Phishing Track · Part 3 of 3

Don’t just delete the email. Trace it.

The TRACE method, for people without a tech background: preserve the evidence, reveal the real sender, read what the headers actually say, check where the link really lands, and report it so the whole campaign dies — not just your copy.

  • Time~4 hrs
  • LevelAdvanced
  • FormatHands-on labs
  • FinishCertificate

The brief

What you'll walk away with

  1. 01The forensic mindset

    Think evidence-first: what to preserve, what to never touch, and why it matters.

  2. 02Take a snapshot

    Preserve suspicious messages without destroying the evidence most people delete.

  3. 03Reveal the real

    Find the “View Original” button every client hides, and the three header lines that matter.

  4. 04Authenticate the sender

    SPF, DKIM, and DMARC as one plain question: pass, fail, or missing?

  5. 05Check the landing

    Follow a link safely — homographs, redirects, sandboxes — without ever clicking it.

  6. 06Escalate

    Report so IT, APWG, brands, and law enforcement can actually stop the campaign.

“You can’t always spot a fake. But you can always preserve the evidence, read what a message actually carries, and report it in a way that protects thousands of other people.”

Curriculum

Six modules, then the exam

6 modules · 18 lessons · ~4 hrs

Final Assessment

10 min Certificate upon passing

Who it's for

Evidence handlers

Security champions

You’ve finished the first two courses and want to contribute evidence, not just avoid attacks.

Team leads & managers

You receive phishing reports from your team and want to respond with the right next step.

The curious

You want to know what happens after you hit “Report” — and how to make it matter.

Close the loop

Make your reports matter.

Four hours from “this looks suspicious” to evidence a security team can act on. Free, certificate at the end.

Begin Module 1