Nano-lesson · usually takes 2–3 minutes
Spot phishing emails
The foundation course everyone should take first — whether you work in the warehouse, accounts or sales.
It starts with a message
"Your parcel is awaiting customs clearance — pay £1.99." That's usually how it starts: a message that looks like something you're expecting. Phishing is fake messages designed to trick you into clicking, logging in or paying — and you can spot most of them in seconds.
Look out for
- Unexpected urgency — "your account will be closed in 24 hours". Pressure is a classic trick.
- The wrong sender — hover your mouse over the name (on mobile: tap it) and read the actual address.
- Odd links — hover over the link, or press and hold on mobile, until the address shows. If the domain doesn't match, don't click.
- Requests for a password or payment — legitimate senders don't ask for this by email.
Who is the sender, really?
The name Royal Mail looks right — but the sender address is actually royalmail-parceldelivery.info, not royalmail.com. Always read the actual address, not just the displayed name.
Does your email hide the real address?
Press Reply (but don't send) — the "To" field will then show the genuine sender address. A handy check on mobile, where the name is often all you see.
So where does the link actually lead?
http://
www.paypal.com.Subdomain
Domainsecure-login.ru
/accountPath
- Protocol
- The way the page is retrieved (http or https).
- Subdomain
- The free part in front of the domain — this is where the scammer has added a familiar-looking name.
- Domain
- The actual place the page lives. This is the part you need to read.
- Path
- The specific page on the domain.
Look only at the domain — it sits right before the first slash (/). Here it's secure-login.ru, a completely different site from PayPal. The scammer added the familiar name at the front to fool you; it says nothing about where you'll end up.
What does the padlock mean?
https://www.gov.uk/log-in-register-hmrc-online-services
The padlock only means the connection is encrypted — not that the page is genuine. Scammers' copycat sites have padlocks too. If it's missing entirely, that's a red flag — but what determines authenticity is always the domain.
Remember
What the research says
On average, victims click a phishing link about 21 seconds after opening the email, and enter data after roughly 28 seconds — under a minute in total; the human element is involved in 68% of all data breaches. It's not the sender's spelling mistakes but the bait itself that decides whether we fall for it.
Question 1 of 3
An email from "the bank": your account will be closed in 1 hour unless you click and confirm. You're in a hurry. What do you do?
✓ Correct!
Pressure with a deadline is a classic trick. Go to the source yourself — don't click "just to have a look", and don't reply: your reply goes straight to the scammer.
Question 2 of 3
A link displays the text "www.royalmail.com", but when you hover your mouse (or finger) over it, it actually reads royalmail.com.parcel-fee.info/track. Where do you end up if you click it?
✓ Correct!
Always look at what comes right before the first slash — that's where you'll land. Familiar names placed in front are just window dressing added by the scammer.
Question 3 of 3
An email looks almost genuine, but something feels off. What's the best thing you can do?
✓ Correct!
If you delete it, colleagues can still fall for it — and if you reply, you're talking to the scammer. One report warns everyone who received the same email.
Well done!
You've completed one of the foundation courses — the ones everyone gets for free.
With a free login:
- Your points, progress and course certificate are saved.
- You get courses tailored to your role — not just the foundation courses.
- We send training exactly when you need it — for example, as a follow-up to a phishing test.