analyzing-phishing-email-headers — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited analyzing-phishing-email-headers (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Email headers contain critical metadata that reveals the true origin, routing path, and authentication status of emails. Analyzing these headers is a foundational skill for identifying phishing attempts, verifying sender authenticity, and gathering threat intelligence. This skill covers systematic extraction and interpretation of email headers using both manual techniques and automated tools.
From and Return-Path domainsAuthentication-ResultsReceived chains with unfamiliar relay serversX-Originating-IP from unexpected geographiesMessage-IDX-Mailer values (e.g., mass-mailing tools)Gmail: Open email -> Three dots -> "Show original"
Outlook: Open email -> File -> Properties -> Internet Headers
Thunderbird: View -> Message Source (Ctrl+U)Use the scripts/process.py script to automate header analysis including IP geolocation, authentication validation, and anomaly detection.
Received headers from bottom to top~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.