Kasspar kasspar.com
TOOL / Spot the phish

Find the red flags before you click.

Two fictional messages, modelled on real ones. Click anything that looks suspicious, or reveal all the flags at once. The organisations named do not exist.

Reading about red flags is not the same as spotting them in a message that looks routine. Below are two fictional messages modelled on real phishing: a bank security alert by email and a parcel-fee text. Click every part that looks wrong, then compare your finds with the list under each message. The organisations, addresses and numbers are invented.

Example 1: a fake bank security email

Found 0 of 6 red flags
From
Northbridge Bank Security <>
To
Subject

We detected a sign-in to your online banking from an unrecognised device. For your protection, access will be restricted unless you confirm your identity.

Please using the secure link below.

Northbridge Bank Customer Security Team

  1. 01
    Sender domain is not the bank's. "northbridge-secure-login.com" is a lookalike. A real bank sends from its own domain, and even that can be faked, so the domain alone never proves anything.
  2. 02
    Generic greeting. Your bank knows your name. "Valued Customer" means the same message went to thousands of people.
  3. 03
    Manufactured urgency. A 24-hour deadline and "URGENT" in capitals are there to stop you thinking.
  4. 04
    Asks for your password and memorable word. No bank asks you to type these into a link from an email. This is the entire point of the message.
  5. 05
    The link text does not match the real destination. The button says northbridge.com, but hovering (or long-pressing on a phone) shows a different address on someone else's hosting.
  6. 06
    Tells you not to check with anyone. Isolation is a classic scam move. A genuine bank would be glad you called your branch.

Example 2: a fake parcel-delivery text message

Found 0 of 4 red flags
SMS
from

ParcelPoint: due to an unpaid customs fee of £1.45.

  1. 01
    An ordinary mobile number. Delivery firms send from short codes or named senders. Also: you did not give a courier your number for any parcel.
  2. 02
    No parcel details. No tracking number, no sender, no description. It is designed to fit whatever you happen to be expecting.
  3. 03
    A lookalike link. "parcelpoint-redelivery.info" is not the company's site. The small "fee" exists only to collect your card number.
  4. 04
    A deadline. "Within 12 hours" again. If you are expecting a parcel, check in the courier's own app or on the retailer's order page.
The golden rule: go in through your own front door.

Never open a site from a link in an unexpected message. Open your bookmark or the official app instead and look for the problem there. If it is real, it will be waiting. If it is not, the scam just failed, and you did not have to spot a single red flag.

Why this matters

Almost every phishing message pulls the same levers: a trusted name, a generic greeting, urgency, a request for something secret, a link that goes somewhere else, and a reason not to check with anyone. Once you have consciously spotted each of these a few times, they start to jump out on their own, even in a message that looks perfectly professional.