- From
- Address hidden
- To
- sam@example.com
- Subject
Phish or IT, the daily phishing game
A phishing game for anyone with a work inbox: five emails a day, the same five for everyone. Some are phish, and some are your own company failing its own training.
You work at example. com. Five emails: call each one phish or legit.
Today's round
On today's shift, so this one earns merit.
Today's round Done for todayToday's round done
- Your bestBest
- Next round
Solo round
Today's roundEmail 1 of 5Score 0
Time card
| Jargon quiz | Not punched yet |
|---|---|
| Reorg | Not punched yet |
| Meeting or Email | Not punched yet |
| Boss Key | Not punched yet |
| Coffee Badge | Not punched yet |
| You're on Mute | Not punched yet |
| The Application | Not punched yet |
| Pizza Party | Not punched yet |
| Expense Report | Not punched yet |
| Self-Review | Not punched yet |
| Real or fake | Not punched yet |
| Work memes | Not punched yet |
| What really happened | Not punched yet |
| Reply game | Not punched yet |
Each day's shift is 5 of these 14 games.
The next shift starts at midnight.
This week's review
- Days clocked in
- Merit earned
- Job title
Note from HR
How the phishing game works
Scoring the phishing game
Each email arrives as a printed sheet: the sender, your own address at example.com, the subject and the body. Call it Phish or Legit. A right call scores 100, and a fast one up to 50 more. The bonus holds for 8 seconds, then loses 5 a second. An average adult reads a typical email here in about 9 seconds. A wrong call scores nothing, and five emails make a top score of 750.
Once you call it, the red pen goes over the sheet. It underlines the words that gave the email away and numbers them. Under the verdict, each red flag gets its quote and one line on why it counts.
The speed bonus is the game’s own red flag. Phish push you to act fast, and urgency is a warning sign on both the US and UK government lists. With “Take your time” checked there is no bonus to chase. Every right call pays 100, though the round never sets a best.
Twists, dailies and solo rounds
Today’s twist, when the round has one, sits on the start panel under the game’s one line. Phone view hides every sender’s address until you call it, so the words have to give the email away. Friday at 4:55 holds the full bonus for 4 seconds, then takes 10 a second. Near misses deals five of the hardest calls in a solo round, such as lookalike domains, forged company addresses and real mail from outside partners.
Like the daily jargon quiz, Phish or IT gives everyone the same five emails on the same date. Finishing them on a weekday clocks you in. Solo rounds leave out today’s five and whatever this browser dealt you lately.
What counts as legit
You work at example.com, and on paper so does every real email from your company. Some phish forge that address, and some come from a colleague whose account was taken over. Some real mail comes from outside partners, such as the payroll firm, the travel agency and the building’s managers. For those, the body decides.
The satire, and the real red flags
Why your own IT fails the test
Phish or IT is satire. The company, its people and every address are made up, on domains reserved for examples. The joke is that real company mail breaks the company’s own phishing rules. The phishing training reminder warns that your account may be restricted. Payroll’s tax form email has IMPORTANT in the subject and opens with Dear Employee. The CEO says layoffs the professional way, as changes to our structure that affect some roles.
Training doesn’t fix it either. A 2025 study followed more than 19,500 health system staff for eight months. Whether someone had just done the annual training made no significant difference to whether they clicked. By the eighth month, more than half had clicked at least one test phish.
UK security guidance says no training can teach people to spot every phishing email. It also says blaming the people who click doesn’t work.
The red flags that are real
Every red flag in the game comes from US and UK government security guidance. Six of them are worth checking on any email you get:
- Urgency or a threat: minutes to act, a locked account, pay held back.
- A request for a password, a sign-in code, card numbers or bank details. Anyone who asks for your verification code is a scammer.
- An address or link that nearly matches the real one. Read a domain from the right, so example.com.example.net belongs to example.net.
- A short link or a QR code, which hides where it leads, or an attachment you weren’t expecting.
- Gift cards. No real business asks to be paid in them.
- New bank details for a payment. Check them by phone, on a number you already have.
Spelling tells you less than it did. Scammers now use AI to write clean phishing, so the other signs matter more.
What to do with a suspicious email
Don’t click, reply or open the attachment. Use your mail app’s report button or send it to IT. If it might be real, reach the sender through a number or website you already know, never the one in the email.
If you already clicked, tell IT at once and change any password you entered. People who fear trouble report late or never, so good security teams thank the ones who speak up. For a round where nothing is at stake, Real or fake job titles asks the same kind of question about job titles.
Questions about phishing emails
Is there a free phishing email simulator?
Phish or IT is free and needs no sign-up, and it simulates the inbox only. It never sends an email or tracks who clicks. It shows five made-up emails a day and marks the red flags in each one after your call.
What are the red flags of a phishing email?
Urgency, threats, and any ask for your password, a login code or payment details. Check the sender and every link for a near miss of the real domain, and distrust short links, QR codes and surprise attachments. Bad spelling counts for less now that scammers write with AI.
What should I do if I clicked a phishing link at work?
Tell your IT team straight away, and change any password you typed on the page. The sooner IT hears, the sooner it can lock the account. A good security team thanks you, because people who fear blame report late or never.
Sources
The 19 sources behind this page
- NCSC: Identifying and reporting a suspected phishing email (Exercise in a Box micro exercise)
- NCSC: Phishing attacks, defending your organisation
- NCSC: QR codes, what's the real risk?
- CISA: Recognize and Report Phishing
- CISA: Teach Employees to Avoid Phishing
- CISA: Cybersecurity Advisory AA24-290A
- FBI IC3: Business Email Compromise, the $55 Billion Scam
- FTC: What's a verification code and why would someone ask me for it?
- FTC: Only scammers tell you to buy a gift card to pay them
- FTC: Protect yourself from phishing scams
- UC San Diego Today: Cybersecurity training programs don't prevent employees from falling for phishing scams
- NIST: SP 800-63B-4, Digital Identity Guidelines, Authentication and Authenticator Management
- Microsoft Security: File hosting services misused for identity phishing
- Microsoft Security: Investigating targeted payroll pirate attacks affecting US universities
- Microsoft Learn: File format reference for Word, Excel, and PowerPoint
- Microsoft Learn: Macros from the internet are blocked by default in Office
- Singapore Police Force: Business email compromise scams involving the purchase of gift cards
- BBB Scam Alert: That's not your boss texting
- Journal of Memory and Language (Brysbaert): How many words do we read per minute?
Manager's comment