researchIntermediate3-4 hours

Catch a Phish: Investigate a Suspicious Email

Maps to: Cybersecurity Analyst · SOC Analyst · Incident Responder · Threat Intelligence Analyst · Security Engineer

Ever gotten an email that felt a little off, like something wasn't right about it? This project is that feeling, but done for real. You'll look at a group of suspicious emails, emails that might be trying to trick or steal from someone, and figure out which ones are dangerous and which ones are safe. This is the actual first job in cybersecurity, the work of keeping computers and accounts safe from people trying to break in or trick people. You'll check where each email really came from (every email carries a hidden trail that shows this, even when the name on top is faked) and check its links and senders against websites that keep lists of known scams, all without ever clicking anything risky. Then you'll decide: is this email a real attack (someone genuinely trying to scam or hack you), something worth sending to a supervisor because you're honestly not sure, or nothing to worry about? You'll walk away with a checklist you can reuse on any new suspicious email, and a short written report explaining what you found and why, the kind of real work that gets a beginner noticed. One honest note: this is the defending side, stopping attacks, not the movie version where you break into things. Defending is most of what these jobs actually are, and it's not the boring version.

You're done when: You've gone through at least 5 suspicious emails, and for each one you wrote down the proof you found and the decision you made. On the one email that was genuinely hard to judge, you made a real decision, send it to a supervisor, or decide it's safe, and wrote down why. You turned what you learned into a checklist you can reuse, and you posted a short report online explaining the whole investigation. Done isn't "I labeled some emails." It's "I can explain, out loud, why I made every decision, especially the ones I wasn't sure about."

How this shows up on a resume or college app

I investigated N suspicious emails the way an entry-level security analyst does, analyzing hidden headers, sender authentication (SPF/DKIM/DMARC), and link/file reputation to separate real phishing attacks from false alarms, then built a reusable triage checklist and published an investigation report. I learned that most of cybersecurity is patient, careful evidence-gathering, and that the hard part is making a call you can defend when the evidence is incomplete.

When you finish, Sidequest drafts your Common App activity description from what you actually built.

Not sure yet? Play 5 minutes as a cybersecurity analyst first and see how the work feels.

The plan

  1. 1

    Step 1

    Read it first: decide before you check anything online

    Don't set anything up yet, and don't look anything up online yet either. Get a small group of suspicious emails, emails that might be someone trying to trick or steal from you, in front of you and just read them the way the person who sent them hopes you won't: closely. For each one, write a one-line first guess, before you think too hard about it: does it look like a real attack, does it look a little sketchy, or does it look totally harmless? Also write down the one detail that first made you suspicious. You'll be wrong about some of them, and that's the whole point: this quick first guess is what you'll test with real evidence and defend later.

  2. 2

    Step 2

    Get the proof: who really sent this

    Now you move from 'this feels off' to 'here's the proof.' This is the slow, careful, step-by-step part, and it's most of the real work people in this job do. Every email carries hidden technical information inside it, information you can't see just by reading the email, kind of like a shipping label on the back of a package, and that hidden information shows where the email actually came from, whether it's lying about who sent it, and where its links really go if you clicked them. You won't have to read any of that hidden information yourself; free websites do it for you and show you a simple yes-or-no answer. You'll also check the email's links and any attached files against other websites that keep lists of emails and links already known to be scams, all without ever clicking a link or opening a file yourself.

  3. 3

    Step 3

    The message you cannot tell is real or a scam, and the checklist you keep

    Most of the emails in your group are obvious by now. But there's almost always one email where the evidence doesn't give a clear answer: it passes some checks and fails others, and the link looks a little odd but nothing proves it's actually bad. That's the real job: making a decision you can defend even when you're not fully sure, and deciding whether to send it up to a supervisor (someone with more experience who decides the tricky ones) or decide it's safe. You'll make that decision yourself first. Then you'll have an AI act like a doubtful supervisor and argue against your reasoning, trying to find the weak spots in it, before you make your final decision.

  4. 4

    Step 4

    Write it up, put it out, and see what it says about you

    People in this job live and die by the written report: writing it up clearly is half the work. Pull together the evidence you gathered and the decisions you made into one short written report, then put it somewhere online where one real person who'd actually use it can read it. That report is something you can show anyone, a real link, not just a claim. And here's why it's worth doing: this kind of work is growing fast, but getting hired into it is harder than it used to be. The people who get hired are the ones who can show they've already done real work, not the ones with the longest list of online course certificates. A real, readable investigation beats one line on a form you fill out to apply for a job. You just made one.

Tools you'll use

Resources