High School BeginnerModule B9Lesson 2 of 7

B9.2 Phishing Email Warning Signs

Learn how to inspect sender details, subject lines, wording, requests, links, attachments, and context without interacting with suspicious email content.

Lesson Progress

Phishing Email Warning Signs

High School BeginnerB9: Phishing and Social Engineering Defense • Lesson 2 of 7

29% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

A Professional-Looking Email Can Still Be Fake

Phishing emails may use copied logos, familiar names, official colors, realistic signatures, and correct personal details. Defenders look beyond appearance and inspect the full sender, request, context, destination, and file evidence.

Safety reminder: every email, sender, domain, link, attachment, account, and organization in this lesson is fictional. Never use real suspicious content.

Learning Objective

Inspect display name, full sender address, domain, subject, wording, request, link, attachment, and context.

Learning Objective

Identify mismatches, urgency, credential requests, unexpected files, and unofficial destinations.

Learning Objective

Verify suspicious email claims through a separate official channel and report them safely.

Why This Matters

Email Is Often the Beginning of a Larger Incident

A phishing email may attempt to steal credentials, capture MFA codes, deliver a suspicious file, request money, change account recovery, or pressure the target into approving access. Recognizing warning signs early can prevent several connected problems.

Visual Diagram

The Phishing Email Review Flow

Strong email review checks the sender, request, evidence, and official verification path before any interaction.

1

Check the sender

Compare the display name, full address, domain, and whether the sender is expected.

2

Check the request

Identify what the message wants: a click, reply, login, payment, download, approval, or sensitive information.

3

Check the evidence

Review urgency, wording, links, attachments, context, and whether the request matches normal procedures.

4

Verify separately

Use the official website, school portal, directory, known phone number, or trusted person instead of the email.

Defender rule: inspect displayed evidence without clicking links, opening attachments, replying, calling numbers, or entering information.

Core Concept

Compare Identity, Request, and Context

The strongest phishing judgments use multiple clues. A mismatched sender, unusual request, urgent deadline, suspicious destination, unexpected attachment, and broken context become more meaningful when considered together.

Key Vocabulary

Terms for Phishing Email Analysis

Sender address

The full email address that shows where a message was sent from, which may differ from the displayed name.

Display name

The visible sender name shown by an email service. It can be copied and does not prove identity.

Domain

The main website or email address name associated with an organization, such as the part after the @ symbol.

Spoofing

Making a message or sender identity appear to come from a trusted person or organization.

Link destination

The website address a link is expected to open. It should match the official service and context.

Attachment

A file included with an email. Unexpected or suspicious attachments should not be opened or tested.

Technical Breakdown

Phishing Email Clue Board

No single clue proves everything. Defenders compare several pieces of evidence before deciding whether an email is normal, suspicious, or report-first.

Sender identity

Review question

Do the display name, full address, domain, and expected sender all match?

Safer choice

Treat mismatches as warning signs and verify through a known official channel.

Request and pressure

Review question

Does the email ask for credentials, codes, money, downloads, approvals, secrecy, or immediate action?

Safer choice

Pause and confirm the request independently before doing anything.

Links and destinations

Review question

Does the displayed link appear to match the official service and context?

Safer choice

Do not use the email link; open the official website or app directly.

Attachments and files

Review question

Was the file expected, and does its name, type, sender, and purpose make sense?

Safer choice

Do not open unexpected files; verify the sender and assignment separately.

Fake Dashboard

Phishing Email Warning-Sign Panel

This fictional panel helps students compare sender, subject, request, link, attachment, and context clues safely.

Fake Data

Sender mismatch

Display name says School Support, but the address uses an unrelated domain

Strong warning sign. Do not reply; verify through the official school directory or portal.

Urgent account threat

Subject says account closes today unless the student signs in

Urgency clue. Open the official account directly and review alerts there.

Unexpected attachment

File claims to contain an updated class schedule

Do not open it. Confirm the schedule through the official portal or teacher.

Credential request

Message asks the student to reply with a password and MFA code

High-risk request. Never share credentials or codes; report the email.

