Would your people spot a real scam? Now you can know.

Scam Check is a timed, branded scam-spotting test built from the techniques criminals actually used between 2024 and 2026 — lookalike domains, fake CAPTCHAs, payment redirects, deepfake calls — across email, text, phone, QR and six more channels. Every person gets their own link and their own questions. You get a score, not a guess.

Pay per campaign — no subscription Test your staff — or your customers Nothing for recipients to install

The usual security awareness campaign measures the wrong thing

Commonly-used phishing awareness email campaigns send your staff a fake phishing email and count who clicks. It sounds rigorous. Look closer at what the numbers actually mean.

The first flaw: silence counts as a win

Ignoring the email is a “pass”

Someone who never saw the simulation — buried inbox, out of office, filtered to junk — is scored as if they resisted it. Most of your “improvement” is people not opening an email. You learn nothing about the majority of your company.

The second flaw: opens prove nothing

An open is not a decision

Preview panes, phones and security scanners register “opens” on their own. And a human opening an email hasn’t fallen for anything — reading is what you want people to do before they judge. Yet open-rates end up in the board report as risk.

The third flaw: nobody meets a real scam

Sanitised templates, one channel

Simulations are email templates from a library — no rn↔m lookalike domains, no fake CAPTCHA that hijacks your clipboard, no payment-redirect cons, no deepfake voice calls. Scams arrive by text, phone, QR and chat; a simulation only ever knocks on the inbox.

The fourth flaw: trapping people costs trust

Your staff learn to distrust you

Deceptive tests have triggered union grievances and HR escalations, and research finds they erode trust in leadership — people stop reporting real threats because reporting got a colleague shamed. Security that your people resent is security that fails quietly.

We test judgment, openly

No traps, no fake emails from “HR”. People know they’re being tested — then they meet the real techniques, under time pressure, and every answer is scored. Try one:

Which of these is the genuine MailNest sign-in page?

https://login.rnailnest.com https://login.mailnest.com https://login.mai1nest.com

The tell: the first swaps the m for an r and an n pushed together — nearly identical in an address-bar font. The third uses the digit 1 for the letter l. Most people miss at least one at reading speed. That miss, in your results, is a gap you can close — before a criminal finds it first.

How a campaign runs

From first click to results, without touching your mail servers or installing anything.

Step one, build it

Pick questions, brand it yours

Choose from 243 questions built on real scam techniques seen between 2024 and 2026 — including packs for NZ, Australia, the UK, US and Canada — or add your own. Your name, your logo, your colours. Recipients never see ours.

Step two, send it

One personal link per person

Pay once for the number of people you’re testing and get a unique link for each. You send them from your own address, so the invitation carries your name and your trust — not a stranger’s domain. Each person gets a different subset of questions, so shared answers are worthless.

Step three, read the results

See exactly where the gaps are

Score distributions, the hardest questions, which channels catch your people out, who’s over the time budget — and an export your auditor or insurer will accept as training evidence. Run it anonymously and you get the numbers with no names stored at all.

243 questions, across every way a scam actually arrives

All of it written from real scam techniques seen between 2024 and 2026 — not a template library that has been sitting still since someone wrote it. Pick a whole category, filter to the channels your people actually use, or let the builder spread a campaign across all of them.

Lookalike domains12Delivery & parcel18Invoice & payment14Fake sign-in pages24OTP & MFA handover11Executive impersonation9QR codes7Voice & SMS41Investment & crypto11Romance & long con5Tech support11AI & deepfakes7Attachments6Shared-file lures8Job & recruitment9Charity & disaster6Marketplace & selling15Account takeover & recovery11Fake CAPTCHA & human checks8Blackmail & extortion3In person & in public4Prizes, lotteries & inheritance3

The bank is refreshed monthly from what our scanner sees in the wild, so a question tagged seen this month is a lure that was live against real people weeks ago. That is the part a static training library cannot copy.

Side by side

What a fake-phishing-email campaign tells you, against what a Scam Check tells you.

A commonly-used phishing email campaignSafeToOpen Scam Check
What’s measuredWho clicked one template emailScored judgment across real scam techniques
Non-participationCounted as a pass — silence looks like skillVisible as “not started” — you know who you know nothing about
Channels testedEmail onlyEmail, SMS, voice, QR, web, chat, social, app, marketplace, post
RealismTemplate libraryLookalike domains, fake CAPTCHAs, payment redirects, deepfakes, regional scams
Staff experienceDeception — documented trust and HR falloutAn open test people can even enjoy — feedback after every answer
Who you can testEmployees on your directoryStaff and customers — white-label, no directory needed
PrivacyPer-employee tracking, alwaysAnonymous mode: results without names ever stored
PricingPer-user annual subscriptionPay per campaign. Run one, or four a year — your call

Run the first one free. Then pay once per campaign.

Try it on a department before you spend anything. After that you pay once, for the number of people you are testing — not per seat, not per year, and not again next month. A 100-person company runs its annual scam check for US$200.

Your first campaign is free 10 questions, up to 25 people. A real results dashboard at the end of it — the score distribution, the weakest areas, who ran out of time. Not a demo with invented numbers. One per organisation — we ask for a card to keep it that way, and nothing is charged to it.
Start free

Then, for the whole organisation:

US$2.00
per person tested
US$1.50
per person, from 400 people
US$1.20
per person, from 1,000 people

What one campaign includes

Up to 20 questions in the pool

Pick up to twenty, from any of the 22 categories, plus any you write yourself. There is no per-question charge.

You choose how many each person answers

Serve the whole pool to everybody, or have the builder deal each person a different subset — eight of your twenty, say. Colleagues then get different questions, so comparing answers across the desk is worth nothing. Around ten questions takes most people four to five minutes.

Every option, on every campaign

Your branding, the timer, anonymous mode, the regional packs, the results dashboard and the score export. Nothing is held back for a higher tier — the only thing that changes with volume is the price per person.

The free run is the same product

Nothing is watered down for it — same questions, same branding, same anonymous mode, same dashboard. It is smaller, not lesser. What it will not do is cover everybody, which is rather the point.

Links that last as long as you need

Set how long they stay open, up to 120 days. Reminders to the people who have not finished cost nothing extra.

Part of Business Plus. Testing a customer base of 10,000 or more? Talk to us about population pricing.

Questions we get

No — deliberately. Nobody is tricked and nothing is disguised. People take an open, timed test against real scam techniques, get feedback after every answer, and are scored on judgment. You get better data, and your staff don’t learn to resent security.

Never. You get one personal link per person and send them yourself, from your own address — so the invitation arrives with your name on it, and your sending reputation stays yours. An unexpected email from an unknown security vendor asking people to click a link would be exactly the thing we’re testing for.

Yes. In anonymous mode no address is ever written to our database — not hidden, not hashed, never stored. You see the scores and the gaps; nobody sees names. It’s the mode works councils and privacy teams approve.

Yes — it’s built for it. The test is fully white-label, needs no directory or login, and includes country-specific scam content. If your organisation carries the cost when customers are scammed, measuring their scam literacy is the first step to reducing it.

Completion and score records export per campaign, which is the evidence ISO 27001, SOC 2 and PCI DSS awareness controls — and cyber-insurance questionnaires — ask for. A scored assessment is stronger evidence than a completion certificate, because it shows what people can actually do.

Run your first campaign this week

Build it in an afternoon, send it from your own address, and know by Friday where the gaps are.