Spot phishing and social engineering
Recognize the tricks that target people instead of computers, and check where links really go.
- Recognize urgency, authority and secrecy pressure tactics
- Check a link’s real destination and spot lookalike domains
- Know why phishing-resistant sign-in and reporting matter
Many breaches start not with clever code but with a convincing message. Social engineering manipulates people into giving away access, money or information. Common forms:
- Phishing - email that imitates a trusted sender (spear phishing targets one person using researched details).
- Smishing / vishing - the same by text message or phone call.
- Business email compromise - posing as an executive or supplier to redirect payments.
- MFA fatigue - spamming sign-in approval prompts until someone taps “Approve”.
They work by triggering emotions that short-circuit careful thinking: urgency (“within 24 hours”), authority (“the CEO needs this”), fear (“your account is suspended”), curiosity or greed, and secrecy (“keep this between us”).
Try it
Red-flag hunt
Read each message like a suspicious security analyst. Click every part that’s a warning sign, then check what you found.
Click every part that looks suspicious. There are 6.
Where does that link really go?
The text of a link can say anything; what matters is the href - hover (or long-press) to see it. Then read the hostname from the right: in login.example-bank.com, the registrable domain is example-bank.com; in example-bank.com.secure-login.net, it is secure-login.net. Attackers also register lookalike domains: examp1e-bank.com, example-bank.co, or letters from other alphabets that look identical.
1from urllib.parse import urlparse
2for url in ["https://login.example-bank.com/", "https://example-bank.com.secure-login.net/"]:
3 host = urlparse(url).hostname
4 print(host, "->", ".".join(host.split(".")[-2:]))login.example-bank.com -> example-bank.com example-bank.com.secure-login.net -> secure-login.net
Key takeaways
Social engineering exploits urgency, authority, fear and secrecy.
Check a link’s real destination and read its domain from the right.
Phishing-resistant MFA, out-of-band verification and easy reporting beat “just be careful”.
Lesson quiz
6 questions · pass with 5 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Practice: write Python
Write Python in the editor and run it against sample inputs. Python runs locally in your browser using a WebAssembly runtime.
Does the link go where it says?
Each line is display text|href. If the display text looks like a URL (starts with http or www.), compare its hostname with the href’s hostname: print ok: HOST if they match, otherwise MISMATCH: shows A, goes to B.
If the display text isn’t a URL, print check: text link goes to HOST.
- Four links
Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.
Catch lookalike domains
The first line lists your trusted domains, comma-separated. Each following line is a hostname. Treat the last two labels as the registrable domain.
- If the registrable domain is trusted, print
trusted HOST. - Otherwise, if its first label - after mapping
0→o,1→l,3→e,5→sand removing hyphens - equals a trusted domain’s first label (also without hyphens), or any label of the host equals a trusted domain’s first label, printlookalike HOST (imitates TRUSTED). - Otherwise print
unknown HOST.
- Mixed hosts
Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…