TRAINING SIMULATION — this email, company, and every name and address in it are invented for this exercise. No real organisation or person is depicted.

Spot the Phish

Below is a simulated email. Click on every part of it that makes you suspicious — the subject, the sender, a phrase, a link, the attachment, anything.

When you're done, press Check My Answers. You'll see what you caught, what you missed, and why — plus anything you flagged that was actually fine.

Tip: real email clients let you hover over a link without clicking it, to preview where it actually leads. Try hovering the button in this email before you decide whether to select it.
Selected: 0 of 13
You found it You missed it You flagged something that was fine
Status bar — hover a link to preview where it really goes

Here's how you did

0/9
Warning signs found
0
Warning signs missed
0
Fine details flagged by mistake
The 9 warning signs in this email
Parts of this email that were actually fine
A real version of this message would be worth confirming through a channel you already trust — call the helpdesk on a number you looked up yourself, or check the company intranet — rather than by replying to the email or clicking anything inside it.