Email

Phishing analysis

The Phishing analysis module examines a suspicious message and reports only verifiable technical facts: what anyone can re-check by reading the file and querying DNS. No judgement on the tone of the text, no brand or reputation lists: an indicator is a fact, or it isn't there. Links are never opened.

What it does

What the Phishing analysis module does

Server route

Every hop (Received) with server, IP, delays and inconsistent times; for public IPs the reverse name and the network owner (RDAP).

SPF, twice

The result recorded by the server that received the message, and a fresh evaluation per RFC 7208 with a trace of every step: include, redirect, the ten-lookup limit.

DKIM

The body hash is verified offline; the signature, with the key published in the domain's DNS. For each signature: domain, selector, algorithm and result.

DMARC

Alignment between the visible sender's domain and those authenticated by SPF and DKIM, and the policy published by the domain.

Links: text against target

If a link's text shows an address and the link leads to another host, it is flagged. The comparison is on hosts, not path or parameters, and a subdomain of the same domain is consistent. Links to IP addresses, with @ and domains with non-ASCII characters are flagged too.

Attachments

The whole tree, attached messages and winmail.dat included: double extensions, real type different from the declared one, executables, encrypted ZIP archives.

YARA

The rules downloaded from the configured endpoint are applied to the message and its attachments. If they can't be downloaded, the report says so: “could not look” is not “clean”.

Headers and PDF report

All headers, the Authentication-Results outcomes and a report with every finding and its explanation.

Step by step

How it works

  1. Drop the message (.eml, .emlx, .msg) and choose whether to use network checks and YARA.
  2. Follow the progress step by step: isolated reading, DKIM keys, analysis, DNS, route IPs, SPF.
  3. Read the findings by category and generate the PDF report.
FAQ

Frequently asked questions

Does Probatio open the message's links?
No. Links are extracted and compared, never opened. The only network queries are DNS and RDAP on the domains and IPs present in the message, and they can be switched off.
Why doesn't it assess the message's text?
Because a judgement on tone is not a re-checkable fact and produces false alarms on legitimate emails. Probatio reports only what can be verified in the file and in DNS.
What's the difference between SPF “at delivery” and “today”?
The first is the result recorded by the server that received the message; the second is recomputed today on the current DNS records. If the domain has changed its records in the meantime they can differ, and the report flags it.
Can DKIM be verified offline?
Partly: the message body hash yes. The signature needs the public key, published in the signing domain's DNS.