High School BeginnerModule B14Lesson 3 of 7

B14.3 Phishing and Email Triage Lab

Practice reviewing fictional sender details, message wording, domains, links, attachments, headers, business context, and safe reporting decisions without interacting with suspicious content.

Lesson Progress

Phishing and Email Triage Lab

High School BeginnerB14: Beginner Defensive Practice Labs • Lesson 3 of 7

43% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

The Safest Email Investigation Often Begins by Not Clicking

Defenders can learn a great deal from sender details, wording, timing, domain differences, link mismatches, attachment names, headers, and business context without opening suspicious content.

Lab safety reminder: do not open attachments, visit links, reply to senders, enter credentials, or use real suspicious messages. Every example in this lesson is fictional and inert.

Learning Objective

Explain phishing, email triage, display-name spoofing, link mismatches, attachment warnings, and evidence preservation.

Learning Objective

Analyze fictional sender, message, link, file, header, and business-context evidence.

Learning Objective

Choose safe reporting, verification, warning, blocking, and escalation actions.

Why This Matters

One Message Can Target Accounts, Money, Data, Devices, and Trust

Phishing can imitate teachers, managers, vendors, banks, support teams, delivery companies, or friends. Strong triage protects the recipient while preserving the evidence needed to protect others.

Visual Diagram

The Safe Email-Triage Workflow

Defensive email review protects the user, preserves evidence, and avoids interacting with suspicious content.

1

Preserve the message

Do not reply, forward casually, open attachments, or click links. Keep the original report and timestamps.

2

Inspect safely

Review sender details, wording, domain, link text, attachment name, headers, and known business context.

3

Assess the evidence

Separate confirmed indicators from assumptions and identify what still needs verification.

4

Report and respond

Use approved reporting channels, warn affected users when authorized, and escalate according to policy.

Triage rule: investigate the message without interacting with its suspicious links, attachments, forms, or reply instructions.

Core Concept

No Single Indicator Proves a Message Is Safe or Malicious

Defenders compare multiple clues: actual sender address, domain, wording, urgency, request type, link destination, attachment, timing, headers, prior conversation, and normal business procedure.

Key Vocabulary

Terms for Phishing and Email Triage

Phishing

A deceptive message designed to pressure someone into revealing information, opening unsafe content, sending money, or taking another harmful action.

Email triage

The structured review of a reported message to decide its priority, evidence, likely risk, and safest next action.

Display name

The visible sender name shown by an email client, which may not match the real sending address.

Link mismatch

A difference between the visible link text and the actual destination shown through safe inspection.

Attachment warning

An indicator that a file type, filename, source, or delivery method may require additional caution.

Preservation

Keeping the original message, headers, timestamps, and related evidence unchanged for authorized review.

Email Review

Phishing Decision Board

Strong triage considers the sender, message, links, files, context, reporting path, and evidence together.

Sender

Review question

Does the actual address and domain match the person or organization being represented?

Strong defensive action

Check the full address, spelling, domain, reply address, and known contact method.

Message

Review question

Does the message use urgency, fear, secrecy, unusual wording, or an unexpected request?

Strong defensive action

Compare the request with normal procedures and verify independently.

Links and files

Review question

Are links mismatched, shortened, unfamiliar, or connected to unexpected attachments?

Strong defensive action

Do not click or open them; use approved inspection and reporting methods.

Response

Review question

Which reporting, warning, blocking, verification, or escalation step is authorized?

Strong defensive action

Use the approved channel, preserve evidence, and document the decision.

Fake Email Dashboard

Message Triage Review

This fictional panel compares sender details, message context, suspicious indicators, and safe defensive actions.

Fake Data

Payroll update request

Urgent message from a look-alike domain asking for bank details

High concern. Preserve the message, report it, verify through a trusted channel, and do not use the embedded link.

Shared document notice

Unexpected attachment with a generic filename and no prior context

Investigate safely. Do not open the file; confirm with the supposed sender through a separate channel.

Password expiration warning

Message threatens account closure and links to a mismatched domain

Likely phishing. Use the official portal directly rather than the message link.

Known vendor invoice

Expected invoice from the correct address and documented purchase

Lower concern, but still verify amount, attachment type, and business context before processing.

