Forensic Investigation on Email
What is a common indicator in the email header that could suggest the email originated from a suspicious source?
Why is the absence of SPF, DKIM, or DMARC records in an email concerning?
Which tool is commonly used to scan email attachments for known threats during content analysis?
What does a mismatched domain in the 'From' field in an email header typically indicate?
Which of the following is a key benefit of SPF, DKIM, and DMARC email authentication protocols?
What is the first step in analyzing a suspicious email to detect phishing?