IN DEVELOPMENT · BUILT WITH YOUR EXPERIENCES

A familiar name
isn’t proof.

The logo looks right. The message sounds urgent. But is the business behind it who they say they are?

We’re building PhishTrust to make business identity easier to question—before you trust a message. Real phishing stories will help us test better warnings.

Share your phishing story

About 3 minutes. No account. A near miss counts.

Northline Deliverydelivery@example.invalid
09:41
ILLUSTRATIVE MESSAGE

Your delivery needs
one small update.

Confirm your details to keep your parcel moving.

Update delivery details

LOOK BEYOND THE NAME

Business identity unverified

A familiar brand name alone doesn’t verify the sender or the link.

Concept illustration · not a live scan or product screenshot

Identity first.Clearer context.More informed decisions.

01 / THE IDEA

Check the identity.
Keep your judgement.

Phishing borrows trust. We’re exploring a clearer way to show when a claimed business identity holds up—and when it doesn’t.

The approach compares a message’s claimed business with its sender and clickable link domains. Four identity states explain what could be established.

An identity check isn’t a verdict on the message. Even a verified business can send unsafe or misleading content.

GREEN / VERIFIED

Business identity verified

Business identity verified. Message content not verified.

YELLOW / PERSONAL

Personal or unverified

No business identity is claimed. That alone doesn’t establish whether a message is safe.

ORANGE / UNKNOWN

Claim not verified

A business is claimed, but its domain hasn’t been verified against that identity.

RED / CONFLICT

Identity doesn’t match

An explicit mismatch between the claimed business and a checked domain needs attention.

02 / YOUR EXPERIENCE MATTERS

The moment you
almost believed it.

You don’t have to have lost money to have a story worth sharing.

Tell us what made a message convincing, what happened next, and what helped you notice something wasn’t right.

Tell us what happened
01

Your words, without private details

Describe the experience. Leave out passwords, account numbers, real links and identifying information.

02

Your choice about publication

Research consent and permission to publish are separate choices in the form.

03

Better questions for our testing

Stories help us understand the cues people trust and the warnings we need to evaluate.

Read the privacy policy

03 / WHERE WE’RE HEADING

Listen. Test.
Then take the next step.

We’re exploring a future Kickstarter campaign. First, we’re collecting experiences and testing the idea. There’s no live crowdfunding campaign or launch date to announce yet.

  1. 01
    NOW

    Listen to real experiences

    Learn what makes phishing persuasive.

  2. 02
    IN DEVELOPMENT

    Test clearer identity warnings

    Evaluate the prototype and its limitations.

  3. 03
    PLANNED

    Explore a Kickstarter launch

    Share evidence, scope and next steps before asking for backing.

HELP SHAPE WHAT COMES NEXT

Start with your story.

Share your experience

No account needed. Follow-up contact is optional.