B9.2 Phishing Email Warning Signs
Learn how to inspect sender details, subject lines, wording, requests, links, attachments, and context without interacting with suspicious email content.
Lesson Progress
Phishing Email Warning Signs
High School Beginner • B9: Phishing and Social Engineering Defense • Lesson 2 of 7
Readiness Check
Before You Start
0/3 ready
Professional Hook
A Professional-Looking Email Can Still Be Fake
Phishing emails may use copied logos, familiar names, official colors, realistic signatures, and correct personal details. Defenders look beyond appearance and inspect the full sender, request, context, destination, and file evidence.
Learning Objective
Inspect display name, full sender address, domain, subject, wording, request, link, attachment, and context.
Learning Objective
Identify mismatches, urgency, credential requests, unexpected files, and unofficial destinations.
Learning Objective
Verify suspicious email claims through a separate official channel and report them safely.
Why This Matters
Email Is Often the Beginning of a Larger Incident
A phishing email may attempt to steal credentials, capture MFA codes, deliver a suspicious file, request money, change account recovery, or pressure the target into approving access. Recognizing warning signs early can prevent several connected problems.
Visual Diagram
The Phishing Email Review Flow
Strong email review checks the sender, request, evidence, and official verification path before any interaction.
Check the sender
Compare the display name, full address, domain, and whether the sender is expected.
Check the request
Identify what the message wants: a click, reply, login, payment, download, approval, or sensitive information.
Check the evidence
Review urgency, wording, links, attachments, context, and whether the request matches normal procedures.
Verify separately
Use the official website, school portal, directory, known phone number, or trusted person instead of the email.
Core Concept
Compare Identity, Request, and Context
The strongest phishing judgments use multiple clues. A mismatched sender, unusual request, urgent deadline, suspicious destination, unexpected attachment, and broken context become more meaningful when considered together.
Key Vocabulary
Terms for Phishing Email Analysis
Sender address
The full email address that shows where a message was sent from, which may differ from the displayed name.
Display name
The visible sender name shown by an email service. It can be copied and does not prove identity.
Domain
The main website or email address name associated with an organization, such as the part after the @ symbol.
Spoofing
Making a message or sender identity appear to come from a trusted person or organization.
Link destination
The website address a link is expected to open. It should match the official service and context.
Attachment
A file included with an email. Unexpected or suspicious attachments should not be opened or tested.
Technical Breakdown
Phishing Email Clue Board
No single clue proves everything. Defenders compare several pieces of evidence before deciding whether an email is normal, suspicious, or report-first.
Sender identity
Review question
Do the display name, full address, domain, and expected sender all match?
Safer choice
Treat mismatches as warning signs and verify through a known official channel.
Request and pressure
Review question
Does the email ask for credentials, codes, money, downloads, approvals, secrecy, or immediate action?
Safer choice
Pause and confirm the request independently before doing anything.
Links and destinations
Review question
Does the displayed link appear to match the official service and context?
Safer choice
Do not use the email link; open the official website or app directly.
Attachments and files
Review question
Was the file expected, and does its name, type, sender, and purpose make sense?
Safer choice
Do not open unexpected files; verify the sender and assignment separately.
Fake Dashboard
Phishing Email Warning-Sign Panel
This fictional panel helps students compare sender, subject, request, link, attachment, and context clues safely.
Sender mismatch
Display name says School Support, but the address uses an unrelated domain
Strong warning sign. Do not reply; verify through the official school directory or portal.
Urgent account threat
Subject says account closes today unless the student signs in
Urgency clue. Open the official account directly and review alerts there.
Unexpected attachment
File claims to contain an updated class schedule
Do not open it. Confirm the schedule through the official portal or teacher.
Credential request
Message asks the student to reply with a password and MFA code
High-risk request. Never share credentials or codes; report the email.
Known portal notice
Notification appears inside the official school portal
More trustworthy context, but still review the request and avoid sharing sensitive information.
Fake Dashboard
Fake Phishing Email Dashboard
Training dashboard using fictional sender, subject, request, link, attachment, and verification evidence.
Emails reviewed
24
Fictional school, account, prize, payment, and support messages.
Sender mismatches
9
Display names did not match the full sender address or expected domain.
Reported safely
11
Suspicious messages were verified separately and reported through approved channels.
Fake SOC Alert
School Support Email Requests Password and MFA Code
Source: Fake School Email Training • Time: 10:26 AM
Fake Log Panel
Fake Email Analysis Log
10:14:06 EMAIL display_name='School Support' sender_domain='unrelated-example.test' 10:15:31 SUBJECT urgency='account_closes_today' 10:17:04 REQUEST password='true' mfa_code='true' 10:19:22 LINK destination_match='false' action='not_opened' 10:23:18 VERIFICATION channel='official_school_directory' result='message_not_confirmed' 10:26:02 REPORT method='school_phishing_report' status='submitted'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Which Clues Make This Email Suspicious?
What is the safest conclusion?
Common Mistakes
Mistakes That Weaken Email Judgment
Safe Defensive Lab
Classify Fictional Emails Without Interacting
Fake Email Set
School Email Review
A fictional student receives an urgent account warning, an unexpected schedule attachment, a prize email, a fake support request, and one verified portal notification.
Defender Review Steps
- Check the display name, full address, and domain.
- Identify urgency, fear, rewards, secrecy, or authority pressure.
- Identify the requested action and sensitive information involved.
- Review link and attachment clues without opening them.
- Classify each message as normal, suspicious, or report-first.
Scenario Decision Lab
A Teacher Email Contains an Unexpected Attachment
A fictional email uses a teacher’s name and includes a file called UpdatedExamSchedule.zip. The message came from an unfamiliar address, and the student was not expecting the file.
Scenario Decision Lab
An Account Warning Uses a Login Button
A fictional email says the student’s account will be deleted today and provides a button labeled Verify Now.
Defender Habits
Phishing Email Warning-Sign Checklist
Check Your Understanding
B9.2 Mini Quiz: Phishing Email Warning Signs
Choose your answers first. Explanations appear only after submission.
1. Why is the display name not enough to prove who sent an email?
2. Which clue is the strongest sender warning sign?
3. What is the safest response to an urgent account-warning email?
4. What should a student do with an unexpected attachment?
5. Which request should never be completed through email?
Portfolio Prompt
Portfolio Prompt
Create a one-page fictional phishing email analysis sheet. Include sender details, subject, request, pressure tactic, link or attachment clue, context, classification, verification channel, and recommended response.
Key Takeaways
What You Should Remember
Navigation