How to Teach Kids to Recognize Phishing Emails and Fake Sites
Table of Contents

How to Teach Kids to Recognize Phishing Emails and Fake Sites

Phishing is the most common cyber attack kids face. This guide teaches parents how to explain phishing to children of every age and build lasting recognition skills.

Your 11-year-old receives an email that looks exactly like it came from Roblox: the logo, the color scheme, even the sender name. It says their account is being deleted unless they log in through the provided link within 48 hours. The email even includes their username. They click the link and see what looks like Roblox’s login page. They type their credentials. The next day, their account is gone. The Anti-Phishing Working Group (APWG) recorded over 5 million phishing attacks in 2023—a record high—and children are disproportionately targeted because they lack the experience to recognize subtle signs of deception. The good news: phishing has tells, and they’re teachable.

Key Takeaways

  • Phishing works by creating a convincing imitation of a trusted source—the tell is almost always in the URL, the sender address, or the urgency framing
  • Children ages 9–12 are the highest-risk group for gaming-related phishing; teens face more email and SMS phishing targeting financial accounts
  • The single most effective skill to teach is “check before you click”—specifically, how to read a URL and verify a sender address
  • Real companies never ask for passwords, payment information, or login credentials via email or chat
  • A “phishing test” exercise at home (using real spam emails together) is more effective than any rule-based explanation

What Phishing Is and How It Works

Phishing is an attempt to steal credentials, financial information, or personal data by impersonating a trusted source. The word is a play on “fishing”—the attacker casts out bait and waits for someone to bite. The bait is usually an email, text message, or direct message that appears to come from a legitimate organization: a bank, a gaming platform, a streaming service, a school, or even a friend.

The mechanics are straightforward: the message creates urgency or fear (“your account will be deleted”), directs the victim to a fake website that looks like the real one, and captures whatever the victim types—typically a username and password. In more sophisticated attacks, the fake site may also ask for payment information, home address, or answers to security questions.

Phishing attacks have evolved significantly. Modern phishing emails often include:

  • The recipient’s actual username or name (gathered from previous breaches or social media)
  • Accurate logos and brand formatting copied from real communications
  • Sender addresses that look legitimate at a glance (support@roblox-security.com rather than support@roblox.com)
  • SSL certificates (the green padlock) on the fake website, which children and many adults incorrectly interpret as a safety indicator

The Four Signs of a Phishing Attempt

Teach your child these four checks as a sequence—not a list of rules, but a procedure to run through before clicking anything unexpected.

Sign 1: Check the Sender Address (Not Just the Name)

Email clients show a display name (which can be anything: “Roblox Support,” “PayPal,” “Your Bank”) and the actual email address (which reveals the truth). Show your child how to click on the sender name to reveal the full address. Legitimate Roblox emails come from @roblox.com. Anything else—@roblox-security.com, @roblox.net, @notifications-roblox.com—is fake.

Exercise: Find 3 emails in your spam folder together. Click on each sender name and examine the actual email address. Discuss what makes each one suspicious or legitimate.

Sign 2: Check the URL Before Clicking

The most important skill: before clicking any link, verify where it goes. On desktop, hovering over a link shows the destination URL in the browser’s status bar. On mobile, long-pressing a link shows a preview of the destination.

Teach the anatomy of a URL:

  • The domain is the last two parts before the first single slash: roblox.com/security is legitimate; roblox-security.com/roblox is not
  • Legitimate websites end in the expected domain (.com, .org, .gov for official US sites, .edu for schools)
  • Misspellings like “paypa1.com” or “rblox.com” are phishing indicators
  • A suspicious-looking string before the legitimate domain (roblox.com.hack-site.net) means the actual domain is hack-site.net, not roblox.com

Exercise: Visit a gaming website your child uses. Look at the URL together and identify the actual domain. Then look at a made-up suspicious URL you write on paper and have them identify what’s wrong with it.

Sign 3: Recognize the Urgency and Fear Pattern

Legitimate organizations do not threaten you with account deletion in 48 hours via email. Legitimate organizations do not send emails saying you must act NOW or face irreversible consequences. When any communication—email, text, in-game message—creates extreme urgency or fear, that urgency itself is the warning sign.

Teach the “pause rule”: any time a digital message makes you feel you must act immediately to avoid a bad outcome, you pause. You don’t click anything. You go directly to the official website (by typing it yourself) or ask a parent.

The clearest rule: never enter a username or password on any page you reached by clicking a link in an email, text message, or chat message. Always navigate to the site yourself by typing the URL. This eliminates phishing landing pages entirely, because the attacker can only steal credentials you type on their fake page—if you navigate to the real site yourself, you’re safe.

Age-Appropriate Teaching Approaches

Ages 6–8: The “Trick Email” Concept

At this age, children can understand that some messages are “trick messages” that try to steal information. Frame it concretely: “Some bad people send fake emails that look real to try to steal your game password. They’re like someone wearing a costume to pretend they’re from Roblox.” The takeaway for this age is simple: “Never click links in emails without asking me first.”

Ages 9–11: The URL Check

Children at this age can learn to read URLs and check sender addresses. Make it a game: “Let’s look at this email and figure out if it’s real or fake.” Practice with spam emails in your own inbox. This age group encounters gaming phishing most frequently, so ground examples in gaming contexts.

