Phish Focus : Header Parsing

This article takes you through Header Parsing, a new feature within our Phish Focus solution.

Benefits of this feature to Security Team and / or Phriendly Phishing Company Administrator

  1. Admins can inspect the header of the messages that was sent though to Phish Focus.
  2. Admins can do a header search and identify matches via the search bar added at the top of the Header information. Matches in the header record are highlighted.
  3. Admins can view suspected issues with DMARC, SPF and DKIM records. These are highlighted. 

This articles answers below questions:

  1. Where can I find the HEADER tab in Phish Focus?
  2. How can I search for characters in the header to identify matches?
  3. Where can I find the Delivery Information ummary: DMARC, SPF and DKIM possible issues?
  4. How does Header Inspection work?

Where can I find the HEADER tab in Phish Focus?

  • Click Inbox and choose a message.
  • Click HEADER

How can I search for characters in the header to identify matches?

  • Click Inbox and choose a message.
  • Click HEADER
  • Scroll down to Header Content

Where can I find the Delivery Information summary: DMARC, SPF and DKIM possible issues?

  • Click Inbox and choose a message.
  • Click HEADER
  • Under Delivery Information, click View Detail

How does Header Inspection work?

To scan DMARC, DKIM and SPF information, we have built a system that operates based on an Email Header Analyser. Refer to below scenarios:

  • For new emails reported and sent to Phish Focus > The tool analyses the header in real time.
  • For existing emails > The tool analyses the header in real time when email is opened
  • Header analysis results are not stored in database

 

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.