Skip to content
IGCSE·Tuition
Computer Science · Lessons

Identify a phishing signal in a fictional message

A fake message can look polished, so students often miss the single detail that gives it away.

On this page
  1. What signals should I look for?
  2. Worked example
  3. The mistake to watch for
  4. Check yourself
  5. Where does this lead next?

Phishing is a message designed to trick you into revealing personal data by pretending to be someone you trust. You should be able to point at specific features of a message and explain why each one is a warning sign.

The message below is entirely fictional. This lesson uses reading URLs and belongs to the internet security module.

What signals should I look for?

  • Sender: an address that does not match the organisation, or a generic greeting such as “Dear customer” instead of your name.
  • Urgency or threat: “act within 24 hours or your account will be closed”. Pressure stops you thinking.
  • A request for private data: real organisations rarely ask for a full password or PIN by message.
  • A suspicious link: the domain (read from the right) does not belong to the organisation named.
  • Poor language or odd formatting: spelling errors and mismatched logos, though polished fakes exist too.
  • Unexpected attachment: a file you did not ask for.

Worked example

From: security@sunrise-bank-alerts.example.net Subject: Urgent: account locked

Dear customer, we noticed unusual activity. Verify your details within 12 hours or your account will be closed: https://www.sunrisebank.example.com.secure-check.example.net/login

Identify three signals.

Step 1, greeting: “Dear customer” is generic. A bank that holds your account would normally use your name.

Step 2, urgency: “within 12 hours or your account will be closed” is a threat that pushes you to act quickly.

Step 3, the link domain: the host name is www.sunrisebank.example.com.secure-check.example.net. Reading from the right, the domain is example.net. The words sunrisebank.example.com are only subdomain labels. The link does not go to the bank’s own domain, even though the bank’s name appears first.

Step 4, sender: sunrise-bank-alerts.example.net is not the bank’s own domain either.

Safe action: do not click. Use the bank’s number or app you already trust.

The mistake to watch for

Mistaken answer: “The message is safe because the link starts with https and shows the bank’s name.”

The student trusted the padlock and the first words of the address.

HTTPS only shows that the connection is encrypted. It says nothing about who owns the site. Check the domain, not the brand word and not the protocol.

Check yourself

1. Name two signals of phishing in: “Dear user, your parcel is held. Pay RM5 now at http://post-delivery.example.org/pay.”

Show answer

Any two of: generic greeting (“Dear user”); pressure to pay now; an unexpected request for payment details; a link to a domain that is not a known delivery company’s own; an unencrypted http link when payment is asked for.

2. Which is the real domain in https://login.myschool.example.edu.update-now.example.org/?

Show answer

example.org. Reading from the right, .org is the ending and example is the registered name. The rest are subdomain labels.

3. Give one thing a user should do on receiving a message like this.

Show answer

Do not click the link or open attachments. Contact the organisation through a website or number already known to be genuine, and report the message.

Where does this lead next?

Knowing the signals is one defence, and systems add their own, which is the focus of explaining a defensive control. Test the whole module with the mixed practice set. The mistake log and retest queue helps you track which signals you forget.

If you are unsure how much detail an answer needs, one-to-one feedback in Computer Science tuition can show you where it earns the mark.

Questions people ask

What is phishing?

Phishing is sending a message, often by email or text, that pretends to come from a trusted organisation to trick the reader into giving away personal data, such as passwords or card details. It relies on the reader acting quickly without checking the sender or the link.

What is the difference between phishing and pharming?

Phishing tricks the user with a message, usually containing a link. Pharming redirects the user to a fake website even when they type the correct address, by interfering with how the address is looked up. Both aim to collect personal data from the victim.

What should I do with a message I think is phishing?

Do not click links or open attachments. Contact the organisation using a number or website you already know, not one in the message. Report it to the real organisation or to your school if the message reached a school account.

Can a phishing link still start with https?

Yes. HTTPS means the connection is encrypted, not that the site owner is honest. Anyone can obtain HTTPS for their own domain, so the domain in the link matters more than the padlock.

Updated:

Your next step

If you recognise phishing in class but struggle to explain the signals in the exact words a mark scheme wants, a one-to-one teacher can drill that wording with fresh examples.

Paid one-hour trial at your assigned teacher’s confirmed rate, starting from RM80. Other fees, schedules and ongoing arrangements are confirmed directly with your teacher after the trial class.

Tuition is arranged with a parent or guardian. Send them this page on WhatsApp and they can enquire for you.

Parent or guardian? Enquire here

9,000+ students helped through our service