Ages 12–15: Full Phishing Literacy

Teenagers can understand the full mechanism. Walk through a real (or realistic) phishing email together and identify every element of the deception: the cloned logo, the manipulated sender address, the fake URL, the urgency framing, and what would have happened if they’d clicked and entered credentials. Resources like Google’s Phishing Quiz (phishingquiz.withgoogle.com) allow teens to test their phishing identification skills interactively.

Common Phishing Scenarios Targeting Kids

PlatformCommon BaitRed Flags
Roblox”Your account violated terms,” “Verify to claim free Robux”Sender not @roblox.com, links to roblox-related domains
Fortnite/Epic”Your account is banned,” “Claim your V-Bucks”Links to non-epicgames.com domains
Minecraft”Account migration required,” “Your Java license expired”Links not to microsoft.com or minecraft.net
YouTube”Your channel is being removed,” “Claim your Creator reward”Sender not @youtube.com, non-google.com links
Gaming general”You won a tournament,” “Free gift card”No prior entry, vague “tournament” reference
School”Important: your account password must be changed”Non-school domain, requests password via email

What to Do When Your Child Encounters a Phishing Attempt

  1. Don’t click anything. Close the email/message without clicking.
  2. Screenshot and show a parent. This isn’t about getting in trouble—it’s about learning to identify these together.
  3. Report the phishing attempt. Forward suspicious emails to reportphishing@apwg.org. For platform-specific phishing (fake Roblox emails), forward to phishing@roblox.com. Google at phishing-report@google.com. This helps platforms protect other children.
  4. If credentials were already entered: Change the password immediately on the real platform. Enable or verify 2FA is active.

What to Watch For Over 3 Months

  • Month 1: Have one “phishing training session” using your spam folder. Pick three emails together and evaluate each one. Explain the sender address check and the URL hover check. Make it interactive, not a lecture.
  • Month 2: Set up phishing filters if you haven’t already. Gmail, Outlook, and most email services have built-in phishing detection, but it’s not perfect. Ensure your child’s email account has these filters active.
  • Month 3: Check whether your child’s email address appears in any data breaches (use haveibeenpwned.com). If it does, they’re likely on phishing lists and may receive more targeted attempts. Increase the frequency of conversations accordingly.

Also watch for: your child mentioning “strange emails” from their favorite platforms, accounts with unexpected password reset messages, or your child seeming anxious about an account being deleted.

Frequently Asked Questions

What’s the difference between phishing, smishing, and vishing?

Phishing uses email. Smishing uses SMS text messages (“Your package is delayed—click here to reschedule”). Vishing uses phone calls (“This is Microsoft Support—your computer has a virus”). All three use social engineering tactics to steal information. The recognition principles are the same: verify the source independently, never provide credentials when contacted rather than contacting first.

Possibly. Clicking a phishing link can expose your device to drive-by malware downloads (where malicious code is installed just from visiting the page) and can confirm to the phisher that the email address is active. Run a malware scan on the device. Change passwords for any accounts they’ve recently logged into on that device as a precaution.

How can I tell if an email is really from the school?

Check the sender’s domain. Your school’s emails should come from @[schoolname].edu or @[schooldistrict].org, not from generic Gmail or Yahoo addresses. Schools don’t ask for passwords by email. If you receive an urgent email from “school” to an unfamiliar address, call the school directly before responding.

Are there tools that help protect children from phishing automatically?

Yes. DNS-level content filters like OpenDNS FamilyShield or CleanBrowsing block known phishing domains before they load. These are free, require only a router configuration change, and apply to all devices on your home network. They’re a useful technical layer, but they don’t eliminate all phishing and are not a substitute for teaching recognition skills.


About the author

Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.


Sources

  1. Anti-Phishing Working Group (APWG). Phishing Activity Trends Report Q4 2023. apwg.org. https://docs.apwg.org/reports/apwg_trends_report_q4_2023.pdf
  2. Federal Bureau of Investigation (FBI). Phishing. fbi.gov. https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-scams-and-crimes/phishing
  3. Cybersecurity and Infrastructure Security Agency (CISA). Phishing Guidance. cisa.gov. https://www.cisa.gov/topics/cyber-threats-and-advisories/malware-phishing
  4. Federal Trade Commission. How to Recognize and Report Spam Text Messages. consumer.ftc.gov. https://consumer.ftc.gov/articles/how-recognize-and-report-spam-text-messages
  5. Google. Phishing Quiz. phishingquiz.withgoogle.com. https://phishingquiz.withgoogle.com
  6. National Institute of Standards and Technology (NIST). Phishing Resistance. nist.gov. https://pages.nist.gov/800-63-3/sp800-63b.html
  7. Proofpoint. 2024 State of the Phish Report. proofpoint.com. https://www.proofpoint.com/us/resources/threat-reports/state-of-phish
Ricky Flores
Written by Ricky Flores

Founder of HiWave Makers and electrical engineer with 15+ years working on projects with Apple, Samsung, Texas Instruments, and other Fortune 500 companies. He writes about how kids learn to build, think, and create in a tech-driven world.