Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

Email Header Analysis: What SMTP Metadata Reveals About Infrastructure and Identity

The email your team flagged as probable phishing contains the attacker's entire infrastructure in 30 lines of plain text. Most analysts check 2 things: SPF pass/fail and the From address.

  • Received chain provides forensic anchor with relay hops, server specs, protocol, and timestamp
  • SLOW#TEMPEST campaign routed Cobalt Strike payloads through Shenzhen Tencent Cloud infrastructure
  • SPF failures pinpoint unauthorized sending IPs for immediate threat intelligence cross-referencing

More from Sunday 6 September →