What this is about

Ten emails have arrived in your practice inbox. Some are genuine, some are traps. Open each one, look closely and decide: genuine or trap? Afterwards you'll see right away what gave it away.

What you practise

Reveal the real sender, read where a link really goes, recognise dangerous attachments.

Your situation in this exercise

You are Sam Taylor. You bank with Kestrelmoor Bank and subscribe to Flickerhaven. At the weekend you ordered a kettle from CraneBasket, and your brother Jonah promised to send you photos from the barbecue.

Tip: point at a link with your mouse without clicking, and just read the address. On a phone, use the “Show link target” button here — in real messages, it's best not to touch the link at all.

On a real phone: don't tap links, and don't press and hold them either. A press that's too short is a tap, and some phones already show a preview of the page. If in doubt, open the app or type the known address yourself. To see where a link leads without opening it, use a computer: point at it with the mouse, don't click. In text messages, the address is usually shown as text anyway — reading it is enough.

iPhone: if a preview does appear, don't tap it — tapping anywhere outside it closes it.

Exercise

The interactive exercise needs JavaScript. Without it, you can read through all messages with their explanations here.

ParcelGull Customer Service <service@parcelgull-delivery.test>

Your parcel is waiting: £1.99 customs fee outstanding

Dear customer,

we were unable to deliver your parcel PG-4471-0925 because a customs fee of £1.99 is outstanding.

Please pay within 24 hours, otherwise the parcel will be returned to the sender: [Pay the fee now → https://parcelgull.test.customs-fee.test/pay]

Your ParcelGull team

Well spotted: this is a trap.

A trap. The link belongs to a completely different address, and the email pushes you to pay quickly. Real parcel services do sometimes send payment links for customs fees — still, only pay in the app or on the website you open yourself.

  • The sender's address ends in parcelgull-delivery.test — not parcelgull.test, the parcel service's address. One extra word makes it a completely different address.
  • The link starts with “parcelgull.test”, but what matters is what comes right before the ending: customs-fee.test. The beginning is just camouflage.
  • A small amount plus a deadline: nobody thinks twice about £1.99 — that's the whole trick. The fake page then asks for your card number.

Kestrelmoor Bank <service@kestrelmoorbank.example>

Your September statement is ready

Hello Sam Taylor,

your statement for September 2026 is ready in your online banking under “Messages”.

For your security, this email contains no link. Please sign in as usual through our app or the address you know.

Kind regards Kestrelmoor Bank

Correct: this message is genuine.

Genuine. Nothing in this email asks you to enter or pay anything through a link.

  • The sender's address ends in kestrelmoorbank.example, which fits your bank. On its own that proves little, because senders can be faked — but here the email also asks nothing of you.
  • No time pressure, no link, nothing to type in. That the email knows your name proves nothing — scammers sometimes know it too. What matters: you're asked to sign in yourself, the usual way.

ParcelGull <notifications@parcelgull.test>

Your CraneBasket parcel arrives today

Hello Sam Taylor,

your parcel from CraneBasket (order 3310-8842) will arrive today between 10 am and 2 pm.

See where your parcel is right now: [Track parcel → https://click.mail-dispatch.test/pg/8KX2QF]

Your ParcelGull team

Correct: this message is genuine.

Genuine. The email fits your order and asks nothing of you. You don't need the link, though: to check, open the ParcelGull app or type the address yourself. And if you chose “trap”, you did nothing wrong — a false alarm costs little.

  • The sender's address ends in parcelgull.test, the parcel service's address. On its own that proves little — but the content fits too: your order and the day CraneBasket mentioned.
  • The link belongs to mail-dispatch.test, not ParcelGull. Real companies often send emails through mailing services like this — so a foreign link target alone doesn't mean “trap”. But you can't tell for sure from the address.
  • No payment, no data, no deadline — just a message that fits your order.

Kestrelmoor Security <security@kestrelmoor-review.example>

Important: your online banking has been temporarily restricted

Dear customer,

during a routine check we noticed unusual sign-in attempts. To protect you, we have restricted your access.

Confirm your identity now so that your account is not permanently blocked: [Confirm identity → https://kestrelmoor-login.example/security/confirm]

After 48 hours we will have to close your account for security reasons.

Kind regards Kestrelmoor Security Team

Well spotted: this is a trap.

A trap. Your bank doesn't ask you to enter your login details through a link — if in doubt, open your banking app yourself.

  • kestrelmoor-review.example is not the bank's address (kestrelmoorbank.example).
  • The link goes to kestrelmoor-login.example — again, not kestrelmoorbank.example.
  • Fear plus a deadline: a threatened block, 48 hours. Reputable banks don't ask you to enter your login details, PIN or codes through a link in an email.

Accounts <invoice@office-billing.test>

Unpaid invoice no. 2026-3381 — final reminder

Hello,

despite our reminder, invoice no. 2026-3381 for £284.90 is still unpaid. Please find the details attached.

