Recognising phishing in 30 seconds
What you'll learn
Slow down. Domain, link target, urgency, ask — check all four.
- Four checks: sender domain · urgency · link target · credential ask.
- Hover before you click; type domains by hand if uncertain.
- Wire-transfer / gift-card / MFA-code asks → call the person on a known number.
Most phishing fails one of four checks: the sender domain doesn't match the brand (e.g. it claims to be from your bank but the domain is bank-secure-portal.com); the urgency is artificial ("act in the next 4 hours"); the link target on hover doesn't match the visible text; or the request asks for credentials, payment details, or to forward an MFA code.
Run the 30-second triage: (1) check the sender domain character-by-character; (2) hover the link and read the actual target; (3) ask yourself whether the email pressures you to skip verification. If any of the three fails, do not click and do not reply.
Spear-phishing — the targeted variant — gets the sender domain right by spoofing or compromising a real account. The remaining tells are: unexpected channel for the topic (CFO asking for gift cards via email is the canonical example), and any "please don't loop in finance/legal" preamble.
Key points
- Four checks: sender domain · urgency · link target · credential ask.
- Hover before you click; type domains by hand if uncertain.
- Wire-transfer / gift-card / MFA-code asks → call the person on a known number.
Pitfalls
- Clicking 'unsubscribe' on a phishing email — it confirms your address is live.
- Replying with 'Is this legit?' — same problem.
Ask your security team
In a real Adept rollout this routes to your company's security Claude project; in the demo it opens a fresh Claude chat.