Email Security beginner

Analyze a Suspicious Email

Forward suspicious emails to SecurEcommerce for analysis. Learn what we check and how to respond.

5 minutes
4 steps
beginner level

Before You Start

  • SecurEcommerce installed
  • Email access

When to Analyze an Email

Forward emails when you see:

  • Emails claiming to be from your brand
  • Suspicious links or requests
  • Customer forwards of “your” emails
  • Anything that doesn’t look right

Step 1: Get Your Analysis Address

  1. Open SecurEcommerce
  2. Navigate to Email Security > Email Analysis
  3. Find your unique forwarding address
  4. Copy the address

Step 2: Forward the Suspicious Email

Important: Forward as Attachment

For best analysis, forward the email as an attachment, not inline:

In Gmail:

  • Select the email
  • Click More (three dots)
  • Choose “Forward as attachment”

In Outlook:

  • Select the email
  • Click Forward
  • Choose “As Attachment”

This preserves the email headers we need to analyze.

Step 3: Wait for Analysis

We analyze the email for:

Authentication Checks

  • Did it pass SPF?
  • Was DKIM valid?
  • What does DMARC say?

Phishing Indicators

  • Suspicious links
  • Known phishing patterns
  • Deceptive sender information

Reputation Checks

  • Is the sender known bad?
  • Have I Been Pwned data
  • Known scam patterns

Step 4: Review Results

You’ll receive results showing:

Verdict

  • Legitimate - Appears to be from you
  • Suspicious - May be spoofed or phishing
  • Malicious - Clear phishing/scam attempt

Details

  • What checks passed/failed
  • Specific concerns identified
  • Recommended actions

Next Steps

Based on findings:

  • For legitimate: No action needed
  • For suspicious: Investigate further
  • For malicious: Warn customers, report

What We Check

Technical Analysis

  • Email headers
  • Sender authentication
  • Server reputation

Content Analysis

  • Link destinations
  • Attachment types
  • Known scam patterns

External Data

  • Threat intelligence feeds
  • Reputation databases
  • Known phishing campaigns

Using Results

If Phishing Confirmed

  1. Don’t click any links
  2. Warn customers if needed
  3. Report the phishing
  4. Check your email authentication

If Spoofing Detected

  1. Review your SPF/DKIM/DMARC
  2. Strengthen authentication
  3. Monitor for more attempts

Related Guides

Let SecurEcommerce Handle This For You

This guide works, but it takes time. SecurEcommerce automates security so you can focus on growing your business.

★★★★★ 5/5 on Shopify 7-day free trial No credit card required