Known portal notice

Notification appears inside the official school portal

More trustworthy context, but still review the request and avoid sharing sensitive information.

Fake Dashboard

Fake Phishing Email Dashboard

Training dashboard using fictional sender, subject, request, link, attachment, and verification evidence.

Emails reviewed

24

Fictional school, account, prize, payment, and support messages.

Sender mismatches

9

Display names did not match the full sender address or expected domain.

Reported safely

11

Suspicious messages were verified separately and reported through approved channels.

Fake SOC Alert

School Support Email Requests Password and MFA Code

Source: Fake School Email Training • Time: 10:26 AM

High Severity
A fictional email uses the display name School Support, but the sender address uses an unrelated domain and asks the student to reply with a password and MFA code.
Defensive recommendation: Do not reply or share credentials. Open the official school portal, contact technology staff through the school directory, and report the email.

Fake Log Panel

Fake Email Analysis Log

training-log-viewer.log
10:14:06 EMAIL display_name='School Support' sender_domain='unrelated-example.test'
10:15:31 SUBJECT urgency='account_closes_today'
10:17:04 REQUEST password='true' mfa_code='true'
10:19:22 LINK destination_match='false' action='not_opened'
10:23:18 VERIFICATION channel='official_school_directory' result='message_not_confirmed'
10:26:02 REPORT method='school_phishing_report' status='submitted'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Which Clues Make This Email Suspicious?

The display name says School Technology Office.
The full sender address uses an unrelated domain.
The email threatens account closure in ten minutes.
The message asks for a password and MFA code.

What is the safest conclusion?

Common Mistakes

Mistakes That Weaken Email Judgment

Trusting the display name without checking the full sender address.
Clicking a link because the message uses a real logo or familiar colors.
Assuming grammar or spelling alone can prove whether an email is legitimate.
Opening an unexpected attachment to see what it contains.
Replying with a password, MFA code, recovery code, or private information.
Using the suspicious email’s link, phone number, or reply button to verify the message.

Safe Defensive Lab

Classify Fictional Emails Without Interacting

Fake Email Set

School Email Review

A fictional student receives an urgent account warning, an unexpected schedule attachment, a prize email, a fake support request, and one verified portal notification.

Defender Review Steps

  • Check the display name, full address, and domain.
  • Identify urgency, fear, rewards, secrecy, or authority pressure.
  • Identify the requested action and sensitive information involved.
  • Review link and attachment clues without opening them.
  • Classify each message as normal, suspicious, or report-first.

Scenario Decision Lab

A Teacher Email Contains an Unexpected Attachment

A fictional email uses a teacher’s name and includes a file called UpdatedExamSchedule.zip. The message came from an unfamiliar address, and the student was not expecting the file.

Scenario Decision Lab

An Account Warning Uses a Login Button

A fictional email says the student’s account will be deleted today and provides a button labeled Verify Now.

Defender Habits

Phishing Email Warning-Sign Checklist

Check Your Understanding

B9.2 Mini Quiz: Phishing Email Warning Signs

Choose your answers first. Explanations appear only after submission.

1. Why is the display name not enough to prove who sent an email?

2. Which clue is the strongest sender warning sign?

3. What is the safest response to an urgent account-warning email?

4. What should a student do with an unexpected attachment?

5. Which request should never be completed through email?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional phishing email analysis sheet. Include sender details, subject, request, pressure tactic, link or attachment clue, context, classification, verification channel, and recommended response.

Use fictional sender addresses, domains, links, attachments, organizations, and account details only.
Do not include real suspicious URLs, files, credentials, or private information.
Explain how several clues support the final classification.

Key Takeaways

What You Should Remember

1.A display name, logo, signature, or professional design does not prove who sent an email.
2.The full sender address and domain are important evidence.
3.Urgent deadlines, credential requests, suspicious links, and unexpected attachments are major warning signs.
4.Suspicious claims should be verified through a separate official channel.
5.Students should inspect displayed evidence without clicking, replying, downloading, opening, forwarding, uploading, or testing content.

Navigation

Continue Module B9