Blog/Phishing

Testing Yourself: Phishing Quiz With Explained Answers

Six illustrative messages: some phishing, some genuine. Decide for each one, then read the explanation. A quick way to practise spotting phishing emails and texts.

CyberWatch AI2 October 2026 · 2 min read
A blue question mark on a pink background

Read each illustrative message and decide: phishing or genuine? Then read the explanation underneath. None of these are real messages, and all links are deliberately broken.

Question 1

Illustrative example · Email
From: IT Service Desk <helpdesk@company-mailbox-support[.]com>
Your mailbox is 98% full. Messages will be rejected after 5pm today. Increase your storage: hxxps://company-mailbox-support[.]com/upgrade
Phishing. The sender domain is not your organization's, there is a same-day deadline, and the link asks you to log in. See IT-themed phishing.

Question 2

Illustrative example · Text message
Your parcel could not be delivered due to an incomplete address. Update within 12 hours: hxxps://parcel-redeliver-now[.]info
Phishing. No courier name, no tracking number, a short deadline and an unrelated domain. See parcel delivery text scams.

Question 3

Illustrative example · Email
Hi, your order has shipped. You can track it in your account under Orders. We will never ask for your password or payment details by email.
Probably genuine. No link to click, no request for details, and it points you to your account. Still, check through the app rather than any link.

Question 4

Illustrative example · Email from a known supplier's real address
Hello, please note our bank details have changed following an audit. Kindly use the attached details for this month's invoice. Our phone lines are down, so please reply by email only.
Phishing, even from a real address. The supplier's account may be compromised. Changed bank details plus "email only" is the classic sign. Call them on a known number. See vendor email compromise.

Question 5

Illustrative example · Phone call
"This is your bank's fraud team. We have stopped a suspicious payment. To cancel it, please read me the code we have just sent to your phone."
Phishing (vishing). Your bank will never ask you to read out a code. Hang up and call the number on your card. See fake fraud department calls.

Question 6

Illustrative example · Email
A document has been shared with you: "Q3 Salary Adjustments.pdf". Open in browser: hxxps://docs-view-secure[.]app/file
Phishing. A tempting title, an unknown sharing domain, and it will ask you to log in to "view". See document share phishing.

The method behind every answer

  1. Sender: is the address exactly right?
  2. Link: where does it really go? See how to read a URL.
  3. Request: does it ask for a login, code, payment or file?
  4. Pressure: is there a deadline or a threat?

Got a real message you are unsure about? Paste it into CyberWatch AI Scan for a free check.

Spotted one? See how to report phishing in our complete guide.

Frequently asked questions

Are these real phishing messages?

No. They are illustrative examples written to show common patterns. Links are broken on purpose so they cannot be clicked.

What if I got some wrong?

That is the point of practising. Focus on the method: check the sender, the link, the request and the pressure.

Can a genuine message look suspicious?

Yes. That is why the safest habit is to check through the official app or website, whatever the message looks like.

Sources

  1. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  2. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
  3. Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.