Phishing Resilience Test: Practice Real-or-Phish Decisions Safely
Why useful phishing practice measures decisions and confidence instead of testing security vocabulary or blaming the user.
Phishing practice should test decisions
Phishing often succeeds in a short moment of uncertainty. The message may look routine, arrive during a busy day, resemble an expected workflow, or ask for an action that feels normal. Memorizing a list of warning words does not fully prepare someone for that decision.
The Phishing Resilience Test uses safe fictional situations to practice classifying a message as legitimate, suspicious, or not enough information. The focus is not on knowing technical vocabulary. It is on interpreting identity, context, pressure, requested actions, domains, and uncertainty.
Quick Challenge or Full Assessment
The Quick Challenge contains six scenarios and is designed for a short practice session. The Full Assessment contains all 18 scenarios and covers a broader mix of email, SMS, workplace, account, payment, support, and customer-service situations.
Every destination in the scenarios uses reserved fictional examples. The exercise does not require a user to visit a suspicious website, enter an email address, or share a real message.
Why legitimate and uncertain scenarios matter
A quiz made entirely of obvious scams teaches people to treat every message as dangerous. That can create fatigue and false positives without improving judgment.
The CheckLink assessment includes legitimate, suspicious, and genuinely uncertain cases. Legitimate messages may use expected domains and direct users to an existing bookmark. Suspicious messages may combine an identity conflict with a high-impact action. Uncertain messages may simply lack enough evidence for a confident label.
Learning to say not enough information is an important security skill. It creates space for verification instead of forcing confidence where the evidence is incomplete.
Immediate feedback after every answer
After each classification, the tool explains the useful evidence, a signal that may have been missed, a safe verification action, and a short learning point. Feedback appears immediately so the connection between the decision and the evidence remains clear.
The scenarios do not claim that one urgent phrase, one familiar name, or one authentication signal proves an answer. They emphasize combinations and the quality of the verification route.
Confidence is separate from accuracy
Users rate confidence from one to five for each scenario. This makes it possible to distinguish a wrong low-confidence answer from a wrong high-confidence answer.
The final result reports accuracy, false negatives, false positives, and confidence calibration separately. Missing a suspicious message can expose an account or payment. Treating every legitimate message as phishing can interrupt work and teach people to ignore security tools. Both deserve attention, but they are not the same mistake.
What the score does not mean
The result is educational and private. It is not a scientifically validated measure of intelligence, character, trustworthiness, technical expertise, or future behavior. It should not be used to rank employees or make employment decisions.
Age, gender, nationality, education, profession, and other demographic attributes are not requested or used. Optional habit questions may tailor learning suggestions, but they do not change the core answer score.
Turn feedback into verification habits
- Open known services from a bookmark or independently typed address.
- Use a trusted directory instead of a phone number in the message.
- Treat payment, credential, MFA, and bank-change requests as high impact.
- Ask what evidence is missing before choosing a confident label.
- Look for identity and destination evidence before relying on tone.
- Require a second channel for unusual workplace or supplier requests.
Privacy by default
Answers, confidence ratings, progress, and results remain in the browser tab. They are deleted when the user resets or leaves the page. No account is required, and scenario answers are not sent to analytics.
This matters because learning tools should not create a hidden profile of mistakes, confidence, or personal characteristics.
What to do after the assessment
Use the recommendations to choose one or two habits to practice rather than trying to remember every signal. If a real suspicious message is waiting, open the Phishing Message Analyzer. If raw headers are available, use the Email Identity Checker. If an interaction already occurred, use Phishing First Aid immediately.
For the complete relationship between the tools, read the CheckLink Human Risk Intelligence guide.
Continue with the right checker
CheckLink browser extension
Open the current page, inspect links from the browser menu, and jump into CheckLink faster without an account.
Works with Chrome and compatible Chromium-based desktop browsers. Firefox and Safari versions are not currently available.

The extension sends a URL only when you choose a scan action. It does not store scan history.