Phishing Quiz — 50 Questions on Spotting Fake Messages

5 rounds · 50 questions

Round 1 of 5 · Question 1 of 50

Who really sent it

An email looks like it came from your bank. Which part of the address actually decides where it came from?

Show all 50 questions with answers and explanations

Every question, answer and explanation

Who really sent it

  1. An email looks like it came from your bank. Which part of the address actually decides where it came from?

    Answer The domain after the final @ sign

    Read an address from the right. Everything before the final @ is chosen freely by the sender; only what follows it is registered to someone. That single habit defeats most casual attempts.

  2. The sender shows the name Support, and its address ends in yourbank.secure-login.net. Which domain is the message really from?

    Answer secure-login.net

    Split it at the dots and take the last two parts: secure-login.net. Everything to the left, including a familiar bank name, is a subdomain that whoever owns that domain can invent at will.

  3. The display name is your manager's full name, but the address is a free webmail account. What does that tell you?

    Answer Display names are typed by the sender and prove nothing on their own

    A display name is a label typed by the sender, like the name on an envelope. Mail clients show it because it is convenient, not because anything verified it.

  4. A reply arrives inside a real email thread and quotes messages you actually sent. Does that prove it is genuine?

    Answer No, someone reading a compromised mailbox can reply inside real threads

    Thread hijacking is common precisely because it defeats the usual advice. If someone is reading a real mailbox, they can reply with genuine history quoted underneath, and nothing about the thread will look wrong.

  5. Two addresses look identical until you notice one uses rn where the other uses m. What is happening?

    Answer A lookalike domain registered to be misread at a glance

    In many fonts rn is nearly indistinguishable from m at reading speed. The same trick uses l for I, or 0 for O. Selecting the address and enlarging it, or reading it aloud letter by letter, breaks the illusion.

  6. An email appears to come from your own address and claims the sender has been inside your account for months. What is the most likely explanation?

    Answer The sender address was simply forged, which takes no access at all

    Forging a from-address takes no access at all — it is like writing any return address on an envelope. If the message came with a password, that almost always came from a public breach list rather than from your machine.

  7. A message passes SPF and DKIM checks. What has actually been proven?

    Answer That the sending domain authorized that server, and nothing about the content

    SPF and DKIM answer one narrow question: was this server allowed to send for that domain. They say nothing about whether the domain is trustworthy — an attacker's own domain can pass both perfectly.

  8. A colleague's genuine account starts sending odd payment requests at three in the morning. What is the likely situation?

    Answer Their account has been taken over, so the address checks will all pass

    This is the case where every technical check passes, because the mail really is from that account. The only defense left is the content: an unusual request, at an unusual hour, that moves money.

  9. The address is a no-reply mailbox. How should that weigh in your judgment?

    Answer It carries almost no weight either way, since both real and fake mail use it

    Plenty of genuine automated mail comes from no-reply, and attackers use it too because it discourages you from replying to ask. Treat it as neutral and judge the request instead.

  10. On a phone, only the sender's name is shown and the address is hidden. What is the safest habit?

    Answer Tap the name to expand the full address before acting on anything

    Most phone mail apps show only the display name by default, which is exactly the field an attacker controls. Tapping the name to reveal the real address takes a second and removes the easiest deception.

Where the link really goes

  1. In the address https://accounts.example.com.verify-id.co/login, which site will actually open?

    Answer verify-id.co

    Read to the left of the first single slash, then take the last two labels: verify-id.co. The familiar name earlier in the address is decoration — anyone can put any words in front of their own domain.

  2. Which part of a web address decides the real destination?

    Answer The ending such as .com or .co.uk plus the name right before it

    The registered domain is the suffix plus the one label before it. Everything to the left is chosen by the owner, and everything after the first slash is chosen too. Only that middle pair identifies who is responsible.

  3. A link is displayed as your bank's address but the status bar shows a different domain when you hover. Which one wins?

    Answer The destination shown on hover, because link text is free-form

    Link text is free-form, exactly like a display name. In a browser the true destination appears in the status bar on hover; on a phone, press and hold rather than tapping.

  4. The page has a padlock and starts with https. What does that guarantee?

    Answer The connection is encrypted, and nothing about who owns the site

    A padlock means the traffic is encrypted, nothing more. Certificates are free and instant, so most phishing pages have one — the padlock tells you nobody is eavesdropping while you hand over your password.

