Scam Check is a timed, branded scam-spotting test built from the techniques criminals actually used between 2024 and 2026 — lookalike domains, fake CAPTCHAs, payment redirects, deepfake calls — across email, text, phone, QR and six more channels. Every person gets their own link and their own questions. You get a score, not a guess.
That is not a failing — it is how good the scams have got. Anyone can take our free public quiz, twelve questions built from the same material Scam Check uses, and here is how everyone has done so far. It updates as new results come in.
Commonly-used phishing awareness email campaigns send your staff a fake phishing email and count who clicks. It sounds rigorous. Look closer at what the numbers actually mean.
Someone who never saw the simulation — buried inbox, out of office, filtered to junk — is scored as if they resisted it. Most of your “improvement” is people not opening an email. You learn nothing about the majority of your company.
Preview panes, phones and security scanners register “opens” on their own. And a human opening an email hasn’t fallen for anything — reading is what you want people to do before they judge. Yet open-rates end up in the board report as risk.
Simulations are email templates from a library — no rn↔m lookalike domains, no fake CAPTCHA that hijacks your clipboard, no payment-redirect cons, no deepfake voice calls. Scams arrive by text, phone, QR and chat; a simulation only ever knocks on the inbox.
Deceptive tests have triggered union grievances and HR escalations, and research finds they erode trust in leadership — people stop reporting real threats because reporting got a colleague shamed. Security that your people resent is security that fails quietly.
No traps, no fake emails from “HR”. People know they’re being tested — then they meet the real techniques, under time pressure, and every answer is scored. Try one:
Which of these is the genuine MailNest sign-in page?
https://login.rnailnest.com https://login.mailnest.com https://login.mai1nest.comThe tell: the first swaps the m for an r and an n pushed together — nearly identical in an address-bar font. The third uses the digit 1 for the letter l. Most people miss at least one at reading speed. That miss, in your results, is a gap you can close — before a criminal finds it first.
From first click to results, without touching your mail servers or installing anything.
Choose from 243 questions built on real scam techniques seen between 2024 and 2026 — including packs for NZ, Australia, the UK, US and Canada — or add your own. Your name, your logo, your colours. Recipients never see ours.
Pay once for the number of people you’re testing and get a unique link for each. You send them from your own address, so the invitation carries your name and your trust — not a stranger’s domain. Each person gets a different subset of questions, so shared answers are worthless.
Score distributions, the hardest questions, which channels catch your people out, who’s over the time budget — and an export your auditor or insurer will accept as training evidence. Run it anonymously and you get the numbers with no names stored at all.
All of it written from real scam techniques seen between 2024 and 2026 — not a template library that has been sitting still since someone wrote it. Pick a whole category, filter to the channels your people actually use, or let the builder spread a campaign across all of them.
The bank is refreshed monthly from what our scanner sees in the wild, so a question tagged seen this month is a lure that was live against real people weeks ago. That is the part a static training library cannot copy.
What a fake-phishing-email campaign tells you, against what a Scam Check tells you.
| A commonly-used phishing email campaign | SafeToOpen Scam Check | |
|---|---|---|
| What’s measured | ✗Who clicked one template email | ✓Scored judgment across real scam techniques |
| Non-participation | ✗Counted as a pass — silence looks like skill | ✓Visible as “not started” — you know who you know nothing about |
| Channels tested | ✗Email only | ✓Email, SMS, voice, QR, web, chat, social, app, marketplace, post |
| Realism | ✗Template library | ✓Lookalike domains, fake CAPTCHAs, payment redirects, deepfakes, regional scams |
| Staff experience | ✗Deception — documented trust and HR fallout | ✓An open test people can even enjoy — feedback after every answer |
| Who you can test | ✗Employees on your directory | ✓Staff and customers — white-label, no directory needed |
| Privacy | ✗Per-employee tracking, always | ✓Anonymous mode: results without names ever stored |
| Pricing | ✗Per-user annual subscription | ✓Pay per campaign. Run one, or four a year — your call |
Try it on a department before you spend anything. After that you pay once, for the number of people you are testing — not per seat, not per year, and not again next month. A 100-person company runs its annual scam check for US$200.
Then, for the whole organisation:
Pick up to twenty, from any of the 22 categories, plus any you write yourself. There is no per-question charge.
Serve the whole pool to everybody, or have the builder deal each person a different subset — eight of your twenty, say. Colleagues then get different questions, so comparing answers across the desk is worth nothing. Around ten questions takes most people four to five minutes.
Your branding, the timer, anonymous mode, the regional packs, the results dashboard and the score export. Nothing is held back for a higher tier — the only thing that changes with volume is the price per person.
Nothing is watered down for it — same questions, same branding, same anonymous mode, same dashboard. It is smaller, not lesser. What it will not do is cover everybody, which is rather the point.
Set how long they stay open, up to 120 days. Reminders to the people who have not finished cost nothing extra.
Part of Business Plus. Testing a customer base of 10,000 or more? Talk to us about population pricing.
No — deliberately. Nobody is tricked and nothing is disguised. People take an open, timed test against real scam techniques, get feedback after every answer, and are scored on judgment. You get better data, and your staff don’t learn to resent security.
Never. You get one personal link per person and send them yourself, from your own address — so the invitation arrives with your name on it, and your sending reputation stays yours. An unexpected email from an unknown security vendor asking people to click a link would be exactly the thing we’re testing for.
Yes. In anonymous mode no address is ever written to our database — not hidden, not hashed, never stored. You see the scores and the gaps; nobody sees names. It’s the mode works councils and privacy teams approve.
Yes — it’s built for it. The test is fully white-label, needs no directory or login, and includes country-specific scam content. If your organisation carries the cost when customers are scammed, measuring their scam literacy is the first step to reducing it.
Completion and score records export per campaign, which is the evidence ISO 27001, SOC 2 and PCI DSS awareness controls — and cyber-insurance questionnaires — ask for. A scored assessment is stronger evidence than a completion certificate, because it shows what people can actually do.
Build it in an afternoon, send it from your own address, and know by Friday where the gaps are.