Phishing is a message designed to trick you into revealing personal data by pretending to be someone you trust. You should be able to point at specific features of a message and explain why each one is a warning sign.
The message below is entirely fictional. This lesson uses reading URLs and belongs to the internet security module.
What signals should I look for?
- Sender: an address that does not match the organisation, or a generic greeting such as “Dear customer” instead of your name.
- Urgency or threat: “act within 24 hours or your account will be closed”. Pressure stops you thinking.
- A request for private data: real organisations rarely ask for a full password or PIN by message.
- A suspicious link: the domain (read from the right) does not belong to the organisation named.
- Poor language or odd formatting: spelling errors and mismatched logos, though polished fakes exist too.
- Unexpected attachment: a file you did not ask for.
Worked example
From: security@sunrise-bank-alerts.example.net Subject: Urgent: account locked
Dear customer, we noticed unusual activity. Verify your details within 12 hours or your account will be closed:
https://www.sunrisebank.example.com.secure-check.example.net/login
Identify three signals.
Step 1, greeting: “Dear customer” is generic. A bank that holds your account would normally use your name.
Step 2, urgency: “within 12 hours or your account will be closed” is a threat that pushes you to act quickly.
Step 3, the link domain: the host name is www.sunrisebank.example.com.secure-check.example.net. Reading from the right, the domain is example.net. The words sunrisebank.example.com are only subdomain labels. The link does not go to the bank’s own domain, even though the bank’s name appears first.
Step 4, sender: sunrise-bank-alerts.example.net is not the bank’s own domain either.
Safe action: do not click. Use the bank’s number or app you already trust.
The mistake to watch for
Mistaken answer: “The message is safe because the link starts with https and shows the bank’s name.”
The student trusted the padlock and the first words of the address.
HTTPS only shows that the connection is encrypted. It says nothing about who owns the site. Check the domain, not the brand word and not the protocol.
Check yourself
1. Name two signals of phishing in: “Dear user, your parcel is held. Pay RM5 now at http://post-delivery.example.org/pay.”
Show answer
Any two of: generic greeting (“Dear user”); pressure to pay now; an unexpected request for payment details; a link to a domain that is not a known delivery company’s own; an unencrypted http link when payment is asked for.
2. Which is the real domain in https://login.myschool.example.edu.update-now.example.org/?
Show answer
example.org. Reading from the right, .org is the ending and example is the registered name. The rest are subdomain labels.
3. Give one thing a user should do on receiving a message like this.
Show answer
Do not click the link or open attachments. Contact the organisation through a website or number already known to be genuine, and report the message.
Where does this lead next?
Knowing the signals is one defence, and systems add their own, which is the focus of explaining a defensive control. Test the whole module with the mixed practice set. The mistake log and retest queue helps you track which signals you forget.
If you are unsure how much detail an answer needs, one-to-one feedback in Computer Science tuition can show you where it earns the mark.