The important role email plays in Internet communication has made it a popular attack vector. Phishing, in particular, has evolved and become more sophisticated and more dangerous. As a result, cybersecurity professionals should know how to analyze emails to determine potential ‘maliciousness’. In this presentation, attendees will learn how to manually analyze email headers to determine whether individual emails can be trusted. The presentation will begin with an introduction to email architecture that includes a discussion of the DNSSEC security protocol. It will then move a review of email header structure and a discussion of those fields that are most important for email tracing. The presentation will end with the analysis of several (potentially) malicious emails. After the presentation, electronic copies of the presentation and all lab materials will be made available to attendees so that they can be used in their own courses.