Worked example · PSE / Well-being · Year 8
DCF: Citizenship → Online behaviour and online bullying
A secure Year 8 response, annotated, covering every warning sign in all four emails. Emails 1, 2 and 3 are fake. Email 4 is genuine. Work Email 1 through on the board using the annotations below, then let pairs do 2, 3 and 4 themselves.
| Name / address mismatch | Rushed you | Generic greeting | Link goes elsewhere | Attachment or password | Best piece of evidence | |
|---|---|---|---|---|---|---|
| 1 | Yes | Yes | Yes | Yes | Yes | It asks for “card number and PIN”. No bank has ever asked for a PIN by email. Everything else is decoration next to that. |
| 2 | Yes | Yes | Yes | No link | Yes | “Open the attached form and enter your school username and password”. The IT team already has my account — they never need my password. |
| 3 | Yes | Yes | Yes | Yes | Payment, not an attachment | “No tracking number is available for this item.” A real delivery company always has a tracking number, because that is how deliveries work. |
| 4 | No | No | No | No link at all | No | It asks for nothing and offers a face-to-face route instead: “come and find me in room B14 at break”. |
Each row picks the single strongest piece of evidence rather than listing everything, and quotes the words. That is the second criterion.
Email 1 — Setup-Bank.
Mismatch: the display name says “Setup-Bank Security Team” but the address ends login-check.net. Worse, the Reply-To is a completely different domain, mailhost-8842.info, and it is labelled “winnings.dept” — nothing to do with a security alert.
Urgency: “will be CLOSED in 24 hours”, “closed permanent and your funds transfer to holding”, and it was sent at 03:41 on a Sunday.
Greeting: “Dear Valued Customer” — and the To line says “undisclosed-recipients”, so it went to thousands of people at once.
Link: the text reads setup-bank.co.uk/secure but the status bar shows setup-bank.secure-login-check.net. The real owner is whoever owns secure-login-check.net.
Asks for a secret: full name, date of birth, card number and PIN.
Extra: “We have detect unusual activity on you account” — two grammar errors in nine words.
All five signs found and quoted, including the Reply-To line that most pupils skip. The grammar point is listed last because it is the weakest tell — a careful criminal writes properly.
Email 2 — Scoolmail.
Mismatch: it was sent to year8@ysgolnantgwyn.cymru but comes from scoolmail-support.com. Our school’s own email ends ysgolnantgwyn.cymru, so the school’s IT team would be writing from inside that domain, not from a different company.
Urgency: “unless you act today”, and the threat is aimed at a pupil specifically — “you will stop receiving email, including homework”.
Greeting: “Hello user”. The school knows my name; it is in their system.
Attachment: Mailbox_Quota_Form.html. An HTML attachment is a web page hidden in an email, and this one exists only to collect a password.
The giveaway: “enter your school username and password”. Nobody in school ever needs my password.
Extra: “99.8%” is a suspiciously precise number designed to look automatic, and it arrived at 22:17, when no helpdesk is working.
Compares the sender’s domain with the school’s own domain rather than judging the tone, which is the first criterion. Explains what an HTML attachment actually is.
Email 3 — Parcel Post Cymru.
Mismatch: the domain is delivery-fee.info, with “parcel-post-cymru” stuck on the front as a subdomain. Read from the right: the owner is whoever owns delivery-fee.info.
Urgency: “returned to sender after 48 hours”, sent at 05:02.
Greeting: “Dear customer”, and the To line is blank.
Link: pay-release.info, which is not the sender’s domain either.
The giveaway: no tracking number, and I have not ordered anything. The £1.87 is not the point — the card details are.
Identifies that the tiny amount is bait for card details rather than the theft itself. That is the insight the extension question is aiming at.
| Address or link, as printed | The real domain | Whose is it, really? |
|---|---|---|
| secure.alerts@setup-bank-verify.login-check.net | login-check.net | Whoever registered login-check.net. “setup-bank-verify” is just a label they typed in front of it — anyone can put any word there. |
| it-helpdesk@scoolmail-support.com | scoolmail-support.com | Not the school. The school is ysgolnantgwyn.cymru, and “Scoolmail” is a misspelling designed to be read quickly. |
| no-reply@parcel-post-cymru.delivery-fee.info | delivery-fee.info | Whoever registered delivery-fee.info. The Welsh-sounding part is bait. |
| headofyear8@ysgolnantgwyn.cymru | ysgolnantgwyn.cymru | The school itself. This is the only one of the four where the domain is the organisation that claims to be writing. |
Reads every domain from the right and states who owns it. This is the skill that transfers to real scams, where the wording will be different but the trick is identical.
I am reporting the email that arrived on Tuesday at 22:17 with the subject “Mailbox full — action required”. It claims to be from the Scoolmail Helpdesk. Three things are wrong with it. First, it comes from scoolmail-support.com, which is not our school’s domain — ours is ysgolnantgwyn.cymru. Second, it asks me to type my username and password into an attachment called Mailbox_Quota_Form.html, and I know the school never needs my password. Third, it tries to make me hurry by saying I will stop receiving homework today. I did not open the attachment, I did not reply and I did not click anything. I have left it in my inbox so you can see the headers, and I am telling my form tutor as well. This one worried me most because it was aimed at pupils specifically, using homework as the threat.
Names the email, gives three pieces of evidence with the exact domains, and states clearly what was not done. Keeping the email rather than deleting it, so the headers survive, is the detail that shows real understanding.