Bulk marketing email flagged as suspicious by content filter
A-104200:00time on this alert, target 20 minutes
Back to queueAlert details
- Source
- Email Gateway
- Detection rule
- EGW-SUSPICIOUS-CONTENT-014
- Affected user
- k.mensah
- Affected host
- WKS-HR-02
- Source IP
- —
- First seen
- 2026-07-24T13:12:00Z
Why this fired, in plain English
The filter saw urgent wording plus a tracking link and flagged the message for a human to look at.
Suggested playbook
Phishing report triage
- 1. Pull the message headers. Check SPF, DKIM and DMARC results.
- 2. Compare the sending domain to the real domain character by character (rn vs m, l vs I, 0 vs o).
- 3. Check the reply-to address — attackers often differ it from the From address.
- 4. Run WHOIS on any linked domain. Domains under 30 days old are a strong signal.
Raw log evidence
Exactly what the tools recorded — 3 events.
Guided hint: this line matters
ts=2026-07-24T13:10:02Z src="email_gateway" event=message_delivered from="news@benefits-hub.example" to="k.mensah@northwind-mfg.example" subject="Last chance: open enrollment closes Friday" spf=pass dkim=pass dmarc=pass
All three sender-authentication checks passed, so the sender really is who they claim to be.
ts=2026-07-24T13:10:03Z src="email_gateway" event=content_score msg_id="9c30de" urgency_terms=2 tracking_pixels=1 link_count=6 score=61 threshold=60
The score only just crossed the threshold — a sign of a borderline rule, not an attack.
ts=2026-07-24T13:12:00Z src="email_gateway" event=alert_raised msg_id="9c30de" rule="EGW-SUSPICIOUS-CONTENT-014"
Related events
The order things happened in.
13:10Z
Message delivered and scored
13:12Z
Alert raised for review
Enrichment lookups
Mock lookups. Run each one yourself — a real analyst never guesses what a lookup would have said. There is no "run everything" button on purpose.
Not checked yet.
Not checked yet.
Not checked yet.
techniques
Your verdict
Keyboard shortcuts 1–4, or click. You can always change your mind afterwards.