Staying safe
Recognizing a fraudulent email
What you will be able to do In 6 minutes, you'll know how to recognize a fraudulent email without clicking on anything.

A fraudulent email has a name: it's phishing, a fake message that imitates a service to get you to hand something over. On a computer, you have an advantage a phone doesn't give you: the screen is big, and everything can be read. The exact address of the sender behind the displayed name, the real destination of a button when you hover over it without clicking, the name of the attached file. Five signs are enough, and none of them require clicking. We're going to spot them one by one, on a screen we built ourselves. Nothing here is real, so nothing can happen to you.
Simulated screen
I practice
This screen was drawn by us. Nothing is sent, nothing is installed, and no real brand is shown.
The situationIt's 8 am, you open your mailbox on the computer. This message is at the top of the list.
The interactive exercise needs JavaScript. The written step by step, just below, says exactly the same thing.
The written step by step
The same steps, in words, to read or print. This sheet works even without the exercise.
Who's really writing
Your turn Two lines talk about the sender. Tap the one that really says who's writing.
Below the displayed name, the full address reads in full: customer-service@verify-my-account-2b.example. That's what says who's writing, not the name.
A message written for no one
Your turn Tap the line that shows this message wasn't written for you.
The line "Dear valued customer" replaces your name. A service that knows you writes your name, it doesn't need a catch all phrase.
The countdown and the request
Your turn Tap the sentence that gives you a deadline and asks for your bank details.
The sentence that sets tomorrow 8 am and asks for your bank details stacks two signals: false urgency, and a request that's never made by email.
The file you weren't expecting
Your turn One thing in this message should never be opened. Tap it.
The attachment Refund_to_confirm.zip is a file attached to the message. A file you weren't expecting never gets opened.
Reading a button without clicking it
Your turn The button's text says one thing. Tap what really says where it leads.
You hover over the button without clicking, and the destination shows up at the bottom of the window. The site name there is verify-my-account-2b.example.
What to do with this message
Your turn The message is unmasked. Tap what you do with it.
You click on nothing, you don't reply, you report the message, then you delete it. Reporting an email is done through Signal Spam.
The sheet to keep
- The displayed name of a sender is just a label. Only the full address, the one with the at sign, says who's writing.
- A catch all greeting, like "Dear valued customer", replaces the name a real service would have written.
- No organization, public or private, asks for your bank details or your access codes by email.
- The tight deadline is there to stop you from checking. A real service gives you time.
- An attachment you weren't expecting doesn't get opened, even when its name looks official.
- Hover over a link without clicking: its real destination shows up at the bottom of the window. The site name is right before the first forward slash.
- You click on nothing, you don't reply: you report it to Signal Spam, then delete it. A fraudulent SMS, meanwhile, is forwarded to 33700.
- If you're unsure what to do next, cybermalveillance.gouv.fr offers a free assessment.
The reflexes in this skill
I look at WHO is speaking
A displayed name is just text, so it can be copied. What matters is the exact address of the sender, or their phone number. A delivery announced from an unknown mobile number is not a delivery.
I stop before I click
Urgency is the sign of a trap. A message that counts down the hours is trying to stop you from thinking. Putting your phone down for two minutes costs nothing, and it is almost always enough.
The padlock is not enough: I read the address
The little padlock icon means the connection is encrypted, not that the site is honest. A scam site has one too. The name of the site sits just before the first forward slash: that is where to look.
No one serious ever rushes me
No threats, no countdown, no secret to keep. And asking for help is a reflex, not a failure: saying it out loud to someone makes most scams fall apart.
Two questions to check
Nothing is graded, and nothing is saved anywhere except in your own browser.
An email shows "Customer Service" as the sender. What should you look at to know who's really writing?
See the answer
The full address of the sender, the one with the at sign
The displayed name is a label chosen by whoever is sending, like the signature on a letter. The full address, on the other hand, points to a specific domain: it's the only thing that says where the message really comes from.
An email contains a button that says "Confirm my details". How do you find out where it leads, without taking a risk?
See the answer
I hover over it without clicking, the destination shows up at the bottom of the window
The text on a button is written by the sender, it proves nothing at all. Hovering over it without clicking shows the real destination at the bottom of the window, and you decide afterwards, without having opened anything.
I've done it
Check this box once you can do this skill on your own.
Your progress stays in your own browser.