Phishing Awareness Simulator
Click through a realistic inbox and learn to spot phishing red flags
Inbox
0 / 8 reviewed
How to spot phishing
Check the actual domain
Not just the display name — hover over the sender address and any links to see where they really go. Lookalike domains (amaz0n, secure-bank-verify) are the most common trick.
Be suspicious of urgency
"24 hours", "account suspended", "offer expires soon" — artificial time pressure is designed to stop you thinking carefully.
Never enter credentials via email links
Go directly to the organisation's app or official site instead of clicking through from an email, especially for banking or account logins.
Watch for impersonated authority
Scams often pretend to be a boss, teacher, or official body asking you to act quickly and quietly — real authority figures rarely need secrecy.
Frequently asked questions
What is phishing?
Phishing is a scam where an attacker sends a message — usually email — pretending to be a trusted source (a bank, a company, a colleague) to trick you into revealing information, clicking a malicious link, or taking an action like paying money.
What are the most common phishing red flags?
A sender domain that looks almost right but isn't (lookalike domains), artificial urgency pressuring quick action, requests for login details or payment via an email link, generic greetings instead of your name, and unexpected "prizes" for things you never entered.
How can I check if a link is safe before clicking?
Hover over a link (without clicking) to see the actual destination URL, and compare it carefully to the organisation's real domain. When in doubt, go directly to the organisation's official site or app instead of clicking through from the email.
Is this simulator based on real phishing techniques?
Yes — every scenario in this simulator is modelled on real, common phishing patterns (lookalike domains, urgency, authority impersonation, small-fee scams) used in actual attacks, adapted into a safe practice format.