  5. An urgent message contains a shortened link. What is the problem with that?

    Answer The destination is hidden until you have already opened it

    A shortener hides the destination behind an address you cannot evaluate. Some services let you preview a short link before opening it, but the safer move is simply to reach the site the way you normally would.

  6. A domain uses letters from another alphabet that look like ordinary Latin letters. What is this designed to do?

    Answer Make a different domain read as a familiar one at a glance

    This is a homograph attack: the Cyrillic and Greek alphabets contain letters shaped exactly like Latin ones, so a familiar name can be spelled with one character swapped and still look right. Browsers defend by displaying suspicious names in punycode, which is why an address sometimes appears as xn-- followed by nonsense — that is a warning, not a glitch.

  7. An email contains a QR code instead of a link. Why does that raise the risk?

    Answer You cannot read the destination before opening it, and phones often hide it afterwards

    A QR code is a link you cannot read. It also moves you onto a phone, which shows less of the address and is more likely to be signed into everything. Treat a code in an unexpected message the way you would treat a shortened link.

  8. A message asks you to sign in through a link to fix a problem with your account. What is the safer route?

    Answer Open the service the way you normally do and look for the same notice there

    The safe route never starts from the message. Open the app or type the address you already know, and if the problem is real it will be waiting there. Nothing genuine depends on you using their link.

  9. The link is https://yourbank.account-check.com/. What role does the familiar name play here?

    Answer It is a subdomain chosen by whoever owns account-check.com

    yourbank here is a subdomain of account-check.com, invented by whoever registered that domain. Subdomains are unlimited and free, which is why a familiar name on the left is worth nothing.

  10. An attachment opens a page that asks for your email password to view the document. What is that page?

    Answer A credential-harvesting page, since documents do not need your mail password

    There is no legitimate reason a document would need your email password. Any page that asks for one credential in order to show you something is a harvesting page, whatever it looks like.

Pressure and bait

  1. A message says your account will be closed within twenty-four hours unless you confirm now. Why is the deadline there?

    Answer To stop you checking through a channel you already trust

    Urgency is not a side effect of these messages; it is the mechanism. The deadline exists to stop you doing the one thing that would expose it — checking through a channel you already trust.

  2. An unexpected message says you have won a prize in a draw you never entered. What is the clearest signal?

    Answer You cannot win a draw you never entered

    Nothing else is needed. If you did not enter, there is no draw. Attackers use prizes because the story explains away the odd sender and makes you supply details willingly.

  3. A message from a senior manager asks you to handle something quietly and not mention it to anyone else. What is the request for secrecy doing?

    Answer Removing the one step that would expose the fraud, which is asking someone else

    Secrecy removes verification, which is the only real defense against a request that looks legitimate. A genuine manager will not mind you confirming, and an attacker cannot afford to let you.

  4. You get an alert about a sign-in from another country. What is the safe response?

    Answer Open the service yourself and check its own security log

    Sign-in alerts are the single most imitated message type, because they are alarming and everyone gets real ones. Never use the link — open the service and read its own recent-activity page.

  5. A manager asks you to buy gift cards for a client and send the codes, promising reimbursement. What makes gift cards attractive to a fraudster?

    Answer The codes are spendable immediately and almost impossible to reverse

    Gift card codes are the closest thing to untraceable cash that an ordinary person can send. They can be spent within minutes and there is no chargeback. That is the whole reason the request exists.

  6. A text says a parcel could not be delivered and a small fee is due. Why does this one work so often?

    Answer Many people are waiting for a parcel, so the message lands on a real expectation

    It works on volume: send it to enough people and some are genuinely waiting for a parcel. The small fee is chosen to feel too trivial to check, and the real prize is the card details you enter.

  7. A job offer arrives for a role you never applied to, and the first step is paying for equipment or training. What is the pattern?

    Answer Money moving from you to the employer before any work exists

    In any real job, money moves toward you. A request to pay for equipment, training or a background check before any work has happened is the whole scam, and no legitimate employer does it.

  8. A page in your browser says your device is infected and gives a support number to call. What is happening?

    Answer A web page cannot scan your device, so the warning is theater to get you on a call

    A web page cannot scan your computer. What it can do is show an alarming animation and a phone number, and the person who answers will ask for remote access or payment.

  9. A message threatens to publish embarrassing recordings unless you pay, and includes an old password of yours. Where did the password come from?

