High School IntermediateModule I7Complete

I7: Email Security and Phishing Defense

Learn how defenders evaluate fictional senders, domains, authentication, social engineering, links, attachments, impersonation, business email compromise, filtering, message traces, user reports, containment, validation, and evidence without interacting with suspicious content.

Module Snapshot

Lessons

8

Module Test

25 Questions

Portfolio Outcome

Phishing-Defense Case Report

Main Question

How can defenders decide whether a message is trustworthy without relying on one clue or taking unsafe actions?

Defensive Goal

Combine sender, domain, authentication, message, business, security-control, user-action, account, and monitoring evidence before deciding whether to allow, report, quarantine, verify, contain, remediate, or close.

Safety Boundary

Use only fictional messages and supplied training evidence. Never open suspicious attachments, enter credentials, scan unknown QR codes, follow suspicious links, contact a sender through the message, or test real accounts and mail systems.

Professional Workflow

A Six-Step Email Defense Process

1

Preserve the message safely

Keep the fictional message, headers, delivery records, links, attachment names, timestamps, user report, and security alerts without interacting with suspicious content.

2

Identify the claimed sender and request

Record the fictional display name, address, domain, reply path, organization, business purpose, requested action, urgency, and expected relationship.

3

Correlate technical evidence

Compare fictional headers, authentication, message trace, reputation, link analysis, attachment results, mailbox actions, and account activity.

4

Verify through an independent path

Use a known fictional contact method, established business process, trusted portal, approved directory, or separate workflow rather than replying through the message.

5

Contain and remediate narrowly

Apply approved fictional quarantine, blocking, session review, credential reset, account recovery, payment hold, user notification, and related-message search when evidence supports it.

6

Validate and document

Confirm required communication still works, unsafe access is denied, affected users and accounts are reviewed, monitoring is active, and residual risk is recorded.

Learning Objectives

What You Will Be Able to Do

Objective 1

Explain how fictional messages, senders, domains, mail systems, security controls, mailboxes, and users interact.

Objective 2

Evaluate display names, addresses, domains, headers, reply paths, SPF, DKIM, DMARC, alignment, and their evidence limits.

Objective 3

Recognize social-engineering techniques, impersonation, unusual requests, business-process mismatches, and sensitive-action pressure.

Objective 4

Use safe independent verification for suspicious links, attachments, QR codes, login requests, payment changes, and account-recovery messages.

Objective 5

Interpret fictional email-security controls, quarantine decisions, message traces, alerts, mailbox events, and user reports.

Objective 6

Create a professional fictional phishing-defense investigation with findings, owners, remediation, validation, monitoring, and residual risk.

Module Lessons

Eight Lessons and Defensive Labs

I7.1Lesson 1 of 8

Email Threat Landscape and Message Anatomy

Focus

Learn how fictional email moves through senders, domains, mail systems, security controls, inboxes, links, attachments, replies, and user decisions.

Defensive Lab

Map a fictional message from sender to recipient and identify which evidence belongs to the message, the delivery path, the mailbox, and the user action.

Open I7.1
I7.2Lesson 2 of 8

Sender Identity, Domains, and Email Authentication

Focus

Study display names, addresses, domains, reply paths, lookalike domains, SPF, DKIM, DMARC, alignment, and the limits of authentication results.

Defensive Lab

Compare fictional sender, domain, header, and authentication records to determine what is confirmed, what is suspicious, and what remains unknown.

Open I7.2
I7.3Lesson 3 of 8

Phishing Indicators and Social Engineering

Focus

Recognize fictional urgency, authority, fear, curiosity, scarcity, impersonation, unusual requests, payment pressure, credential requests, and context mismatches.

Defensive Lab

Review several fictional messages and explain which persuasion techniques are present without relying on spelling mistakes alone.

Open I7.3
I7.4Lesson 4 of 8

Links, Attachments, and Safe Verification

Focus

Evaluate fictional links, shortened destinations, attachments, file types, QR codes, cloud shares, login prompts, and safe independent verification.

Defensive Lab

Build a safe verification plan for a fictional message without opening suspicious content, entering credentials, or contacting the sender through the message itself.

Open I7.4
I7.5Lesson 5 of 8

Business Email Compromise and Impersonation

Focus

Understand fictional executive impersonation, vendor fraud, payment changes, payroll updates, gift-card requests, reply-chain abuse, and account compromise indicators.

Defensive Lab

Analyze a fictional payment-change request using sender evidence, business process, approval rules, independent confirmation, and transaction controls.

Open I7.5
I7.6Lesson 6 of 8

Email Security Controls and Filtering

Focus

Explore fictional filtering, reputation, attachment inspection, link protection, quarantine, warning banners, blocklists, allowlists, reporting, and user education.

Defensive Lab

Review a fictional email-security policy and propose narrow defensive improvements without blocking legitimate communication.

Open I7.6
I7.7Lesson 7 of 8

Email Logs, Alerts, and Investigation

Focus

Correlate fictional message traces, headers, authentication, mailbox actions, security alerts, URL events, attachment results, user reports, and account activity.

Defensive Lab

Create a fictional email investigation timeline that separates delivery, user interaction, policy action, account activity, and evidence gaps.

Open I7.7
I7.8Lesson 8 of 8

Email Security and Phishing Defense Lab

Focus

Integrate sender analysis, social-engineering review, safe verification, security controls, user response, investigation, remediation, validation, and reporting.

Defensive Lab

Produce a portfolio-ready fictional phishing-defense case report with evidence, findings, actions, owners, validation, monitoring, and residual risk.

Open I7.8

Fake Evidence Preview

One Message, Several Evidence Sources

Source

Message content

Evidence

A fictional executive display name requests an urgent gift-card purchase and asks the recipient not to call.

Limitation

Message language can show pressure and impersonation patterns but does not prove who sent it.

Source

Sender address

Evidence

The fictional address uses a lookalike external domain instead of the organization’s normal domain.

Limitation

A suspicious domain supports concern, but domain appearance alone does not show whether the account was compromised.

Source

Authentication results

Evidence

The fictional message passes SPF and DKIM for the lookalike domain but fails the organization’s expected sender relationship.

Limitation

Authentication can prove the message was authorized by that domain, not that the domain is trustworthy or expected.

Source

Business process

Evidence

The fictional request bypasses the normal purchasing and approval workflow.

Limitation

A process mismatch increases concern but should still be verified through an independent path.

Source

User action

Evidence

The fictional recipient reports the message without replying, opening links, or purchasing anything.

Limitation

The report supports safe handling, but investigators should still search for related recipients and account activity.

Portfolio Outcome

Build a Complete Phishing-Defense Portfolio Artifact

1

A fictional email-message anatomy map showing sender, domain, delivery, filtering, mailbox, link, attachment, and user-action evidence.

2

A sender and domain verification worksheet covering display name, address, reply path, lookalike domain, SPF, DKIM, DMARC, and alignment.

3

A social-engineering analysis that identifies persuasion techniques, requested actions, business-process mismatches, and evidence limits.

4

A safe verification checklist for links, attachments, QR codes, cloud shares, login prompts, payment changes, and recovery messages.

5

A fictional phishing-defense case report with timeline, findings, actions, owners, validation, monitoring, and residual risk.

Module Assessment

I7 Module Test

Complete a 25-question assessment covering message anatomy, sender identity, domain evidence, authentication, social engineering, links, attachments, impersonation, business email compromise, filtering, logs, investigation, containment, validation, and reporting.

Module Navigation

Begin Email Security and Phishing Defense