TechKnowSurge
CompTIA Security+ 2.2 ISC2 CC 2.3 CompTIA Security+ 5.6
InteractiveSecurityFree

Phishing Email Red Flag Spotter

Read a fake payroll email line by line and flag the five red flags hiding among the innocent lines.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Everyone can recite the phishing advice — check the sender, hover the link, watch for urgency — and almost everyone still clicks, because reciting a checklist and applying one to a real message under time pressure are different skills. This activity closes that gap by putting an actual message in front of you. A payroll notice arrives claiming your direct deposit is about to be suspended; it carries a logo, a plausible subject line, a real vendor's name, and a button that makes the problem go away. Five things about it are wrong, and you have to find them by clicking the lines that carry them. Because there is no mouse-hover in a rendered artifact, every link is printed with its display text beside its true destination — the same thing hovering would have told you, and the comparison one of the flags depends on. Submit, and each planted flag opens with the rule behind it rather than a verdict about this one email: why an address is read from the right-hand end, why a logo fetched from a stranger's server is not the sender's logo, why manufactured panic always arrives packaged with its own one-click cure, and why the letter pair "rn" has been impersonating an "m" since the invention of the screen font. The innocent lines are marked too. One of the links in this message is entirely genuine, sitting a few rows below the fake one, and the external-sender banner at the top is a control doing its job — flagging either costs you nothing, but seeing which ones you flagged is the point, because a colleague who reports every message is nearly as expensive as one who reports none.

What you'll learn

Aligned to

CompTIA Security+
2.2 Explain common threat vectors and attack surfaces.
5.6 Given a scenario, implement security awareness practices.
ISC2 CC
2.3 Understand security awareness

Key terms

Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Urgency
A social engineering tactic that pressures a target to act immediately, reducing the likelihood of logical evaluation before compliance.
Typosquatting
A form of impersonation that registers misspelled or look-alike domain names to deceive users into visiting fraudulent websites.
Brand Impersonation
A social engineering technique where an attacker poses as a well-known company or organization to gain a victim's trust and extract information or access.
Spoofing
An attack where an adversary impersonates a trusted entity by falsifying data such as an IP address or email address.
Credential Harvesting
A technique used by attackers to capture usernames and passwords by impersonating a trusted application or login interface.
URL Obfuscation
A technique that disguises a URL's true destination by encoding the target address using methods such as hexadecimal, octal, or username-field embedding to deceive users.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Business Email Compromise
BEC
An attack where a threat actor impersonates a trusted person within an organization via email to deceive employees, often by spoofing or compromising a legitimate email address.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.
Phishing Simulation
A controlled exercise that sends fake phishing emails to employees to test and reinforce their ability to recognize and report phishing attempts.

Topics

Interactive Spot The Error

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →