B14.3 Phishing and Email Triage Lab
Practice reviewing fictional sender details, message wording, domains, links, attachments, headers, business context, and safe reporting decisions without interacting with suspicious content.
Lesson Progress
Phishing and Email Triage Lab
High School Beginner • B14: Beginner Defensive Practice Labs • Lesson 3 of 7
Readiness Check
Before You Start
0/3 ready
Professional Hook
The Safest Email Investigation Often Begins by Not Clicking
Defenders can learn a great deal from sender details, wording, timing, domain differences, link mismatches, attachment names, headers, and business context without opening suspicious content.
Learning Objective
Explain phishing, email triage, display-name spoofing, link mismatches, attachment warnings, and evidence preservation.
Learning Objective
Analyze fictional sender, message, link, file, header, and business-context evidence.
Learning Objective
Choose safe reporting, verification, warning, blocking, and escalation actions.
Why This Matters
One Message Can Target Accounts, Money, Data, Devices, and Trust
Phishing can imitate teachers, managers, vendors, banks, support teams, delivery companies, or friends. Strong triage protects the recipient while preserving the evidence needed to protect others.
Visual Diagram
The Safe Email-Triage Workflow
Defensive email review protects the user, preserves evidence, and avoids interacting with suspicious content.
Preserve the message
Do not reply, forward casually, open attachments, or click links. Keep the original report and timestamps.
Inspect safely
Review sender details, wording, domain, link text, attachment name, headers, and known business context.
Assess the evidence
Separate confirmed indicators from assumptions and identify what still needs verification.
Report and respond
Use approved reporting channels, warn affected users when authorized, and escalate according to policy.
Core Concept
No Single Indicator Proves a Message Is Safe or Malicious
Defenders compare multiple clues: actual sender address, domain, wording, urgency, request type, link destination, attachment, timing, headers, prior conversation, and normal business procedure.
Key Vocabulary
Terms for Phishing and Email Triage
Phishing
A deceptive message designed to pressure someone into revealing information, opening unsafe content, sending money, or taking another harmful action.
Email triage
The structured review of a reported message to decide its priority, evidence, likely risk, and safest next action.
Display name
The visible sender name shown by an email client, which may not match the real sending address.
Link mismatch
A difference between the visible link text and the actual destination shown through safe inspection.
Attachment warning
An indicator that a file type, filename, source, or delivery method may require additional caution.
Preservation
Keeping the original message, headers, timestamps, and related evidence unchanged for authorized review.
Email Review
Phishing Decision Board
Strong triage considers the sender, message, links, files, context, reporting path, and evidence together.
Sender
Review question
Does the actual address and domain match the person or organization being represented?
Strong defensive action
Check the full address, spelling, domain, reply address, and known contact method.
Message
Review question
Does the message use urgency, fear, secrecy, unusual wording, or an unexpected request?
Strong defensive action
Compare the request with normal procedures and verify independently.
Links and files
Review question
Are links mismatched, shortened, unfamiliar, or connected to unexpected attachments?
Strong defensive action
Do not click or open them; use approved inspection and reporting methods.
Response
Review question
Which reporting, warning, blocking, verification, or escalation step is authorized?
Strong defensive action
Use the approved channel, preserve evidence, and document the decision.
Fake Email Dashboard
Message Triage Review
This fictional panel compares sender details, message context, suspicious indicators, and safe defensive actions.
Payroll update request
Urgent message from a look-alike domain asking for bank details
High concern. Preserve the message, report it, verify through a trusted channel, and do not use the embedded link.
Shared document notice
Unexpected attachment with a generic filename and no prior context
Investigate safely. Do not open the file; confirm with the supposed sender through a separate channel.
Password expiration warning
Message threatens account closure and links to a mismatched domain
Likely phishing. Use the official portal directly rather than the message link.
Known vendor invoice
Expected invoice from the correct address and documented purchase
Lower concern, but still verify amount, attachment type, and business context before processing.
School event reminder
Expected announcement from the official domain with no attachment or login request
Likely legitimate, but preserve normal caution and avoid unnecessary data sharing.
Fake Dashboard
Fake Phishing Triage Dashboard
Training dashboard using fictional messages, senders, domains, links, attachments, headers, reports, and response decisions.
Messages reviewed
36
Fictional payroll, password, invoice, document-sharing, support, and school messages.
Messages escalated
9
Look-alike domains, suspicious attachments, mismatched links, and credential requests.
Legitimate messages
21
Expected messages verified through trusted context and official procedures.
Fake SOC Alert
Urgent Payroll Message Uses a Look-Alike Domain
Source: Fake Email Security Monitor • Time: 1:22 PM
Fake Log Panel
Fake Email Triage Log
12:48:03 REPORT user='teacher_12' subject='urgent_payroll_update' 12:51:17 SENDER display='Payroll Office' domain='payro11-example.test' 12:55:44 MESSAGE urgency='high' secrecy='requested' deadline='30_minutes' 13:02:11 LINK visible='Official Payroll Portal' destination='mismatch' 13:08:26 ATTACHMENT present='false' credential_request='true' 13:15:39 CONTEXT payroll_campaign='none' official_notice='none' 13:22:04 DECISION preserve='true' escalate='email_security'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
How Should This Message Be Handled?
What is the safest response?
Common Mistakes
Mistakes That Increase Email Risk
Safe Practice Lab
Triage a Fictional Email Queue
Fake Message Queue
Community Learning Portal Mailbox
A fictional queue includes payroll, shared-document, password, vendor-invoice, event-reminder, delivery, and support messages with different evidence and business context.
Triage Steps
- Preserve the original message and report details.
- Review the display name, full address, domain, and reply address.
- Identify urgency, secrecy, payment, credential, or data requests.
- Inspect provided link and attachment metadata safely.
- Compare the request with normal business procedures.
- Choose report, verify, block, warn, monitor, or close.
Scenario Decision Lab
An Unexpected Attachment Comes From a Familiar Display Name
A fictional message appears to come from a teacher but contains an unexpected file and a short message saying, 'Open this now.'
Scenario Decision Lab
A Password Warning Threatens Immediate Account Closure
A fictional message says the account will close in ten minutes unless the recipient signs in through an embedded link.
Defender Habits
Phishing and Email Triage Checklist
Check Your Understanding
B14.3 Mini Quiz: Phishing and Email Triage
Choose your answers first. Explanations appear only after submission.
1. What is email triage?
2. Why is the display name not enough to trust a sender?
3. What is the safest action for an unexpected attachment?
4. What should a user do with a suspicious password-reset link?
5. Why should the original message be preserved?
Portfolio Prompt
Portfolio Prompt
Create a one-page fictional email triage report. Include the sender display name, full address, domain, reply address, subject, request, urgency, link evidence, attachment evidence, business context, risk indicators, safe decision, reporting path, and final case notes.
Key Takeaways
What You Should Remember
Navigation