I Built a Phishing Email Game to See If You Can Spot a Scam
Reading an article about phishing is easy. You nod along at the screenshots, you spot the obvious "URGENT: verify your account NOW" subject line, and you feel confident you'd never fall for it.
Then a well-written email lands in your actual inbox, formatted correctly, referencing something plausible, and for a second you're not so sure. That gap — between recognizing phishing in a tutorial and recognizing it in the moment, under a little pressure — is exactly what I wanted to train. So I built the Phishing Email Challenge, a free interactive game where you're handed a realistic inbox and have to make the call yourself.
Why I Built This
Most phishing awareness content works the same way: a numbered list of red flags, a couple of obvious screenshots, and a "now you know" ending. It's useful as a reference, but it doesn't test anything. You can read ten articles about phishing red flags and still hesitate on a real email, because reading a list and applying it under time pressure use different parts of your brain.
I wanted something closer to what actually happens: an email shows up, it looks mostly normal, and you have to decide — right now, without a checklist in front of you — whether to trust it. That's the whole premise of the challenge.
How the Game Works
You get a simulated inbox full of emails — some real-looking, some fake, some in a gray zone that's not obviously malicious but isn't clean either. For each one, you have to sort it into one of three buckets:
That third category matters more than it seems. Real inboxes aren't split cleanly into "obviously safe" and "obviously a scam." A lot of real-world phishing lands in that ambiguous middle, and learning to recognize "I should verify this before I act" is arguably a more useful reflex than spotting an email that's already blatantly fake.
The Clues That Actually Give Phishing Away
Every email in the challenge is built around one or more of these signals — the same ones that show up in real phishing campaigns, not made-up textbook examples:
Instant Explanations After Every Decision
After every decision, the game shows you exactly which clues were present and why the email was legitimate, phishing, or suspicious. Getting it right without knowing why isn't useful — the explanation is where the actual pattern-recognition training happens.
The emails that trip people up the most are the well-made phishing attempts — correct grammar, a domain that's close enough not to raise alarm at a glance, a request that sounds plausible. Getting one of those wrong and then seeing exactly which detail gave it away is far more useful than a checklist you read once and forget. That single moment of "oh, that's the tell" tends to stick.
Final Score
At the end of a round, you get a breakdown of how many emails you classified correctly, split across legitimate, phishing, and suspicious. It's a quick, honest gut-check on how sharp your instincts actually are — not just whether you can define "phishing," but whether you can catch it in the moment.
Why This Matters Beyond a Game
What Practicing This Actually Trains
- Speed of recognition: Real phishing doesn't wait for you to research it — you need to notice something's off in the few seconds before you'd normally click.
- The gray zone reflex: Learning to flag "suspicious" instead of forcing a yes/no call is often more valuable than spotting obvious fakes.
- Attention to small details: A single mismatched domain letter or a link that doesn't match its display text is often the only tell — training your eye to catch it matters.
- Resistance to urgency: Once you've seen urgency used as a manipulation tactic a dozen times in the game, it's much easier to recognize the same trick in a real inbox.
- Awareness that isn't theoretical: Security awareness training only works if it changes behavior in the moment — a game that forces a real decision does that better than a slide deck.
Open the inbox, make the call, and see how many you actually get right.
Play the Phishing Email ChallengeWhat's Next
I'm planning to keep adding new email scenarios, including more of the gray-zone "suspicious" cases since those are where people learn the most. If you play it and there's a phishing tactic you think is missing, or an email that felt unrealistic, let me know — that feedback goes straight into what gets added next.
0 Comments