    Answer Almost always a public breach list, which is far cheaper than any real access

    That password almost certainly came from a public breach list, sold in bulk and worth nothing to look up. The claim about recordings is unverifiable by design. Change the password if you still use it anywhere.

  10. Which combination should raise suspicion fastest, on its own?

    Answer Urgency plus a request to act through a link they provide

    Either signal alone is common enough. Together they are the shape of nearly every attack: pressure that stops you thinking, plus a route they control so you cannot check.

What it is asking for

  1. Someone calls, says they are your bank, and asks for the one-time code that just arrived by text. What is that code?

    Answer The final step of a login or payment they are performing right now

    That code is the last step of a login or payment happening right now. No genuine bank, service or support line ever needs it — the code exists precisely to keep it out of anyone else's hands.

  2. A caller asks you to install a program so they can see your screen and fix a problem. What does that give them?

    Answer Control of the device, including anything already logged in

    Remote access software hands over everything already signed in on the device: mail, banking, saved passwords. Real support does not cold-call and ask for it.

  3. A supplier emails a new invoice with different bank details, using the same thread as before. What is the right step?

    Answer Confirm the change by calling a number you already held, not one in the email

    Changed bank details on a real invoice is one of the costliest attacks there is. Confirm using a number you already held from an earlier record — never a number printed in the message itself.

  4. A document tells you to enable editing or enable content to see it properly. What is that asking for?

    Answer Permission to run code embedded in the file

    Enable editing and enable content are the prompts that switch off protected mode and allow embedded macros to run. A document that only needs reading never needs either.

  5. You receive a password reset link you did not request. What is the safest reading?

    Answer Someone may be probing the account, so ignore the link and sign in your usual way to check

    An unrequested reset email usually means someone typed your address into a login form. The link is often genuine, but using it is not the point — if you did not ask, ignore it and check the account yourself.

  6. Early in the conversation, a contact wants to move from a company channel to a personal messaging app. Why does that matter?

    Answer It leaves the place where records, filters and colleagues could catch the problem

    Moving to a personal app strips away everything that would catch the fraud: mail filters, retention, and colleagues who could see the thread. That request is a signal in itself, whoever appears to be making it.

  7. A request arrives to update payroll details through a link, timed just before payday. What makes the timing part of the attack?

    Answer A change made just before payday is noticed only after the money has gone

    Payroll diversion is timed so the change lands after the last check and before the payment. The theft is only discovered when someone reports a missing salary, by which point the money has moved on.

  8. An attachment arrives as a compressed archive containing a single file with a very long name. Why is that shape suspicious?

    Answer Archives cannot be scanned as easily, and a long name can hide the real file type

    Archives get through filters that would open a bare attachment, and a very long filename pushes the real extension off the end of the display. What looks like a document can be a program.

  9. A form asks for your full card number, expiry date and the three digits on the back, to verify identity. What should you conclude?

    Answer Those three digits authorize payments, so nobody verifying identity needs them

    The three digits on the back exist to prove a card is in someone's hand at the moment of payment. An organization verifying who you are already has your account; only someone spending the card needs that number.

  10. A message asks you to confirm your address, date of birth and mother's maiden name to release a refund. What is being collected?

    Answer The answers that reset passwords and pass phone checks elsewhere

    Address, date of birth and mother's maiden name are not identity checks here — they are the answers that reset passwords and pass phone verification at other companies. The refund is the excuse for collecting them.

Telling the real ones apart

  1. A message from your bank contains no links and asks you to call the number printed on your card. How does that read?

    Answer Consistent with genuine practice, since it sends you to a channel you already hold

    Sending you to the number on your own card is the opposite of what an attacker wants, because it moves you to a channel they do not control. It is one of the few structural signs of good faith.

  2. You asked for a password reset a minute ago and the email arrives. What makes this one ordinary?

    Answer You started it yourself, moments earlier, on a service you were using

    The timing is the evidence. You started the action seconds earlier on a service you know, so the message is an answer to something you did rather than an approach out of nowhere.

  3. A delivery notice matches an order you placed, and the same status appears when you open the carrier's site yourself. What have you done?

    Answer Confirmed it through a second, independent route

    You confirmed it through a second, independent route. Independent is the operative word: checking by clicking a link in the same message proves nothing at all.

  4. A receipt shows the correct last four digits of your card, the right amount, and asks for nothing. How suspicious is it?

