StratITech logoStratITech

Free tool

Could you spot the phish?

Eight emails. Some are genuine, some want your money or your password. Read each one the way you would at ten to five on a Friday, then decide. The link destinations are shown, just like hovering over a real link.

Email 1 of 8Score: 0
M

Microsoft 365 Support

<security@rnicrosoft-verify.com>

Your password expires in 24 hours

Your Microsoft 365 password will expire in 24 hours. To avoid losing access to your email and files, verify your account now.

Keep my password

Link destination: http://rnicrosoft-verify.com/renew

All eight are modelled on real campaigns doing the rounds in the UK. Nothing you click here goes anywhere.

Why one quiz is not enough

People do not click phishing emails because they are careless; they click because they are busy. That is why the fix is layered: filtering that stops most fakes arriving, settings that stop your own domain being spoofed (check yours here), MFA so a stolen password is not enough, and short, regular practice like this instead of an annual slideshow. We wrote up the full approach inwhy your staff will click the phishing email.