Many attacks are based on manipulating parts of the email that the user assumes to be reliable. These manipulations can be subtle and difficult to detect without knowing how messages function internally. Analyzing these elements allows for the identification of fraud attempts even when the email appears legitimate at first glance.
Article image

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

From Field Spoofing

The From field is one of the most manipulated, as users often trust it without verifying other technical data.

Reply-To Alteration

The Reply-To field can redirect replies to an address other than the visible sender, allowing attackers to receive information without raising suspicion.

Visually Similar Domains

The use of look-alike domains is a classic phishing technique. Small variations can easily go unnoticed.

Manipulated Links

Links can display visible text that does not match the actual destination, making it easy to redirect the user to fraudulent sites.

Malicious Attachments

Attachments are one of the most dangerous vectors, as they can contain malware or manipulated documents.

Conclusion

Manipulable elements are the foundation of most email attacks. Detecting them requires combining technical header analysis with a critical review of the visible content. This article completes the series dedicated to email anatomy and the techniques necessary to evaluate its legitimacy. Cómo analizar un correo electrónico reenviado: guía forense

What happens to an email when we forward it? (And how not to lose the attacker's trail)

Article image