Privacy Tool · Attacker Mode

Phishing Bait Creator

The best way to spot a phishing email is to build one. Fill in the left panel, watch how the scam takes shape on the right, then hit "Launch Attack" to see every psychological trick you just used — dissected.

Build a fake scam email as the attacker — then see the exact psychological techniques you used, dissected

⚠️ This is a simulation for education only. No emails are sent. No data is collected or stored.

How to use this tool

  1. 1 Type "PayPal Support" as the sender name, then use a fake email like "[email protected]" — watch the red warning appear.
  2. 2 Add urgency words to the subject line: "URGENT: Your account has been suspended".
  3. 3 Paste a typosquatted URL: "http://paypa1-login.secure-verify.net/account".
  4. 4 Click "Launch Attack ▶" to see the exact psychological techniques you just deployed — and how to spot them.

🎣 Attacker Dashboard

You are the attacker. Fill in the fields.

📧 Victim's Inbox

Live preview
mail.example.com/inbox
P

Sender Name

12:34

(no subject)

(no subject)

P

Sender Name

12:34 PM

Dear Customer,

Your account requires attention. Please verify your information to continue.

Link destination:

http://example.com

Organization Inc · 1 Main Street

Unsubscribe · Privacy Policy

The three techniques in every phishing email

🎭 Identity Spoofing

Most Effective

Display name ≠ Email domain

Email clients display only the sender's chosen display name — not the actual address — in most views. Attackers set the display name to "PayPal Support" while sending from any domain they control.

💡 Always click the sender name to expand the full email address. If the domain doesn't match the brand, it's a fake.

⏰ False Urgency

Bypasses Reason

URGENT · ALERT · Suspended · Expires

Urgency activates the brain's threat-response system and suppresses the prefrontal cortex — the part responsible for critical thinking. Victims click before they think. Studies show urgency words increase click-through by up to 42%.

💡 Legitimate organisations do not demand immediate action via email. Close the email and log in directly to the website to check.

🔗 Typosquatting

Hard to Spot

paypa1.com · paypal.secure-login.net

Attackers register domains that look like trusted brands: substituting letters for numbers (o→0, l→1), adding hyphens, or using a real brand name as a subdomain of their own domain.

💡 In a URL, the real domain is always the segment immediately before the TLD (.com, .net). Everything before that is a subdomain the attacker controls.

Why do smart people fall for phishing?

Because phishing doesn't exploit stupidity — it exploits cognitive shortcuts that are useful in everyday life. The same heuristics that help you process information quickly make you vulnerable when an attacker controls the framing.

1

Trust by association: seeing a familiar logo or name triggers trust before the brain checks whether the source is authentic. This is called the 'authority heuristic' — we defer to perceived authority figures.

2

Urgency overrides deliberation: the amygdala (fight-or-flight) can override the prefrontal cortex (rational thought). Urgency triggers make people act on instinct, not analysis.

3

Effort asymmetry: checking the full sender address, hovering over the URL, and verifying through a second channel all require effort. Clicking the button requires none. Attackers exploit this cost difference.

4

Social proof: emails referencing your account, your recent activity, or your city feel personally relevant, which increases trust and reduces scepticism.

💡 Bottom line: The defence is not "be smarter" — it's building a habit: never click email links to enter credentials. Navigate directly to the website yourself. This one rule defeats every technique in this simulator.

Learn more about tracking and deception