Scam › Module 1 › Lesson 4
Lab — Spot the Phishing Email
Practice analyzing sample emails for sender, link, and urgency red flags in a guided lab
Opening
Analyst mode: inspect before you trust
This lab uses fictional sample emails. Your job is not to click anything real—it is to list the red flags like a defender reviewing an alert. Work through each sample slowly.
1. Lab Checklist (use every time)
Phishing inspection checklist — copy and reuse[ ] Full From address checked (not just display name) [ ] Domain spelling looks legitimate [ ] Links match the claimed brand (hover / long-press) [ ] No unexpected attachment [ ] Urgency / threat / prize language noted [ ] Would I open the official site myself instead?
[ ] Full From address checked (not just display name) [ ] Domain spelling looks legitimate [ ] Links match the claimed brand (hover / long-press) [ ] No unexpected attachment [ ] Urgency / threat / prize language noted [ ] Would I open the official site myself instead?
2. Sample A — "Payroll Issue"
From display: HR Payroll <[email protected]> Subject: URGENT: Update your salary details in 2 hours Body: "Dear Employee, your direct deposit failed. Click http://companv-hr-support.com/login to avoid payment delay." Attachment: salary_form.html
Flags to catch
3. Sample B — "Package Delivery"
From: Notifications <[email protected]> Subject: Your package is held at customs Body: "Pay a \$1.99 fee here: https://fedx-delivery-alerts.net/pay or it will be returned."
Brand misspelling, unexpected tiny fee, unknown domain, payment pressure—this is classic courier phishing. Real carriers do not need random \$1.99 "customs" links from surprise emails.
4. Sample C — Legitimate-looking false alarm
Even a clean-looking message can be phishing if you did not expect it. Treat unexpected security alerts as tips to check the official app—not as invitations to click. Write three red flags for Sample A and two for Sample B, then compare with the checklist above.
Complete the phishing spotter lab
For Samples A and B, list the red flags you found and state the safe action (ignore link / report / open official site yourself). Confirm you used the checklist on both samples.
Knowledge Check
In Sample A, which detail is a strong phishing signal?
Multiple choice
Knowledge Check
True or False: A tiny unexpected fee link from a lookalike courier domain is usually safe.
True or False