weakestlink

← All courses

Nano-lesson · usually takes 2–3 minutes

Spot phishing emails

The foundation course everyone should take first — whether you work in the warehouse, accounts or sales.

It starts with a message

"Your parcel is awaiting customs clearance — pay £1.99." That's usually how it starts: a message that looks like something you're expecting. Phishing is fake messages designed to trick you into clicking, logging in or paying — and you can spot most of them in seconds.

Look out for

  • Unexpected urgency — "your account will be closed in 24 hours". Pressure is a classic trick.
  • The wrong sender — hover your mouse over the name (on mobile: tap it) and read the actual address.
  • Odd links — hover over the link, or press and hold on mobile, until the address shows. If the domain doesn't match, don't click.
  • Requests for a password or payment — legitimate senders don't ask for this by email.

Who is the sender, really?

The name Royal Mail looks right — but the sender address is actually royalmail-parceldelivery.info, not royalmail.com. Always read the actual address, not just the displayed name.

Does your email hide the real address?

Press Reply (but don't send) — the "To" field will then show the genuine sender address. A handy check on mobile, where the name is often all you see.

So where does the link actually lead?

Protocolhttp:// www.paypal.com.Subdomain Domainsecure-login.ru /accountPath
Protocol
The way the page is retrieved (http or https).
Subdomain
The free part in front of the domain — this is where the scammer has added a familiar-looking name.
Domain
The actual place the page lives. This is the part you need to read.
Path
The specific page on the domain.

Look only at the domain — it sits right before the first slash (/). Here it's secure-login.ru, a completely different site from PayPal. The scammer added the familiar name at the front to fool you; it says nothing about where you'll end up.

What does the padlock mean?

https://www.gov.uk/log-in-register-hmrc-online-services

The padlock only means the connection is encrypted — not that the page is genuine. Scammers' copycat sites have padlocks too. If it's missing entirely, that's a red flag — but what determines authenticity is always the domain.

Remember

Check the sender and link before you click — and report anything you're unsure about.

What the research says

On average, victims click a phishing link about 21 seconds after opening the email, and enter data after roughly 28 seconds — under a minute in total; the human element is involved in 68% of all data breaches. It's not the sender's spelling mistakes but the bait itself that decides whether we fall for it.

Verizon DBIR 2024 · Ho et al., IEEE S&P 2025.

Question 1 of 3

An email from "the bank": your account will be closed in 1 hour unless you click and confirm. You're in a hurry. What do you do?

Question 2 of 3

A link displays the text "www.royalmail.com", but when you hover your mouse (or finger) over it, it actually reads royalmail.com.parcel-fee.info/track. Where do you end up if you click it?

Question 3 of 3

An email looks almost genuine, but something feels off. What's the best thing you can do?

Well done!

You've completed one of the foundation courses — the ones everyone gets for free.

With a free login:

  • Your points, progress and course certificate are saved.
  • You get courses tailored to your role — not just the foundation courses.
  • We send training exactly when you need it — for example, as a follow-up to a phishing test.