ED-101
Email Analysis
easy
Open Enrollment Benefits Notice
Wealth advisor a.chen flagged a 2026 benefits enrollment email whose portal link does not match Straylight HR systems. Auth failures and a lookalike enrollment domain are already on the table. Prove or kill the phish call.
10-15 min40 pts
Case Brief
Open enrollment week means every finance mailbox gets flooded with HR-looking mail. Wealth advisor a.chen@straylight.finance hit report on a "2026 Benefits Enrollment Window" message because the enroll portal is not the one Straylight publishes. Tess wants a clean call: spoofed enrollment phish, or noisy false positive during benefits season.
Objective
Decide if the message is malicious, cite the auth and domain evidence, and recommend quarantine or block before more advisors click through.
Learning Objectives
- Prove whether SPF, DKIM, and DMARC failed or passed for the reported message
- Separate the real Straylight brand from lookalike sender and enrollment domains
- Capture the portal URL and originating IP as ticket-ready IOCs
- Close with a disposition and containment action you can defend to Tess