Free · no login · no data stored
Can you tell a phishing email from a real one?
A free game that trains you to spot phishing: you get ten real emails, one at a time. Some are genuine, some are scams. You have 24 seconds for each and three lives — and after every answer you're told exactly what gave the email away.
What gives it away?
Every giveaway:
Game over
Today's board
| # | Player | Points | Caught |
|---|---|---|---|
| No one on the board yet today. You could be the first. | |||
The board resets every night.
Five things that give a phishing email away
Most fake emails give themselves away on something very concrete. Those are exactly what the game trains you to spot — and they apply just as well when you're staring at an email right now.
The sender's address, not the sender's name
Anyone can put any name on an email. The address behind it, they can't. Check whether the domain after the @ is the company's real one — not a variant with a hyphen, an extra word or a different ending.
There's a rush
A threat of suspension, a deadline today, an account about to expire. Time pressure is no accident — it's there to make you act before you've had a chance to think. Genuine letters from public bodies and banks give you time.
You have to log in to sort something out
A link that takes you to a login page is the most common way to steal a password. If you do need to log in, do it the way you normally would — in the app, or by typing the address yourself. Never through the link in the email.
You're being asked for something
Card details, a national ID number, an approval on your ID app, a payment to a new account number. Genuine senders don't ask for that sort of thing in an email — and certainly not out of the blue.
An attachment you're meant to open
An invoice you don't recognise, a delivery note, a document that insists you "enable content". If you weren't expecting the file, don't open it — check with the sender through a channel you find yourself.
How the game works
You get ten emails, one at a time. Some are real, some are phishing. You have 12 seconds for each and three lives. After every answer you're told what gave the email away — or what made it convincing, if it was genuine. Being able to recognise an email you can safely trust matters just as much.
The emails aren't made-up examples. The lures come from the library we use for real phishing training in workplaces, and the genuine ones are written to match what actually lands in an inbox here. That's why they're hard — that's the point.
Why is it free?
Because it works best when lots of people try it. There's no account, no email address and no tracking of what you answer — just three initials on today's leaderboard, if you choose to add them. Training a whole workplace on an ongoing basis is what we charge for.
Want to measure yourselves against each other?
With an account, your whole workplace can play — and see how the teams stack up against each other. Individual results are never shown to colleagues.