ED-101
Email Analysis
easy

Open Enrollment Benefits Notice

Wealth advisor a.chen flagged a 2026 benefits enrollment email whose portal link does not match Straylight HR systems. Auth failures and a lookalike enrollment domain are already on the table. Prove or kill the phish call.

10-15 min40 pts

Case Brief

Open enrollment week means every finance mailbox gets flooded with HR-looking mail. Wealth advisor a.chen@straylight.finance hit report on a "2026 Benefits Enrollment Window" message because the enroll portal is not the one Straylight publishes. Tess wants a clean call: spoofed enrollment phish, or noisy false positive during benefits season.

Objective

Decide if the message is malicious, cite the auth and domain evidence, and recommend quarantine or block before more advisors click through.

Learning Objectives

  • Prove whether SPF, DKIM, and DMARC failed or passed for the reported message
  • Separate the real Straylight brand from lookalike sender and enrollment domains
  • Capture the portal URL and originating IP as ticket-ready IOCs
  • Close with a disposition and containment action you can defend to Tess