Please pay immediately to avoid further costs and debt collection.

📎 Invoice_2026-3381.pdf.html

Well spotted: this is a trap.

A trap: a disguised web page wrapped in a reminder that's designed to scare you.

  • The file ends in .html — that's a web page, not a PDF. The “.pdf” in front is camouflage. Opened, it often shows a fake sign-in window that captures your password.
  • A sender with no company name whom you don't know — and you haven't ordered anything from them.
  • “Final reminder” and “debt collection” are meant to scare you into opening the attachment quickly instead of thinking.

CraneBasket <orders@cranebasket.example>

Your order is on its way

Hi Sam Taylor,

good news: your order 3310-8842 (stainless steel kettle) is on its way and should arrive in the next few days.

You can track it in your account: [View order → https://www.cranebasket.example/account/orders/3310-8842]

Best wishes The CraneBasket team

Correct: this message is genuine.

Genuine. Sender and link match the shop, and you're expecting exactly this delivery. Even safer: open your account yourself from a bookmark.

  • The sender ends in cranebasket.example, which fits the shop — though that alone proves nothing, because senders can be faked.
  • The link also goes to cranebasket.example. The “www.” in front changes nothing.
  • You really did order the kettle, the email names your order, and nobody wants money or data from you.

Flickerhaven <account@flickerhaven-account.example>

Your payment failed — your account will be paused

Hello,

unfortunately we could not collect your monthly fee of £9.99. Your account will therefore be paused.

Update your payment details to keep watching films and series: [Update payment details → https://flickerhaven.example-account.example/payment]

Your Flickerhaven team

Well spotted: this is a trap.

A trap. The link doesn't belong to the streaming service — even though its name appears in it.

  • The sender ends in flickerhaven-account.example instead of flickerhaven.example.
  • It says “flickerhaven.example-account.example”: after “flickerhaven” comes a dot, then it continues with a hyphen. So the address belongs to example-account.example.
  • A threatened pause, a small amount. The missing greeting is only a weak sign — what matters: you only change payment details in an account you opened yourself.

Jonah Taylor <jonah.taylor@mailbox.test>

Photos from the barbecue

Hi Sam,

as promised, here are the photos from the barbecue. You have to see the one with the cake!

Love Jonah

📎 IMG_2041.jpg

📎 IMG_2043.jpg

Correct: this message is genuine.

Genuine. Expected, from a known address, harmless attachments. If something were odd — a link instead of photos, a request for money — you'd give Jonah a quick call.

  • You know this address — it's your brother's, and he said he'd send the photos.
  • Ordinary photos (.jpg), and you were expecting them.
  • A personal tone, a shared experience, no request for money or data.

Grebefold <notifications@grebefold.example>

Kestrelmoor Bank Customer Service shared a document with you

Kestrelmoor Bank Customer Service (kestrelmoor.support@mailbox.test) has shared a document with you:

Account_review_2026.pdf — “Please review and confirm by the end of the week, otherwise your online banking will be restricted.”

The document is ready for you: [Open document → https://grebefold.example/d/7Hq2]

Grebefold — share files and forms with ease

Well spotted: this is a trap.

A trap — even though the sender and the link are genuine. The platform is real, the document isn't: anyone can share files there under someone else's name. So also check who is sharing, and whether the route fits your bank. If in doubt, open your banking app yourself.

  • The sender is right: grebefold.example is the address of the platform the document was shared through. Who shared it is in the text — and that's not your bank but a private email address at mailbox.test.
  • The link is right too: grebefold.example. This is where the address rule ends — it only shows that the page is on the platform, not who put the file there. Anyone can open an account on platforms like this and share under any name.
  • Banks usually put documents in the messages section of your online banking — your bank suddenly sharing through an outside platform doesn't fit. The deadline and the threatened restriction are the bait: behind the link there's usually a fake sign-in page.

Ploverbury Market Prize Draw <prize@ploverbury-promo.test>

Congratulations! Your £500 shopping voucher is waiting

Congratulations!

You have been drawn as a winner in our anniversary prize draw and receive a £500 shopping voucher.

Claim your prize within 12 hours. There is just a £2 handling fee for delivery: [Claim your prize now → https://ploverbury-voucher.test/claim?id=58213]

Well spotted: this is a trap.

A trap. A prize you have to pay for first isn't a prize.

  • You never entered a prize draw. And real winners don't have to pay anything — certainly not through a link.
  • ploverbury-promo.test is not ploverbury.test.
  • The link belongs to ploverbury-voucher.test — yet another address.

All companies, people, addresses and numbers in the exercises are invented. Any resemblance to real companies or people would be purely coincidental and unintended.

An unhandled error has occurred. Reload 🗙

Rejoining the server…

Rejoin failed… trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.