Phish or IT, the daily phishing game

A phishing game for anyone with a work inbox: five emails a day, the same five for everyone. Some are phish, and some are your own company failing its own training.

You work at example. com. Five emails: call each one phish or legit.

Today's round

Solo round

How the phishing game works

Scoring the phishing game

Each email arrives as a printed sheet: the sender, your own address at example.com, the subject and the body. Call it Phish or Legit. A right call scores 100, and a fast one up to 50 more. The bonus holds for 8 seconds, then loses 5 a second. An average adult reads a typical email here in about 9 seconds. A wrong call scores nothing, and five emails make a top score of 750.

Once you call it, the red pen goes over the sheet. It underlines the words that gave the email away and numbers them. Under the verdict, each red flag gets its quote and one line on why it counts.

The speed bonus is the game’s own red flag. Phish push you to act fast, and urgency is a warning sign on both the US and UK government lists. With “Take your time” checked there is no bonus to chase. Every right call pays 100, though the round never sets a best.

Twists, dailies and solo rounds

Today’s twist, when the round has one, sits on the start panel under the game’s one line. Phone view hides every sender’s address until you call it, so the words have to give the email away. Friday at 4:55 holds the full bonus for 4 seconds, then takes 10 a second. Near misses deals five of the hardest calls in a solo round, such as lookalike domains, forged company addresses and real mail from outside partners.

Like the daily jargon quiz, Phish or IT gives everyone the same five emails on the same date. Finishing them on a weekday clocks you in. Solo rounds leave out today’s five and whatever this browser dealt you lately.

What counts as legit

You work at example.com, and on paper so does every real email from your company. Some phish forge that address, and some come from a colleague whose account was taken over. Some real mail comes from outside partners, such as the payroll firm, the travel agency and the building’s managers. For those, the body decides.

The satire, and the real red flags

Why your own IT fails the test

Phish or IT is satire. The company, its people and every address are made up, on domains reserved for examples. The joke is that real company mail breaks the company’s own phishing rules. The phishing training reminder warns that your account may be restricted. Payroll’s tax form email has IMPORTANT in the subject and opens with Dear Employee. The CEO says layoffs the professional way, as changes to our structure that affect some roles.

Training doesn’t fix it either. A 2025 study followed more than 19,500 health system staff for eight months. Whether someone had just done the annual training made no significant difference to whether they clicked. By the eighth month, more than half had clicked at least one test phish.

UK security guidance says no training can teach people to spot every phishing email. It also says blaming the people who click doesn’t work.

The red flags that are real

Every red flag in the game comes from US and UK government security guidance. Six of them are worth checking on any email you get:

  • Urgency or a threat: minutes to act, a locked account, pay held back.
  • A request for a password, a sign-in code, card numbers or bank details. Anyone who asks for your verification code is a scammer.
  • An address or link that nearly matches the real one. Read a domain from the right, so example.com.example.net belongs to example.net.
  • A short link or a QR code, which hides where it leads, or an attachment you weren’t expecting.
  • Gift cards. No real business asks to be paid in them.
  • New bank details for a payment. Check them by phone, on a number you already have.

Spelling tells you less than it did. Scammers now use AI to write clean phishing, so the other signs matter more.

What to do with a suspicious email

Don’t click, reply or open the attachment. Use your mail app’s report button or send it to IT. If it might be real, reach the sender through a number or website you already know, never the one in the email.

If you already clicked, tell IT at once and change any password you entered. People who fear trouble report late or never, so good security teams thank the ones who speak up. For a round where nothing is at stake, Real or fake job titles asks the same kind of question about job titles.

Questions about phishing emails

Is there a free phishing email simulator?

Phish or IT is free and needs no sign-up, and it simulates the inbox only. It never sends an email or tracks who clicks. It shows five made-up emails a day and marks the red flags in each one after your call.

What are the red flags of a phishing email?

Urgency, threats, and any ask for your password, a login code or payment details. Check the sender and every link for a near miss of the real domain, and distrust short links, QR codes and surprise attachments. Bad spelling counts for less now that scammers write with AI.

What should I do if I clicked a phishing link at work?

Tell your IT team straight away, and change any password you typed on the page. The sooner IT hears, the sooner it can lock the account. A good security team thanks you, because people who fear blame report late or never.