School event reminder

Expected announcement from the official domain with no attachment or login request

Likely legitimate, but preserve normal caution and avoid unnecessary data sharing.

Fake Dashboard

Fake Phishing Triage Dashboard

Training dashboard using fictional messages, senders, domains, links, attachments, headers, reports, and response decisions.

Messages reviewed

36

Fictional payroll, password, invoice, document-sharing, support, and school messages.

Messages escalated

9

Look-alike domains, suspicious attachments, mismatched links, and credential requests.

Legitimate messages

21

Expected messages verified through trusted context and official procedures.

Fake SOC Alert

Urgent Payroll Message Uses a Look-Alike Domain

Source: Fake Email Security Monitor • Time: 1:22 PM

High Severity
A fictional message claims to be from payroll, threatens delayed payment, and asks the recipient to use a link from a domain with one substituted letter.
Defensive recommendation: Do not click the link or reply. Preserve the message, report it through the approved channel, and verify payroll information through the official portal or known contact.

Fake Log Panel

Fake Email Triage Log

training-log-viewer.log
12:48:03 REPORT user='teacher_12' subject='urgent_payroll_update'
12:51:17 SENDER display='Payroll Office' domain='payro11-example.test'
12:55:44 MESSAGE urgency='high' secrecy='requested' deadline='30_minutes'
13:02:11 LINK visible='Official Payroll Portal' destination='mismatch'
13:08:26 ATTACHMENT present='false' credential_request='true'
13:15:39 CONTEXT payroll_campaign='none' official_notice='none'
13:22:04 DECISION preserve='true' escalate='email_security'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

How Should This Message Be Handled?

A fictional payroll message uses urgent language and threatens delayed payment.
The display name says Payroll Office, but the domain contains a substituted character.
The visible link text says Official Payroll Portal, but the destination does not match.
No official payroll campaign is documented.

What is the safest response?

Common Mistakes

Mistakes That Increase Email Risk

Clicking a suspicious link to see where it goes.
Opening an attachment to confirm whether it is harmful.
Replying to the sender with account or personal information.
Trusting the display name without checking the actual address.
Forwarding the suspicious message to friends instead of using the approved reporting method.
Deleting the message before evidence and headers are preserved.

Safe Practice Lab

Triage a Fictional Email Queue

Fake Message Queue

Community Learning Portal Mailbox

A fictional queue includes payroll, shared-document, password, vendor-invoice, event-reminder, delivery, and support messages with different evidence and business context.

Triage Steps

  • Preserve the original message and report details.
  • Review the display name, full address, domain, and reply address.
  • Identify urgency, secrecy, payment, credential, or data requests.
  • Inspect provided link and attachment metadata safely.
  • Compare the request with normal business procedures.
  • Choose report, verify, block, warn, monitor, or close.

Scenario Decision Lab

An Unexpected Attachment Comes From a Familiar Display Name

A fictional message appears to come from a teacher but contains an unexpected file and a short message saying, 'Open this now.'

Scenario Decision Lab

A Password Warning Threatens Immediate Account Closure

A fictional message says the account will close in ten minutes unless the recipient signs in through an embedded link.

Defender Habits

Phishing and Email Triage Checklist

Check Your Understanding

B14.3 Mini Quiz: Phishing and Email Triage

Choose your answers first. Explanations appear only after submission.

1. What is email triage?

2. Why is the display name not enough to trust a sender?

3. What is the safest action for an unexpected attachment?

4. What should a user do with a suspicious password-reset link?

5. Why should the original message be preserved?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional email triage report. Include the sender display name, full address, domain, reply address, subject, request, urgency, link evidence, attachment evidence, business context, risk indicators, safe decision, reporting path, and final case notes.

Use fictional messages, names, addresses, domains, links, files, headers, and organizations only.
Do not include real suspicious emails, credentials, private messages, or live malicious links.
Explain which indicators are confirmed, which are assumptions, and what requires independent verification.

Key Takeaways

What You Should Remember

1.Phishing messages often use urgency, fear, secrecy, impersonation, suspicious links, or unexpected attachments.
2.The display name alone does not verify the sender.
3.Suspicious links and files should not be opened during triage.
4.Independent verification should use official portals or separate trusted contact methods.
5.Preservation, reporting, documentation, and escalation protect both the recipient and other users.

Navigation

Continue Module B14