Interactive Simulation
Phishing Simulator
90% of breaches start with a simple email. Investigate real-world email and SMS scenarios, earn XP, and find out whether you'd catch the fake before it catches you.
Back to ToolsWhat This Teaches
The Habits That Beat Phishing
Inspect Before You Decide
Hover the sender address and every link before acting. Typosquatted domains ("micros0ft", "amazn") and bit.ly redirects hide in plain sight until you look.
Urgency Is the Tell
"Expires in 2 hours." "Warrant for your arrest." Real companies almost never demand instant action — manufactured panic is the attacker's favorite tool.
Headers Don't Lie
A Return-Path that doesn't match the sender domain and an SPF softfail expose a spoof instantly. Legitimate mail passes SPF and DKIM from the company's own servers.
How Would Your Team Score?
Free assessment for your organization — see who on your team would take the bait before an attacker finds out for you.
Get Your Team's Security Score
Free assessment for your organization