Can AI Write Your Content? Yes, But Not Alone

One of our team received an email that looked, at first glance, quite believable.

The message said:

“Your employer has arranged for you to attend an upcoming Ads on Air webinar…”

That is clever.

It immediately creates a sense of familiarity. Your employer has arranged it. It relates to Google Ads. It sounds like training. There is no obvious demand for money and no wildly suspicious story.

You could quite easily think, “Okay, work has organised this. I’ll sign in.”

And that is exactly why we are sharing it.

A message can mention your employer and still be fake

We tend to be more cautious when an unexpected email comes from a bank, courier company or stranger.

But what happens when it says your employer has organised something for you?

Your guard can drop.

Perhaps you assume somebody else in the business arranged the webinar. Maybe marketing registered the team. Perhaps your manager forgot to mention it.

That small amount of doubt can be enough to make you click.

Netsafe warns that phishing emails are becoming increasingly difficult to identify and can use spoofed sender details, familiar branding and information that makes the message seem credible.

CERT NZ also points out that attackers can make an email appear to come from a person or organisation you know and trust. In some cases, even the displayed sender address can look correct.

What happened in our case?

The email appeared to come from:

no_reply@gotsport.com

It claimed the recipient’s employer had arranged attendance at a Google Ads webinar.

The link then led to:

entry.skillroomonline.com

The page looked remarkably like a genuine Google page.

Google branding.

Google style.

Familiar typography.

Professional layout.

Nothing immediately screamed “fake”.

But looking like Google and being Google are two very different things.

The biggest clue was sitting in the address bar

The destination was not on google.com.

It was on skillroomonline.com.

That alone deserved further checking.

If a website is asking you to sign in to a Google service, but the domain you are visiting belongs to an unrelated organisation, stop.

Google itself advises users not to enter their Google password after following a link in an email. Instead, go directly to the Google service or your Google Account yourself.

That is a simple habit that can save you a considerable amount of trouble.

Then we looked more closely

Several things did not add up.

  • The destination domain did not match Google.
  • Many of the page’s secondary links and navigation elements did not behave like a normal Google website. Some simply returned to the same page or added a # to the URL.
  • The Google branding looked convincing, but branding can be copied.
  • The message was unexpected.
  • The wording encouraged the recipient to trust the request because it supposedly came via their employer.
  • Independent domain checking raised further concerns. A security scanner report dated 14 September 2026 classified skillroomonline.com as suspicious, recorded a blacklist detection and noted that there was very little established reputation history for the domain.

We also used AI as one of several checks on the destination.

That can be useful, but there is an important distinction here.

Do not rely on an AI answer alone to decide whether a link is safe. Check the actual domain, use reputable security tools, contact the organisation independently and, where possible, go directly to the official website instead.

Then we looked more closely

The page looked real. That is the point.

Years ago, many phishing emails were easy to spot.

  • Poor spelling.
  • Odd logos.
  • Strange formatting.
  • Bad English.

That is no longer something you can rely on.

A scam page can copy the appearance of a legitimate website very closely. Google specifically warns that phishing content can look exactly like a message from an organisation or person you trust.

So instead of asking:

“Does this look real?”

Start asking:

“Can I prove this is real?”

There is quite a difference between those two questions.

Stay safe online by checking the destination, not just the design

Before signing in through a link you have received, look at the actual domain.

If you receive a Google notification, open Google yourself.

If Microsoft supposedly needs something, go directly to Microsoft.

If your bank contacts you, open your banking app or type the bank’s known website address yourself.

And if an email says your employer has arranged something that you were not expecting, ask them.

A ten second internal message could prevent an account compromise.

Consumer Protection New Zealand gives similar advice. Do not click a link until you have verified it. Research the organisation independently and use contact details from its official website rather than contact information supplied in the suspicious message.

What if you have already entered your Google password?

Act quickly.

Go directly to your Google Account rather than returning to the link in the email.

Change your password.

Review recent security activity.

Check which devices are signed in.

Remove anything you do not recognise.

Check your recovery email address, phone number and other security settings.

Google recommends immediately changing your password and reviewing account activity if you believe somebody else may have accessed your account.

You should also tell your employer or IT provider, particularly if the account is connected to business systems, advertising accounts, customer information or company files.

Awareness is still one of our best defences

We are sharing this because one person spotting a scam can help ten other people recognise the next one.

This email was convincing.

The website was convincing.

The reference to the employer made it even more believable.

But the domain told a different story.

Stay safe online.

Be cautious with unexpected requests, even when the message mentions your employer, manager, colleague or a company you trust.

And perhaps the most useful rule is this:

If a message wants you to sign in, do not let the email choose where you sign in.

Go there yourself.

FAQs

Can a phishing email really look as though it came from a legitimate sender?

Yes. Sender information can be spoofed, and attackers can also take advantage of compromised or poorly protected email systems. Checking the sender address is useful, but it should not be your only check.

Is a website safe if it has the Google logo on it?

No. Logos, page layouts, fonts and other visual elements can be copied. Check the web address and make sure you are on the organisation’s genuine domain before entering login details.

Should I click a suspicious link to investigate it?

No. If you are unsure, do not click it. Netsafe recommends avoiding links and attachments in suspected phishing emails. Use an independent link checking service or ask your IT provider to investigate it.

Can AI tell me whether an email or website is a scam?

AI can help identify warning signs and assist with research, but you should not treat an AI response as your only security check. Confirm the domain, use recognised security services and contact the organisation independently when necessary.

Where can New Zealanders check a suspicious website?

Netsafe provides its CheckNetsafe service to help New Zealanders assess suspicious websites and links.

Where can I report phishing in New Zealand?

You can report scams and suspicious online activity to Netsafe. Serious fraud can also be reported to New Zealand Police through 105.

Need help protecting your business online?

Cyber safety is no longer just an IT issue. Your email, website, Google accounts, advertising platforms and online business profiles are all connected.

If something does not look right, check it before you act.