Cybersecurity skill game
Phishing Detector.
Read each cybersecurity email like an analyst on shift. Call it phishing, suspicious, or legitimate. After every verdict, a tradecraft breakdown explains what you saw, what you missed, and why it matters in real incident response work.
Email 1 of 8
Score: 0
[IT] Mandatory password reset before April 28
From: IT Helpdesk <it-helpdesk@yourcompany.com>
To: you@example.com · Today 09:15
As part of our quarterly security policy, all employees must reset their passwords before April 28.
Use the self-service portal: yourcompany-passwordreset.com/portal
Failure to reset will result in account suspension on April 29.
If you have questions, reply to this email.
Hover preview, actual link targets
yourcompany-passwordreset.com/portal → https://yourcompany-passwordreset.com/portal
How to read the verdicts
Phishing means there is enough evidence in the visible email to conclude malicious intent: a lookalike sender domain, a credential-harvester link, a financial-fraud pattern, or a clear pretext.
Suspicious means the email may be malicious but cannot be confirmed from the email alone. Real analyst behavior here is to verify out-of-band, check headers and SPF/DKIM/DMARC, and not click. Suspicious is the right call when the email pattern is ambiguous.
Legitimate means the sender, link target, tone, and request all align with a normal communication from the claimed source. Phishers imitate these patterns, so being able to recognize the real thing is half the cybersecurity skill.
Definitions are original explanations written for career development purposes. For authoritative technical definitions, refer to NIST, ISO, or the relevant standards body.