Cyber / Basics

Free practice · Phishing

Spot a phishing message before it costs you

Spam is unwanted. Phishing wants something from you: a password, a payment, a file opened. The good news is that almost every phishing message gives itself away in one of three places — and once you have looked in those three places a few dozen times, you look there without deciding to.

Tell 1 — the name is not the sender

A message shows a display name ("Parcel Desk", "Account Team", your bank's name) and, somewhere near it, an address. Anyone can type any display name. The address is harder to fake and easier to read: look at the part after the @. A company writes from its own domain. A stranger writes from a domain that merely mentions the company, or from a free mail service, or from something long and plausible that you have never seen before.

Tell 2 — where the link really goes

The words of a link are a costume. The destination is what matters, and you can see it without visiting it: press and hold on a phone, or hover on a computer. Then read the address from the left up to the first single slash — that part is the site that owns the page. parcel-desk.example and parcel-desk-updates.example are two different owners, however similar they look.

Tell 3 — pressure, and an action you did not start

"Within 24 hours." "Verify now or the account stays locked." A code you did not ask for. A sign-in request you did not make. Real services rarely need you to hurry, and they never need you to hurry through their own link. The pressure is there to stop you looking at tells 1 and 2.

Practice example
From: Parcel Desk <notices@parcel-desk-updates.example>
Your package couldn't be delivered

We tried twice. Reschedule within 24 hours or it returns to sender. Confirm your address here: https://parcel-desk-updates.example/reschedule

Where the tells are: a display name with no company domain behind it (1); a link whose owner is a look-alike, not the carrier (2); a deadline and a task you did not start (3). Three at once is common — a message that shows one is worth a second look, and a message that shows all three has answered the question.

What to do in the moment

  1. Don't tap the link. Not even to "just look". Looking is what the page is for.
  2. Go the way you always go. Open the app you already have, or type the address you already know, and check there. If there really is a parcel, it will be there too.
  3. If you already tapped and typed something in: change that password from a device you trust, turn on the second sign-in step for that account, and then do the same for your e-mail account — it resets all the others.

What the full app adds

An Inbox Lab with the whole header on screen, because the header is the lesson. A URL Lab for reading addresses at speed. A Call Lab for the same tells spoken aloud. Anything you get wrong comes back later until you get it right. Four languages, offline once signed in, $6 for the first year until 1 December.

Try it — three free questions, no sign-up

Three questions from the same drills subscribers practise every day. Nothing to install, nothing to type in.

Open the full app

Published by VIDANALYTICA INC for the Cyber Basics app, in the app's own words. Content rules this page follows: every message, address and prompt on it is invented for practice; no organisation is named; no fear framing. Questions or corrections: insights@vidanalytica.com · Privacy · Terms · Published 2026-09-21.