    Answer Not particularly, since it matches a purchase you made and makes no request

    It matches a purchase you made and asks for nothing, so there is nothing to act on. Merchants routinely show the last four digits; they never show the full number, and one that did would be the warning sign.

  5. A two-factor code arrives at the exact moment you pressed sign in. What is the plain reading?

    Answer It belongs to the action you just took

    A code that arrives exactly when you pressed sign in belongs to that action. The dangerous version is the one that arrives when you did nothing — that means somebody else has your password.

  6. A newsletter you signed up for has an unsubscribe link at the bottom. Does the link make it suspicious?

    Answer No, and the real question is whether it asks you to sign in or pay

    Unsubscribe links are required by law in most places and are entirely ordinary. What matters is what the link asks for: a page that wants your password to unsubscribe is not an unsubscribe page.

  7. An official notice tells you to log in through the app you already have installed, rather than following a link. Why is that pattern reassuring?

    Answer It moves you to a route the sender does not control

    Pointing you at an app you already installed is a good sign for the same reason a phone number on your card is: it hands control back to you and takes it away from the sender.

  8. A colleague's request is unusual, so you call their known number and they confirm it. What did the call establish?

    Answer That the request itself is real, through a channel the attacker does not hold

    It established that the request itself is real, using a channel the attacker does not control. This is the check that defeats even a compromised account, because it does not depend on the message being genuine.

  9. A security alert only tells you something happened and asks for nothing at all. How does that compare with a phishing alert?

    Answer Phishing almost always needs an action from you, so a message asking for nothing has little to gain

    Phishing needs you to do something — click, reply, pay, enter a code. A message that asks for nothing has no way to profit, which is why pure notifications are far more often genuine.

  10. Which set of signs, taken together, best supports treating a message as genuine?

    Answer The timing matches something you did, it asks for nothing unusual, and the same thing appears when you check independently

    No single sign settles it, which is why the answer is a combination: timing that matches something you did, no unusual request, and a route back that you chose rather than one they supplied.

About the Phishing Quiz

Almost every phishing quiz asks the same thing: is this one fake? That trains half a skill. People who take those quizzes get better at suspicion and then start treating real receipts, real security alerts and real colleagues as attacks, which is its own kind of damage and is exactly why the last round here does the opposite.

The fifty questions are grouped into five rounds. The first four take apart the pieces an attacker actually controls — the sender address, the link, the pressure, and the thing being asked for. The fifth round hands you ordinary genuine messages and asks what makes them ordinary, because knowing when to relax is the part that keeps the rest usable.

No real company is named anywhere. The examples use roles and invented addresses, which keeps the questions about the technique rather than about one brand's current email design, and those designs change every year while the techniques do not.

It is general awareness rather than training for any particular workplace, and it does not replace your own organization's rules on payments and access.

How it works

  1. Answer all fifty questions across five rounds. There is no timer, so read the wording of each option rather than skimming for the scary one.
  2. Watch for the questions where more than one answer is defensible. The intended answer is the one that holds regardless of which company sent the message.
  3. Do the last round with the same care as the first four. Learning to clear a genuine message is a separate skill from spotting a fake one.
  4. Look at which round you lost points in, not just the total. Missing a whole round tells you more than missing ten scattered questions.

Frequently asked questions

Is the Phishing Quiz free, and do I need to sign up?

It is free, there is no account, and nothing is installed. Your answers stay in the browser and no score is recorded anywhere.

How long does the Phishing Quiz take?

Most people finish in eight to twelve minutes. There is no timer, and reading carefully is worth more here than answering quickly.

How is this different from the phishing quizzes run by security companies?

Two things. Those quizzes show you screenshots of specific brands, which teaches you this year's email design as much as the technique. And they almost all ask only whether a message is fake. A fifth of the questions here are genuine messages, because a person who flags everything is nearly as stuck as one who flags nothing.

Does a good score mean I will not be caught out?

No. Quizzes are taken with your attention switched on, and real attacks arrive while you are busy, tired, and expecting a parcel. The realistic benefit is that a few of these patterns become familiar enough to interrupt you at the wrong moment, which is all any awareness training can honestly claim.

Do I need any technical background?

No. Everything is judged from what an ordinary reader can see: the address, the link, the wording and the request. Nothing depends on inspecting mail headers or running tools.

Should I use this to train my team?

You can use it as a conversation starter, but it is not a substitute for your own rules on payments, access and reporting. The single most useful thing an organization can do is make reporting a suspected message easy and blameless, and no quiz can supply that.