The Anatomy of a Phishing Email
Phishing is the number one way attackers break into organizations, and it works by exploiting people, not computers. Before you can use AI to triage phishing, you need to recognize the parts of an email an attacker manipulates. In this lesson you'll dissect a phishing email piece by piece, then use AI to confirm your findings. By the end you'll never look at a suspicious email the same way again.
What You'll Learn
- The six parts of an email that attackers manipulate
- The most common red flags in phishing messages
- How to use AI to explain each part in plain English
- A mental "map" of an email you can carry into the triage lab
What Phishing Actually Is
Phishing is a message that pretends to be from someone you trust to trick you into doing something harmful: clicking a malicious link, entering your password on a fake page, opening an infected attachment, or paying a fraudulent invoice. Variants include spear phishing (targeted at one specific person) and business email compromise (pretending to be your boss or a supplier). The common thread is deception plus urgency.
Attackers succeed by rushing you. Almost every phishing email tries to make you feel a strong emotion (fear, greed, curiosity, or pressure) so you act before you think. Slowing down is your first defense.
The Six Parts Attackers Manipulate
1. The sender ("From") address. The display name can say "PayPal Security" while the real address is paypa1-alerts@random-domain.ru. Attackers rely on you reading the friendly name and ignoring the actual address. Always look at the true address, not just the name.
2. The subject line. Designed to trigger urgency: "Your account will be closed in 24 hours," "Invoice overdue," "You have a new voicemail." Urgency in a subject is a yellow flag.
3. The greeting. Generic greetings like "Dear Customer" or "Dear User" suggest a mass send. Real companies that have your account usually use your name. (Though sophisticated attacks may use your name too, so this is a hint, not proof.)
4. The body and its tone. Look for pressure, threats, unusual requests ("buy gift cards," "confirm your password," "update payment info"), spelling and grammar mistakes, and mismatched branding.
5. The links. The visible text might say www.yourbank.com, but the real destination (which you see by hovering, without clicking) could be somewhere else entirely. Mismatched link text and destination is one of the strongest red flags.
6. The attachments. Unexpected attachments, especially .zip, .html, .exe, or documents that demand you "enable macros," are classic malware carriers.
Try It Now: Have AI Build You a Checklist
Open ChatGPT, Claude, or Gemini and paste:
Role: You are a phishing-awareness trainer.
Task: Give me a checklist of red flags to inspect in a suspicious
email, organized by email part: sender, subject, greeting, body,
links, and attachments.
Format: A checklist with a short "why it matters" for each item.
Save the result. This becomes your reference card for the triage lab.
A Guided Dissection
Here is a fictional phishing email. Read it and try to spot the red flags yourself before reading on.
From: "Microsoft Account Team" <security@micr0soft-verify.com>
Subject: Unusual sign-in activity - action required within 24 hours
To: undisclosed-recipients
Dear User,
We detected a sign in to your acount from a new device. If this
wasnt you, your account will be suspend. Please verify your identity
immediately by clicking the link below:
Verify My Account >> (link text shows account.microsoft.com but
actually points to http://micr0soft-verify.com/login)
Failure to verify within 24 hours will result in permanent closure.
Microsoft Security Team
How many did you catch? The red flags include: a look-alike domain using a zero (micr0soft), a generic "Dear User," urgency and threats ("within 24 hours," "permanent closure"), spelling errors ("acount," "wasnt," "suspend"), a link whose real destination differs from its text, and a vague "undisclosed-recipients" mass send. That's at least six independent signals, which together make this almost certainly malicious.
Confirm with AI
Now paste the same email into your AI tool with this prompt:
Role: SOC analyst.
Task: List every phishing red flag you can find in the email below,
grouped by email part. Then rate overall risk (Low/Medium/High).
Email:
[paste the fictional email above]
Compare the AI's list to your own. You'll usually find you agreed on most, and the AI may catch one or two you missed, while you may catch context it lacks. That partnership, human plus AI, is exactly how professional triage works.
Why Learn the Parts If AI Can Do It?
Because AI is your assistant, not your replacement. When you understand the six parts, you can (1) sanity-check whether the AI's answer makes sense, (2) ask sharper follow-up questions, and (3) make the final call with confidence. An analyst who blindly trusts the tool is one convincing fake away from a bad decision. An analyst who understands the anatomy uses AI to go faster and stays in control.
Key Takeaways
- Phishing exploits people through deception and urgency, not technical flaws.
- Attackers manipulate six parts of an email: sender, subject, greeting, body, links, and attachments.
- The strongest red flags include look-alike domains, mismatched link text and destination, generic greetings, urgency and threats, and spelling errors.
- Use AI to build a red-flag checklist and to confirm your own analysis, then compare notes.
- Understanding the anatomy lets you supervise the AI instead of blindly trusting it.

