C

Scam › Module 1 › Lesson 2

BeginnerModule 1Lesson 2/5

Email Phishing Red Flags

Spot spoofed senders, urgent language, mismatched links, and other email phishing warning signs

15 min+50 XP3 quiz
Module progress2 of 5
From: [email protected]Link ≠ claimed bank domainURGENT · 30 minutes left
Spoofed From · Bad link · Urgency

Opening

Look past the logo

Attackers can copy a bank logo in minutes. What they struggle to fake perfectly is the boring stuff: the real sending domain, consistent language, and links that go exactly where they should. Train your eyes on those details and most email phishing collapses.

1. Sender and Domain Checks

  • Display name ≠ address

    The name may say "PayPal Support" while the address is [email protected]. Always expand the full From address.

  • Lookalike domains

    paypa1.com, micros0ft-support.net, or bankname-secure-login.com are classic tricks. Count letters. Read slowly.

  • Unexpected "internal" mail

    A message from "IT" or "HR" that you did not request is a yellow flag until you verify out-of-band.

2. Link and Attachment Red Flags

Hover (or long-press on mobile) before you click. The visible text may say "www.yourbank.com" while the real URL is different. Unexpected attachments—especially .html, .iso, .js, double extensions like invoice.pdf.exe, or password-protected zips you did not ask for—are high risk. Real vendors rarely send "open this zip to unlock your account."

3. Language and Pressure Clues

Phishing copy often mixes: generic greetings ("Dear Customer"), spelling errors, odd urgency ("within 30 minutes"), threats, or prizes. Good companies still make mistakes, so language alone is not enough—but combined with a weird domain or link, it is decisive. When in doubt, do not use links from the email. Open your browser and type the official site yourself, or use the official app.

Safe habit — open the real site yourself (example)1. Do NOT click the email link 2. Open your browser 3. Type: https://www.yourbank.com 4. Sign in only on that official page

1. Do NOT click the email link
2. Open your browser
3. Type: https://www.yourbank.com
4. Sign in only on that official page

Report, then delete

Use your email client's Report phishing / Report junk button when available. It trains filters and helps your workplace security team.

Knowledge Check

1

Why should you inspect the full From address, not just the display name?

Multiple choice

Knowledge Check

2

True or False: If an email shows a bank logo, the link is guaranteed to be safe.

True or False

Knowledge Check

3

What is the safest way to reach your bank after a suspicious email?

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)