Spot the Phish
A pretend inbox. Some messages are real. Some are fakes trying to steal a password. Tap each one, read the tells, then sort it.
What is a phish?
A message pretends to be someone you trust so you click a bad link or type your password into a fake page. It is a trick on the person, not the computer.
A strong password does not help here. If you type it into a fake page, you handed the
secret away yourself. The only defense is spotting the fake before you act.
๐ The four tells to hunt for
- โฆLookalike sender. The name looks right, but the address is off by a letter or a fake ending.
- โฆUrgent threat. "Act now or lose your account." Fear makes people click without thinking.
- โฆMismatched link. The words say one site, but the real address it points to is somewhere else. Hover to check.
- โฆAsks for your password. A real company never emails you to ask for your password.
Sort the inbox
Tap a message to open it. Hover any link to see where it really goes. Then mark it Safe or Phish. Everything here is pretend and nothing actually opens.
Wrong guesses are fine. The point is learning the tell, not a perfect score. Sort all five to
move on.
The one rule that beats every fake
You cannot always tell a perfect fake from the real thing. So do not try to. Use the rule instead.
๐ซ Never click the link. Open the real site yourself.
- Got a message about your account? Stop. Do not tap its link or button.
- Open a new tab and go to the real site the way you always do, by typing the address you know or using your own saved bookmark.
- Log in there and check. If something real needs your attention, it will be waiting.
- If you are unsure, ask a trusted adult. Calm checking always beats fast clicking.
This works even on a fake you could not spot. The fake link goes to the fake page. The
address you type yourself goes to the real one. So the trap never gets your password.
โ Defense Range ยท every message here is a pretend example in a sandbox. No link works. Tap the underlined word to dig deeper.