Free tool
Could you spot the phish?
Eight emails. Some are genuine, some want your money or your password. Read each one the way you would at ten to five on a Friday, then decide. The link destinations are shown, just like hovering over a real link.
Microsoft 365 Support
<security@rnicrosoft-verify.com>
Your password expires in 24 hours
Your Microsoft 365 password will expire in 24 hours. To avoid losing access to your email and files, verify your account now.
Keep my password
Link destination: http://rnicrosoft-verify.com/renew
A classic. The sender domain is "rnicrosoft" (r + n masquerading as m) and Microsoft never asks you to keep a password via an emailed button.
- Lookalike domain: rnicrosoft-verify.com
- Artificial 24-hour deadline
- Password panic is the oldest lure there is
Microsoft SharePoint
<no-reply@sharepointonline.com>
Karen shared "July rota.xlsx" with you
Karen Wallace shared a file with you. Open it in SharePoint to view or edit.
Open July rota.xlsx
Link destination: https://yourbusiness.sharepoint.com/sites/staff/July-rota.xlsx
This one is genuine: sharepointonline.com is Microsoft’s real sending domain and the link goes to your own company’s SharePoint. The habit to build is checking that you expected the share.
- Genuine Microsoft sending domain
- Link goes to your own tenant, not a random host
- Names a real colleague and a plausible file
Royal Mail
<delivery@royalmail-redelivery-fee.com>
Your parcel is waiting: £1.99 redelivery fee required
We attempted to deliver your parcel today. To arrange redelivery, please pay the outstanding fee of £1.99 within 48 hours or the item will be returned.
Pay redelivery fee
Link destination: http://royalmail-redelivery-fee.com/pay
The small-fee parcel scam. The real Royal Mail domain is royalmail.com, not a hyphenated lookalike, and they do not take £1.99 card payments to redeliver.
- Hyphenated lookalike domain
- Tiny fee designed to feel harmless (they want the card details, not the £1.99)
- Deadline pressure
Sarah at BrightPrint
<accounts@brightprint.co.uk>
Invoice INV-2041 for June
Hi, please find attached our invoice INV-2041 for June’s print run, due on the 30th as usual. Any questions just give me a shout. Thanks!
View invoice INV-2041
Link destination: https://brightprint.co.uk/invoices/INV-2041
A normal supplier invoice: consistent domain, expected billing cycle, no pressure. One caveat for real life: if an invoice ever announces new bank details, confirm by phone on a number you already have.
- Sender domain matches the supplier
- Expected monthly pattern, normal tone
- No urgency, no threats
Reuben Conroy
<r.conroy.ceo.mail@gmail-secure-mail.com>
Quick favour - are you at your desk?
I need you to handle something discreetly. I’m stuck in meetings all day and can’t take calls. Can you buy 4 x £50 Amazon gift cards for a client and send me the codes? I’ll sort the expense after.
(no link, reply requested)
Link destination: reply goes to gmail-secure-mail.com
CEO fraud. The display name says the boss, but the address is a freemail lookalike. Gift cards, secrecy, and "can’t take calls" is the exact script criminals use, because it works.
- Display name does not match the real address
- Gift cards are untraceable cash
- "Discreet" plus "can’t talk" removes your chance to verify
Microsoft account team
<account-security-noreply@accountprotection.microsoft.com>
Unusual sign-in activity on your Microsoft account
We detected a sign-in from a new device in Newcastle, United Kingdom. If this was you, you can safely ignore this email. If not, review your recent activity.
Review recent activity
Link destination: https://account.microsoft.com/activity
Genuine: accountprotection.microsoft.com is a real Microsoft domain and the link goes to microsoft.com. The safest habit is still to open the site yourself rather than clicking, but this email is legitimate.
- Real microsoft.com destination
- No deadline or threat, and "ignore if this was you"
- Consistent sender domain
HM Revenue & Customs
<refunds@hmrc-taxrefund.gov-uk.com>
You are owed a tax refund of £342.16
Following a review of your fiscal activity, HMRC has determined you are owed a refund of £342.16. Submit your claim within 72 hours to receive payment.
Claim my refund
Link destination: http://hmrc-taxrefund.gov-uk.com/claim
HMRC states plainly that it never emails about refunds. The domain ends in gov-uk.com, a paid lookalike, and real government addresses end in .gov.uk.
- gov-uk.com is not .gov.uk
- HMRC never emails refund offers
- Precise amount plus a deadline: bait and pressure
Companies House
<noreply@companieshouse.gov.uk>
Confirmation statement reminder for STRATITECH CONSULTING LTD
The confirmation statement for STRATITECH CONSULTING LTD is due by 14 August. File it online before the deadline to avoid penalties.
File your confirmation statement
Link destination: https://www.gov.uk/file-your-confirmation-statement
Genuine: a .gov.uk sender, a gov.uk destination, and a real statutory obligation with a real date. Note this is the format criminals imitate, so the domain check matters every time.
- Genuine .gov.uk sender and destination
- Names your company correctly
- A real deadline, but no panic tactics
0/8
Now imagine your whole team took this
We run security awareness training and safe phishing simulations for small businesses: short, regular, and no blame. It starts with a free 30-minute chat.
All eight are modelled on real campaigns doing the rounds in the UK. Nothing you click here goes anywhere.
Why one quiz is not enough
People do not click phishing emails because they are careless; they click because they are busy. That is why the fix is layered: filtering that stops most fakes arriving, settings that stop your own domain being spoofed (check yours here), MFA so a stolen password is not enough, and short, regular practice like this instead of an annual slideshow. We wrote up the full approach inwhy your staff will click the phishing email.
