πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout

Free tool Β· Arcade

Pick the Phish

Fifty emails have landed in your inbox. Ten of them are phishing. Work the inbox like an analyst β€” read the headers, hover the links, check the attachments β€” and report the ones that are hostile.

How it is scored

  • +10 for every phishing email you report
  • βˆ’6 for every legitimate email you report
  • Pass catch 6 of 10 and keep false positives to 3 or fewer

Reporting everything does not work. Precision counts as much as recall β€” the same as it does on a real triage queue.

Your tools

  • πŸ”Ž Show original β€” full headers with SPF, DKIM and DMARC results
  • πŸ”— Inspect links β€” the true destination behind every link
  • πŸ“Ž Attachments β€” real filenames, real extensions

Authentication passing does not mean an email is safe. Some of these are sent from genuinely compromised accounts.

Make it your inbox Β· optional

Enter your name and your organisation's website or domain, and the whole inbox reads like your real one β€” addressed to you, from colleagues at your domain, with mail that fits your industry. Visual only; it doesn't change the puzzle or the answers.

Leave blank to use the default inbox.

A fresh set of 50 is dealt every time you play.

Optional low-volume ambient music (πŸ”Š in the inbox) β€” β€œDeep Haze” by Kevin MacLeod (incompetech.com), CC BY 4.0.

Pick the Phish β€” spot the phishing emails | PlayCISO Β· PlayCISO