Phishing Track · Part 3 of 3
Don’t just delete the email. Trace it.
The TRACE method, for people without a tech background: preserve the evidence, reveal the real sender, read what the headers actually say, check where the link really lands, and report it so the whole campaign dies — not just your copy.
- Time~4 hrs
- LevelAdvanced
- FormatHands-on labs
- FinishCertificate
The brief
What you'll walk away with
- 01The forensic mindset
Think evidence-first: what to preserve, what to never touch, and why it matters.
- 02Take a snapshot
Preserve suspicious messages without destroying the evidence most people delete.
- 03Reveal the real
Find the “View Original” button every client hides, and the three header lines that matter.
- 04Authenticate the sender
SPF, DKIM, and DMARC as one plain question: pass, fail, or missing?
- 05Check the landing
Follow a link safely — homographs, redirects, sandboxes — without ever clicking it.
- 06Escalate
Report so IT, APWG, brands, and law enforcement can actually stop the campaign.
“You can’t always spot a fake. But you can always preserve the evidence, read what a message actually carries, and report it in a way that protects thousands of other people.”
Curriculum
Six modules, then the exam
6 modules · 18 lessons · ~4 hrs
The Forensic Mindset
Take a Snapshot (T)
Reveal the Real Sender (R + A)
Check the Landing (C)
Escalate (E)
Final Assessment
Who it's for
Evidence handlers
Security champions
You’ve finished the first two courses and want to contribute evidence, not just avoid attacks.
Team leads & managers
You receive phishing reports from your team and want to respond with the right next step.
The curious
You want to know what happens after you hit “Report” — and how to make it matter.
Close the loop
Make your reports matter.
Four hours from “this looks suspicious” to evidence a security team can act on. Free, certificate at the end.
Begin Module 1