I Built a Phishing Email Game to See If You Can Spot a Scam

I Built a Phishing Email Game to See If You Can Spot a Scam

I Built a Phishing Email Game to See If You Can Spot a Scam

Phishing Email Challenge inbox screen

Reading an article about phishing is easy. You nod along at the screenshots, you spot the obvious "URGENT: verify your account NOW" subject line, and you feel confident you'd never fall for it.

Then a well-written email lands in your actual inbox, formatted correctly, referencing something plausible, and for a second you're not so sure. That gap — between recognizing phishing in a tutorial and recognizing it in the moment, under a little pressure — is exactly what I wanted to train. So I built the Phishing Email Challenge, a free interactive game where you're handed a realistic inbox and have to make the call yourself.

What this covers: How the game works and what you're asked to decide. The real clues that separate legitimate, phishing, and suspicious emails. Why I built this as a game instead of another "how to spot phishing" checklist article.

Why I Built This

Most phishing awareness content works the same way: a numbered list of red flags, a couple of obvious screenshots, and a "now you know" ending. It's useful as a reference, but it doesn't test anything. You can read ten articles about phishing red flags and still hesitate on a real email, because reading a list and applying it under time pressure use different parts of your brain.

I wanted something closer to what actually happens: an email shows up, it looks mostly normal, and you have to decide — right now, without a checklist in front of you — whether to trust it. That's the whole premise of the challenge.

How the Game Works

Example phishing email in the challenge

You get a simulated inbox full of emails — some real-looking, some fake, some in a gray zone that's not obviously malicious but isn't clean either. For each one, you have to sort it into one of three buckets:

Legitimate
A normal, safe email — correct domain, sensible context, nothing manipulative about the request.
Phishing
A malicious email designed to steal credentials, install malware, or trick you into an action that benefits the attacker.
Suspicious
Not clearly malicious, but off enough that a careful person should slow down, verify the sender, or check before acting — this bucket is the one most people get wrong.

That third category matters more than it seems. Real inboxes aren't split cleanly into "obviously safe" and "obviously a scam." A lot of real-world phishing lands in that ambiguous middle, and learning to recognize "I should verify this before I act" is arguably a more useful reflex than spotting an email that's already blatantly fake.

Example legitimate email in the challenge

The Clues That Actually Give Phishing Away

Every email in the challenge is built around one or more of these signals — the same ones that show up in real phishing campaigns, not made-up textbook examples:

Suspicious Sender
The display name says "IT Support" or "Bank Security," but the actual address behind it doesn't match — a different domain, a string of random characters, or a free email provider pretending to be a company.
Fake Domains
Lookalike domains that swap a letter, add a hyphen, or use an unrelated TLD — paypa1.com instead of paypal.com, or a company name tacked onto a domain that isn't theirs at all.
Urgency
"Your account will be suspended in 24 hours," "immediate action required," "final notice." Urgency is deliberate — it's designed to make you act before you think to verify.
Malicious Links
A link's display text says one thing, but the actual URL underneath points somewhere else entirely — often a domain that has nothing to do with the sender it claims to be from.
Unexpected Attachments
An invoice, resume, or "important document" you weren't expecting, especially from a sender you don't normally exchange files with, is one of the oldest and still most effective delivery methods for malware.
Grammar & Context
Awkward phrasing, inconsistent formatting, or a request that doesn't fit the relationship — like a "CEO" emailing a junior employee directly asking for gift cards — is a context mismatch worth noticing.
Spoofed Branding
Logos, colors, and layout copied from a real company to create instant trust, while small details — a wrong logo version, an off font, a mismatched footer — give it away on closer inspection.
Credential Requests
Legitimate companies rarely ask you to "confirm your password" by clicking a link in an email. A request for login details, security codes, or payment info inside an email is a major red flag on its own.
Social-Engineering Tactics
Authority ("this is your manager"), fear ("suspicious login detected"), or reward ("you've won") — these emails are engineered to trigger a reaction before your critical thinking kicks in.
Decision screen where the player classifies the email

Instant Explanations After Every Decision

Explanation screen after answering

After every decision, the game shows you exactly which clues were present and why the email was legitimate, phishing, or suspicious. Getting it right without knowing why isn't useful — the explanation is where the actual pattern-recognition training happens.

Why the Explanation Matters More Than the Score

The emails that trip people up the most are the well-made phishing attempts — correct grammar, a domain that's close enough not to raise alarm at a glance, a request that sounds plausible. Getting one of those wrong and then seeing exactly which detail gave it away is far more useful than a checklist you read once and forget. That single moment of "oh, that's the tell" tends to stick.

Final Score

Final score results screen

At the end of a round, you get a breakdown of how many emails you classified correctly, split across legitimate, phishing, and suspicious. It's a quick, honest gut-check on how sharp your instincts actually are — not just whether you can define "phishing," but whether you can catch it in the moment.

3 Classification categories: Legitimate, Phishing, Suspicious
9 Core red-flag categories built into the emails

Why This Matters Beyond a Game

What Practicing This Actually Trains

  • Speed of recognition: Real phishing doesn't wait for you to research it — you need to notice something's off in the few seconds before you'd normally click.
  • The gray zone reflex: Learning to flag "suspicious" instead of forcing a yes/no call is often more valuable than spotting obvious fakes.
  • Attention to small details: A single mismatched domain letter or a link that doesn't match its display text is often the only tell — training your eye to catch it matters.
  • Resistance to urgency: Once you've seen urgency used as a manipulation tactic a dozen times in the game, it's much easier to recognize the same trick in a real inbox.
  • Awareness that isn't theoretical: Security awareness training only works if it changes behavior in the moment — a game that forces a real decision does that better than a slide deck.
Try it yourself

Open the inbox, make the call, and see how many you actually get right.

Play the Phishing Email Challenge

What's Next

I'm planning to keep adding new email scenarios, including more of the gray-zone "suspicious" cases since those are where people learn the most. If you play it and there's a phishing tactic you think is missing, or an email that felt unrealistic, let me know — that feedback goes straight into what gets added next.

Phishing Email Challenge FAQs

Is the Phishing Email Challenge free?
Yes. You can start sorting emails straight away without creating an account. It's built as a free security awareness tool.
What's the difference between "phishing" and "suspicious" in the game?
Phishing emails are clearly malicious — they're built to steal credentials, deliver malware, or trick you into a harmful action. Suspicious emails aren't confirmed malicious, but they carry enough red flags that a careful person should verify before acting on them. Learning to separate the two is one of the main points of the game.
Are the emails based on real phishing tactics?
Yes. Every email is built around real-world red flags — spoofed domains, urgency, credential requests, spoofed branding, and other tactics that show up constantly in actual phishing campaigns.
Who is this game for?
Anyone who wants sharper phishing instincts — security learners, employees going through awareness training, SOC analysts, or just people who want to feel more confident spotting scams in their own inbox.
Does it explain why an email was phishing or legitimate?
Yes. After every decision, the game shows exactly which clues were present, so you understand the reasoning instead of just seeing right or wrong.

About the Author

Amardeep Maroli

Built the Phishing Email Challenge to turn phishing awareness from a checklist into a trained reflex. Writes about practical, hands-on cybersecurity topics based on real experiments and projects.

Tags: phishing, social engineering, security awareness, email security, side project

Played the challenge? Let me know which email fooled you first.

Post a Comment

0 Comments