Case CN-PH-001
Phishing Email Investigation
Investigation question
Does this message show credential theft, malware delivery, or a false positive?- Sender domain
- payrolI-secure.example
- Lookalike
- Authentication
- SPF: fail · DKIM: none
- Review
- Attachment
- benefits_update.html
- Artifact