Is this email real? It is the question every parent faces the moment a school message lands. The message is addressed to her son, and it looks right. School-blue banner, the district’s name spelled correctly, a subject line that says “Action required: student account verification.” Her son is standing next to her, backpack still on, asking if he should click the button — because it says he’ll lose access to his assignments if he doesn’t.
She reads it twice. Nothing about it screams fake. Nothing about it proves it’s real. And she realizes she’s doing the thing scammers count on: standing in the kitchen, five minutes before dinner, trying to out-think a professional forgery with a hungry twelve-year-old watching her hesitate.
That hesitation is the whole battlefield. So here’s the check she needed — the one you can run in about sixty seconds, and teach your kid to run too. And after the checklist, the honest part: why the checklist alone will never be enough, and what actually ends the guessing.
What is a phishing email, in one sentence
A phishing email is a message that impersonates someone your family trusts — a school, a store, a game, a bank — to trick the reader into clicking a link, opening an attachment, or handing over information. The forgery doesn’t need to fool an expert. It needs to fool one distracted person, once.
The 60-second check
Seconds 0–10: Look at the actual sender address, not the display name. The name says “Lincoln Middle School.” Tap or hover on it. The address underneath is the tell: lincoln-middle-updates@secure-portal-notice.com is not your district’s domain. A real sender’s address ends in the domain you already know — @yourdistrict.org, @amazon.com — not a lookalike with extra words, dashes, or a strange ending.
Seconds 10–20: Check how it greets your child. “Dear Student” and “Dear Parent/Guardian” from an organization that certainly knows the name on the account is a flag. So — counterintuitively — is a message that knows too much: a first name plus a teacher’s name plus a class period can all come from leaked school and app data. A correct greeting proves nothing. A generic one still counts against the message.
Seconds 20–30: Find the pressure. Real organizations almost never make a child race a clock. “Verify within 24 hours.” “Your account will be suspended.” “You’ll lose your assignments.” Urgency is the mechanism of the scam — it exists to make the reader click before they think. If the message is pushing for speed, slow down on purpose.
Seconds 30–45: Inspect the link without clicking it. Press and hold on a phone, or hover on a computer, and read the destination. If the text says “district portal” but the link goes to an address you’ve never seen, you’re done — it’s fake. If you can’t preview the link confidently, treat it as unreadable and move to the last step.
Seconds 45–60: Verify out-of-band. This is the step that settles it every time. Don’t reply, don’t click — go around the email entirely. Type the school portal’s address yourself, open the official app, or call the front office. If the “account verification” is real, it will be waiting there. In our kitchen scene, this is the ending: the mom opens the district portal directly, sees no alert, and the button her son almost clicked goes in the trash.
That’s the whole check. Sender address, greeting, pressure, link, verify. Run it a few times together and it takes less than a minute.
The part the checklist can’t fix
Here’s what sat with that mom afterward, and it’s worth saying plainly: the checklist worked because she was standing there.
Kids mostly read email alone. And a checklist is a skill that has to fire correctly every single time, against opponents who write forgeries for a living and only need it to fail once. Your child can get it right nineteen times, and the twentieth message — the one that names their real teacher, arrives the week of real exams, and looks more legitimate than the school’s actual newsletter — is the one that matters. Asking a twelve-year-old to be the last line of defense isn’t a safety plan. It’s hope with homework attached.
Notice what every step of the check has in common: it happens after the message has already reached your child. The sender address, the fake urgency, the poisoned link — all of it is sitting in the inbox, one tap from a mistake, before anyone has evaluated anything. A spam filter doesn’t change that. Filters guess whether a message looks bad, and a clean, well-written “account verification” note usually looks fine.
Change the question from “is this real?” to “who’s allowed in?”
There’s a different way to run the kitchen scene: the stranger writes the same convincing message to your son’s address — and it never arrives. Not in a junk folder he might dig through. Simply never delivered, because the sender was never on the list of people allowed to reach him.
That’s a consent-based, opt-in inbox. It starts closed. You and your child approve the senders who belong — family, the real school, the coach, known friends — and everyone else stays outside by default. This is what OptMsg email does with patent-pending opt-in technology: instead of asking your kid to spot every fake after it lands, it stops unapproved senders from landing at all. The 60-second check becomes something you use for the adults’ inboxes and the rare edge case — not a reflex your child’s safety depends on.
Teach the checklist. It’s a genuinely useful life skill, and walking through one real example together is the best scam education a kid can get. But give the checklist a backstop that doesn’t require anyone to be perfect at dinnertime.
See how the opt-in inbox works — join the early-access list
FAQ
What is a phishing email example?
A common example: an email that appears to come from a school or retailer, uses an official-looking design, and warns that an account will be suspended unless the reader clicks a link to “verify” details. The sender’s real address doesn’t match the organization’s domain, and the link leads to a lookalike site that captures whatever is typed. The message relies on urgency to beat scrutiny.
How can I tell if an email is real or fake in under a minute?
Check five things: the real sender address (not the display name), the greeting, artificial urgency, the link’s actual destination (hover or long-press — don’t click), and finally verify through the organization’s own site or app, typed directly. If a message fails any step, or you can’t verify it independently, treat it as fake.
How do I protect my child from phishing emails?
Teach the 60-second check using a real example, turn on two-factor authentication, and separate the address your child uses for apps and games from the one trusted people use. For structural protection, an opt-in inbox like OptMsg keeps the inbox closed by default — only senders a parent has approved can deliver, so a convincing fake from a stranger never reaches the child at all.