Practice Lab

The Tackle Box

Each one below is a simulated phishing email. Spot the red flags, then see how you did.

These are based on real-life malicious emails pulled from public databases of confirmed phishing campaigns. Links have been removed, so they're safe to study while preserving the patterns used against real victims.

How to practice

01

Read the whole email

Look at it the same way you would a real email in your inbox: who sent it, what they want, and how urgently they want it.

02

Click what looks suspicious

Anything that seems off is clickable: the sender, the subject, links, attachments, or sentences in the body. To help you learn, suspicious parts are marked with dotted underlines. Click one to pin it, and see how you did at the end.

verify your account
03

Find every red flag

Pin everything you think is a threat, then finish. You will get a full breakdown of what you caught, what you missed, and why each one matters.

The Parking Meter QR CodePhishing example
From
Reply-Tonoreply@parkpay-citywide.net
SubjectUnpaid Parking Session – Pay Now to Avoid Additional Fees
PreviewYour recent parking session was not completed

Click anything that looks suspicious — including the sender info and attachments above — to flag it.

Findings0/4 found

Not found yet

Click it in the email above to see why it's a red flag.

Not found yet

Click it in the email above to see why it's a red flag.

Not found yet

Click it in the email above to see why it's a red flag.

Not found yet

Click it in the email above to see why it's a red flag.

4 remaining

0/38 emails completed

Change difficulty

Practical basics