Attack Type: Reconnaissance

Reconnaissance attacks are quiet, early-stage probes used by attackers to learn about your organization before launching something more serious. These emails might seem harmless—or even blank—but they’re designed to test if your address is valid, see what gets through your filters, and check how your email system responds. Bounce-backs and out-of-office replies may also reveal information about your email gateway and routing configuration to inform future attacks.
You might get a message with no content, a vague subject line, or a blank body. Some use legitimate-looking headers and pass SPF, DKIM, and DMARC checks to stay under the radar. They typically don’t contain links or attachments, which makes them harder to catch with traditional security tools.
Attackers use this information to refine their future attacks, whether it’s phishing, malware, or BEC. By understanding what works and who responds, they can create more targeted campaigns that are harder to detect and more likely to succeed.