ACCOUNTS SUPPORT GUIDE

Email Phishing Investigation and Mailbox Isolation

Accounts troubleshooting guide

Knowledge Base / Accounts / Email Phishing Investigation and Mailbox Isolation

Problem

A user reports a suspicious email, clicks a malicious link, or shows signs that a mailbox may have been compromised.

Quick action is essential to prevent the phishing attempt from spreading or exposing credentials. Preserve evidence, isolate the mailbox, and escalate when the risk is confirmed.

Symptoms to check

  • User reports receiving a suspicious link, fake login page, or urgent request for credentials.
  • Mailbox activity shows unusual sign-ins, forwarding rules, or sent messages.
  • Multiple users report the same phishing theme or email domain.

Possible causes

  • The user clicked a malicious link or opened a credential-harvesting message.
  • An attacker compromised an inbox and added forwarding or malicious rules.
  • Malware or spoofing is being used to masquerade as a trusted sender.

Resolution

  1. Capture the email samples, sender details, and time of receipt. Preserve the message and any screenshots before deleting anything from the user’s inbox.
  2. Review the user’s account for suspicious sign-ins, MFA changes, mailbox rules, or recently added forwarding rules. Check whether the mailbox has been accessed from an unknown device or location.
  3. If the user clicked a malicious link or entered login data, isolate the mailbox or temporarily restrict sign-in according to policy. This helps prevent ongoing access while the investigation continues.
  4. Report the incident to the security team, include the hash or exact message source, and ask for a broader threat check if more than one user is affected.
  5. After security review, restore access, remove malicious rules, and confirm the user can sign in normally without exposing further risk.

Prevention and preparation

  • Train users to report suspicious mail without opening links or attachments.
  • Use security tools to quarantine bulk phishing attempts and detect impersonation campaigns.
  • Document your incident response flow for user reports and mailbox isolation.

Related guides

Still not fixed? Escalate to the security team with the mailbox details, evidence, and whether credentials were entered or clicked. Never attempt to investigate a suspicious email from the affected mailbox alone.

Submit a ticket

Last reviewed: October 2026