Detection Method: Header analysis

Header analysis inspects the metadata in message headers to find suspicious patterns, anomalies, or inconsistencies that could indicate phishing, spoofing, or other types of malicious activity. It looks at various header fields like routing information, authentication results, and sender verification data to help spot potential threats.
This includes sender authentication headers like SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) results to verify the sender's legitimacy. It also checks how the email traveled through mail servers, looking for any unusual routing that might suggest tampering.
Header analysis can detect:
  • Email spoofing, where attackers forge the sender’s address to appear legitimate
  • Mismatched or inconsistent sender details
  • Suspicious return paths that don’t match the expected sender
  • Unusual routing patterns that stand out from normal email flow
  • Authentication failures that signal potential impersonation attempts
For example, attackers might try to forge email headers to make phishing emails appear as if they’re coming from a trusted source like your bank or your company’s internal email. Header analysis helps you catch these attempts by identifying mismatches between the displayed sender and the actual sending server.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Open redirect: Quickbase
9m ago
Oct 6th, 2026
Sublime Security
BEC/Fraud: Fake investment outreach from suspicious TLD
38m ago
Oct 6th, 2026
Sublime Security
Spoofing: Hidden Outlook headers in self-addressed forwards
4h ago
Oct 6th, 2026
Sublime Security
Link: Observed URL path (lht) with recipient email address
5h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
6h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: Amazon
1d ago
Oct 5th, 2026
Sublime Security
Attachment: Fake email body embedded in inline image
1d ago
Oct 5th, 2026
Sublime Security
Link: Possible Intuit link abuse
1d ago
Oct 5th, 2026
Sublime Security
Evasion: Suspicious use of Unicode tag characters
2d ago
Oct 4th, 2026
Sublime Security
Attachment: Suspicious use of Unicode tag characters in ICS File
2d ago
Oct 4th, 2026
Sublime Security
Open redirect: EWeb logout redirect
4d ago
Oct 2nd, 2026
Sublime Security
Brand impersonation: Google Authenticator
4d ago
Oct 2nd, 2026
Sublime Security
Brand impersonation: DHL
5d ago
Oct 1st, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
5d ago
Oct 1st, 2026
Sublime Security
Brand Impersonation: PayPal
5d ago
Oct 1st, 2026
Sublime Security
Service abuse: Monday.com infrastructure with phishing intent
6d ago
Sep 30th, 2026
Sublime Security
Brand impersonation: QuickBooks
6d ago
Sep 30th, 2026
Sublime Security