Inbox Defense is Blue Lantern Security's free phishing assessment. You handle 10 realistic emails for a fictional company and decide whether each one is Safe or Phishing. After every decision you see the detail that gave the message away, and at the end you get a score, accuracy by category, and every message with its tells highlighted. It takes about five minutes and runs in your browser with no account.
Access: free for anyone to play, including the full assessment, the debrief, and the arcade. Recording results for each employee requires a Seat License at $15 per monitored user per month. See current pricing.
How does the assessment work?
- Start a run. You run Harborline Logistics. Every email you handle correctly earns the company money; every mistake costs it.
- Read each message as it would appear in a mail client. Sender name and address, subject, body, links, and attachments. Hover a link, or long-press it on a phone, to see where it really goes. Nothing is live: links never open and attachments never download.
- Decide Safe or Phishing. Use the buttons or the S and P keys. A "Known senders" panel lists the legitimate companies in the game world, so you can compare a sender against the real domain.
- Read the feedback. After each decision you see whether you were right, what it cost or earned, and the one detail that mattered, such as a capital I standing in for an l in the sender's domain.
- Review the debrief. Your score (80% passes), accuracy by category, and each message expandable with every tell highlighted in place.
Each run draws 10 messages from a larger pool: 4 routine, 4 tricky, and 2 advanced, with the advanced ones in the second half. Six or seven are phishing and the rest are legitimate, so a retake brings different messages and guessing "phishing" every time doesn't pay.
What does it cover?
| Category | What it teaches |
|---|---|
| Lookalike domains | Spotting swapped characters and real brands used as a prefix on someone else's domain |
| Deceptive links | Checking a link's real destination instead of its display text |
| Urgent credential requests | Password resets, locked accounts, and full mailboxes that push you to sign in |
| Invoice fraud | Changed bank details and overdue invoices, verified by phone using a number you already have |
| Executive impersonation | Urgent payment or gift-card requests that skip normal approval |
| Shared document lures | File-share notifications that lead to a sign-in page |
| Malicious attachments | Double extensions and attachments that are not what they claim |
| QR code lures | Codes that hide the destination from link checks |
| MFA fatigue | Repeated sign-in prompts you did not trigger |
| Delivery and reward scams | Small redelivery fees and prizes that harvest card details and logins |
| Legitimate mail | Receipts, colleague requests, and real sign-in notices that look like the scams above |
The game uses fictional companies and parodies of real services, so the skill is reading the message rather than recognizing a logo.
How is it scored?
There are two numbers. The training score is the share of decisions you got right, and 80% is a pass. The company balance is the game score:
| Message tier | Correct | Missed phishing | Flagged legitimate mail |
|---|---|---|---|
| Routine | +$10 | $0 | $0 |
| Tricky | +$25 | $0 | -$5 |
| Advanced | +$60 | -$200 (breach) | -$15 |
Flagging legitimate mail costs money on purpose. In a real inbox, treating every message as a threat means missed customers, late payments, and a team that stops reading warnings.
What is the arcade?
Finish a run and the arcade opens. Mail arrives continuously, correct calls earn money, and mistakes cost it. You spend the money on tools modeled on real Blue Lantern Security checks: a sender domain check, a link inspector, a header reveal for SPF, DKIM, and DMARC, and an attachment scanner, each of which reveals findings on the message in front of you. You can hire analysts, but every hire brings in more mail. Deploying AI ends the game.
A typical game takes 9 to 12 minutes, and your best time is saved in your browser.
How do I record results for my team?
Recording turns the assessment into training evidence for insurers, customers, and auditors. It requires a Seat License on the account.
- Connect your directory. Members come from your Google Workspace or Microsoft 365 organization integration.
- Create personal links. In the Monitoring Hub's Training view, an admin creates a link for each active member, or for everyone at once with a CSV download. Links are shown once. Regenerating a link replaces the old one, and a link can be revoked at any time.
- Send the links. Whoever opens a link plays as that member, with no sign-in needed. Seated members can also sign in and play at the training page directly.
- Employees choose what to save. Each finished run offers "Record your results," and only runs the employee saves are recorded. Answers are graded on our servers, not in the browser.
- Review results. Admins see each member's latest result, completion date, number of attempts, and every answer with per-category results. Members who aren't admins see only their own runs.
Results also appear in the Security Attestation Report: how many active members passed in the last 12 months, how many attempted but scored below the pass mark, how many haven't started, and the date of the most recent pass.
Is this a phishing simulation?
No. Inbox Defense is an assessment in a simulated inbox. It does not send fake phishing emails to your employees' real mailboxes. People know they are being tested, which makes it a fair way to teach and measure the skill without tricking staff or flooding the help desk with reports of your own test emails.
If you want to catch real phishing as it arrives, email monitoring analyzes every new message in monitored Gmail and Microsoft 365 mailboxes within seconds.
What happens to my data?
Playing without an account sends nothing: no message content or decisions leave your browser. A recorded run stores the member's email, the messages they were shown, their answers, and the score, under the account that created the link or the member's own signed-in account. Only runs the member chooses to save are kept.
Frequently asked questions
Is it really free? Yes. The assessment, the debrief, and the arcade are free to play with no account. Only recording results per employee requires a Seat License.
How often should employees take it? When they join, then once a quarter. Each run draws new messages, so a retake measures skill rather than memory.
Does phishing training work? Annual compliance training barely changes behavior, according to a large 2025 study. Short, frequent practice with immediate feedback is a better bet, alongside MFA and email filtering. Our post on phishing training for small businesses covers the research and what to do instead.
What should an employee do after clicking a real phishing link? Tell whoever handles IT right away. Our guide on what to do if you clicked a phishing link walks through the steps.