Scam › Module 1 › Lesson 2
Email Phishing Red Flags
Spot spoofed senders, urgent language, mismatched links, and other email phishing warning signs
Opening
Look past the logo. Identity lives in the From domain and the real URL — not in pixels you already trust.
Attackers can copy a bank or shop logo in minutes. What they struggle to fake perfectly, every time, is the boring infrastructure: the mailbox domain that actually sent the mail, and the host a link will open if you tap it. Display names are labels. Links are promises. Phishing is the gap between those and reality. This lesson is how to inspect that gap without visiting the destination. You will not click sample URLs. You will not "just open it in a private window to check." Hover or long-press, read the host, then use a path you already trust. Fictional samples use reserved names such as paypa1-security.example — treat them as pictures, not destinations.
1. Display name is theater; the From domain is the claim you can check
Every email has a display name ("PayPal Support", "HR Payroll") and a From address (local-part plus domain). Clients show the name in bold and hide the domain until you expand the header. Phishing spends its budget on the name because that is what you authenticate with — the same borrowed trust from lesson 1. Expanding the From line is not paranoia. It is reading the field the protocol actually carries. A name that says a brand while the domain is a random registrar name is a mismatch, not a "stylized alias."
Lookalike domains exploit visual habits. Humans read words, not characters: rn can pass as m (rnicrosoft vs microsoft), 1 for l or I, 0 for o, extra hyphens, extra words like -secure-login, a cousin TLD. paypa1-security.example is a teaching fake: the 1 is not an l, and .example is not a bank. You count letters. You read slowly. You do not visit the host to "see if it loads." Loading is how credential pages and malware start. If the domain is wrong, the conversation is over — official app or a URL you type from memory/bookmark, never from this message.
Unexpected "internal" mail is a yellow flag even when the domain looks close. A message from "IT" resetting your VPN, or "HR" demanding salary details you did not request, should be verified on Slack/Teams you already have, a walk to the desk, or a phone number from the company directory — not from the email's own reply-to. Compromised mailboxes of real coworkers can send real-domain phishing. Domain match is necessary, not sufficient, when the ask is a password, a code, a file, or a payment.
2. The visible link is advertising; hover or long-press reads the real host
HTML mail can show https://www.yourbank.example while the href is a different host. On desktop, hover and read the status bar or preview. On mobile, long-press until the full URL appears — then cancel. You are inspecting, not navigating. If the host does not match the brand you think you were talking to, you do not tap. Shorteners and QR codes hide the host until a redirect; treat unexpected shorteners as opaque. This course will not ask you to resolve them. Type the official site yourself or use the official app.
Unexpected attachments are a second channel: .html (credential page saved as a file), .iso / .img, .js, double extensions like invoice.pdf.exe, or a password-protected zip you did not ask for. Real payroll rarely needs you to open salary_form.html from a cousin domain. Do not enable macros "to see the spreadsheet." Do not upload the file to a random scanner that you do not trust. Report in the client, delete, and if you already opened it, that is incident handling later — not a curiosity lab. Combine attachment suspicion with domain and urgency; any two is enough to stop.
3. Urgency plus authority in the body is the same mechanism as lesson 1
Copy that works on email is the same trio: borrowed trust (logo, greeting), a timer or threat, and a rank you are not supposed to question. Generic "Dear Customer," odd grammar, and prize language are extra clues, not a complete test — real companies misspell too. Language alone never green-lights a mismatched domain. Language plus a wrong host plus a login ask is decisive. When in doubt, the safe action is identical every time: do not use the message's links or phone numbers. Open the app you installed, or type the official hostname you already know.
4. Wrong vs right: visiting the fake to "confirm" vs inspecting without navigating
Worked failure — same red flags, opposite action. Right never includes loading paypa1-security.example.
Wrong
Click the link in a private window "just to screenshot the phish." Ping or whois the host from curiosity. Trust the display name because the logo matches last week's real mail. Open salary_form.html. Reply with a password so they can "unlock" you. Forward the live link to a group chat as a joke. Any of those can complete harvest or malware. This course does not teach you to collect live phishing sites.
Right
Expand From. Read the domain slowly (rn vs m, digits as letters). Long-press or hover; cancel. List flags on paper. Use the official app or a typed official URL. Report phishing in the client, then delete. Unique passwords and MFA from Topic 4 still apply if a harvest already happened — rotate from a path you trust, not from the phish.
5. Practical: inspect a fictional sample — list flags, do not visit
The block below is a teaching fake. The host paypa1-security.example is reserved-style fiction (1 not l, .example not a payment brand). Your job is a written flag list: display vs domain, lookalike, urgency, authority, link host mismatch, attachment if any. Then write the safe action. You will not type the URL into a browser, curl it, or ask Mentor to "open it." Next lesson is SMS, where the screen is even smaller.
Command guide
Fictional email — inspect only, never visit the URL
FICTIONAL. Do NOT click, curl, ping, or type this host.
Command — copy this
From: PayPal Security <[email protected]> To: [email protected] Subject: URGENT: Confirm your identity in 12 minutes Body: Dear Customer, We locked your wallet after unusual activity. Verify now or the account closes: https://paypa1-security.example/verify-login — Account Security (authority wording) Attachment: none in this sample
Flag list (write on paper; compare after): [ ] display name != From domain (brand name vs paypa1-security.example) [ ] lookalike (paypa1 digit-1, extra -security, .example) [ ] hover/long-press host would not match a real brand you typed yourself [ ] urgency timer (12 minutes) + threat (account closes) [ ] authority ("Account Security") + generic Dear Customer [ ] asks for a login via the message's link Safe action: do not visit. Open the official app / typed site you already use. If you feared a real lockout: number on YOUR card or in-app chat you started.
NEVER: visit paypa1-security.example NEVER: send a copy of this mail to trick anyone NEVER: paste passwords or codes into a page reached from surprise mail
Mission: six flags, zero visits
Using only the fictional sample (or a real message you do not click), write at least: (1) display name vs From domain, (2) one lookalike trick (digit, rn/m, extra words, or TLD), (3) what hover/long-press is for, (4) urgency and authority in the body, (5) why an unexpected attachment would add risk, (6) the safe action (official app or typed official URL). Confirm you did not visit the sample host.
Stuck? Ask Cyberlium AI Mentor
If display name vs From still blurs, ask for a hint — not a live phish. Try: "Hint only: why can a message say PayPal Security while the domain is paypa1-security.example, and why must I long-press instead of opening the verify-login URL?" No spoilers; you still write the flag list yourself.
You now treat the logo as untrusted paint, the From domain as the first check, lookalikes as character-level lies, and hover/long-press as inspection without navigation. Urgency and authority in the body are lesson 1 again. Unexpected attachments are a malware path. Next — SMS Phishing (Smishing) — the same game on a screen too small to show the host, including texts that steal the MFA codes Topic 4 told you to protect.
Knowledge Check
APPLY: Mail shows "Example Bank" but From is [email protected] and the button says yourbank.example. You have not tapped. Best inspection?
Multiple choice
Knowledge Check
APPLY: Why is "rnicrosoft" vs "microsoft" taught as a lookalike, and what must you not do to "confirm"?
Multiple choice
Knowledge Check
APPLY: True or False: An unexpected salary_form.html from a cousin HR domain is safe if you only open it to "see if it is phishing."
True or False