterns, anomalies, or inconsistencies that could indicate phishing, spoofing, or other types of malicious activity. It looks at various header fields like routing information, authentication results, and sender verification data to help spot potential threats.
This includes sender authentication headers like SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) results to verify the sender's legitimacy. It also checks how the email traveled through mail servers, looking for any unusual routing that might suggest tampering.
Header analysis can detect:
  • Email spoofing, where attackers forge the sender’s address to appear legitimate
  • Mismatched or inconsistent sender details
  • Suspicious return paths that don’t match the expected sender
  • Unusual routing patterns that stand out from normal email flow
  • Authentication failures that signal potential impersonation attempts
For example, attackers might try to forge email headers to make phishing emails appear as if they’re coming from a trusted source like your bank or your company’s internal email. Header analysis helps you catch these attempts by identifying mismatches between the displayed sender and the actual sending server.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS voicemail lure with suspicious link
1h ago
Sep 16th, 2026
Sublime Security
Suspicious message with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Suspicious attachment with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Link: Possible Intuit link abuse
22h ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Kroger
1d ago
Sep 15th, 2026
Sublime Security
Brand impersonation: Wix
1d ago
Sep 15th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
1d ago
Sep 15th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
1d ago
Sep 15th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
2d ago
Sep 14th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
2d ago
Sep 14th, 2026
Sublime Security
Brand impersonation: Netflix
5d ago
Sep 11th, 2026
min0k
Brand impersonation: Survey request with credential theft indicators
5d ago
Sep 11th, 2026
Sublime Security
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
5d ago
Sep 11th, 2026
Sublime Security
Link: Fake Cloudflare verification landing page
5d ago
Sep 11th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
5d ago
Sep 11th, 2026
Sublime Security
Brand impersonation: Google Drive fake file share
6d ago
Sep 10th, 2026
Sublime Security
Attachment: ICS calendar invite with photo/file share lure
7d ago
Sep 9th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
8d ago
Sep 8th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
8d ago
Sep 8th, 2026
Sublime Security