researchIntermediate3-4 hours

Catch a Phish: Investigate a Suspicious Email

Maps to: Cybersecurity Analyst · SOC Analyst · Incident Responder · Threat Intelligence Analyst · Security Engineer

Ever gotten an email that felt off? Catching that feeling and proving it is the actual day job for a huge slice of cybersecurity. You'll work through a batch of suspicious emails the way a brand-new security analyst does on day one: pull apart the hidden information attached to every email, check the links and senders against sites that track known scams (without ever clicking them), and make the call: is this a real attack, something dodgy worth passing up to someone senior, or a harmless false alarm? You'll walk away with a reusable "is this a scam?" checklist and a written investigation, the exact kind of thing that gets a beginner noticed. One honest heads-up: this is the defending side, catching attacks, not the movie-hacker stuff of breaking in. That's not the boring version. It's where most real cyber jobs actually are.

You're done when: You've worked through at least 5 suspicious emails (each with the proof you found and your call), made a real pass-it-up-or-close-it decision on the one that genuinely could go either way and written down WHY, turned it into a checklist you can reuse, and published a short write-up of the whole investigation. Done isn't "I labeled some emails." It's "I can defend every call I made, especially the close ones."

How this shows up on a resume or college app

I investigated N suspicious emails the way an entry-level security analyst does, analyzing hidden headers, sender authentication (SPF/DKIM/DMARC), and link/file reputation to separate real phishing attacks from false alarms, then built a reusable triage checklist and published an investigation report. I learned that most of cybersecurity is patient, careful evidence-gathering, and that the hard part is making a call you can defend when the evidence is incomplete.

When you finish, BuildMe drafts your Common App activity description from what you actually built.

Not sure yet? Play 5 minutes as a cybersecurity analyst first and see how the work feels.

The plan

  1. 1

    Step 1

    First look: make the call before you have any tools

    Don't set anything up yet. Get a small batch of suspicious emails in front of you and just read them, the way the scammer hopes you won't. For each one, write a one-line gut call (looks like an attack, looks dodgy, or looks harmless) and what tipped you off. You'll be wrong on some. That's the point: this first note is the thing you'll test and defend later.

  2. 2

    Step 2

    Get the proof: who really sent it, and where the links go

    Now you go from 'feels off' to 'here's the proof.' This is the patient, methodical part, and it's most of real cyber work. Every email carries hidden information showing where it actually came from, whether it faked who it says it is, and where its links really go. Tools read that for you, and you'll check links and files against sites that track known scams without ever opening them.

  3. 3

    Step 3

    The hard call, and the checklist you'll reuse

    Most of your batch is now obvious. But there's almost always one email the proof doesn't settle: it passed some checks and failed others, the link looks odd but nothing confirms it's bad. That's the real job: making a call you can defend when you can't be sure, and deciding whether to pass it up to someone senior or close it. You'll make that call yourself, then have an AI play a doubtful senior colleague and try to poke holes in it, before you make your FINAL call.

  4. 4

    Step 4

    Write it up, put it out, and see what it says about you

    People in this job live and die by the write-up: a clear report is half the work. Pull your proof and your calls into one short report, then put it out where one real person who'd use it can read it. That report is something you can show anyone. And here's why it's worth doing: cybersecurity is growing fast, but the way in is tighter than it used to be. The people who get in are the ones who can show they've done real work, not the ones with the longest list of certificates. A real investigation someone can read beats a line on a resume. You just made one.

Tools you'll use

Resources