Check a Link Before You Open It

Lesson 15 min Beginner
Practise checking link context and destinations, recognizing suspicious URLs, shortened links and QR codes, and using independent navigation.
Suitable for
All Ages

A link can take you to useful information, but it can also lead to a fake login page, scam website, harmful download or another unexpected destination.

In this lesson you will practise checking the context and destination of a link before deciding whether to open it.

Goal: inspect suspicious links safely, recognize common warning signs and use independent navigation instead of trusting a link automatically.

Before you start

Review How to Recognize Phishing Messages.

Also review How to Check Whether a Website Is Safe.

You do not need to open any suspicious website for this lesson.

The examples use reserved demonstration addresses rather than real suspicious sites.

Why check a link before opening it?

A link can look familiar while pointing somewhere unexpected.

Attackers can use links to send people to:

  • fake login pages
  • fraudulent payment pages
  • impersonation websites
  • malware downloads
  • pages asking for personal information

The safest time to notice a problem is before interacting with the destination.

Start with the message around the link

Before examining the address, ask why the link arrived.

Consider:

  • Was I expecting this message?
  • Do I know the sender?
  • Does the request match something I recently did?
  • Is the message creating unusual urgency?
  • Is it asking me to sign in, pay, download something or provide information?

A link becomes more suspicious when the surrounding request does not make sense.

Unexpected does not automatically mean malicious

Legitimate organizations sometimes send unexpected messages.

The important point is that an unexpected message deserves verification before you follow its instructions.

You do not need to decide whether the message is genuine by clicking its link.

Step 1: Pause before clicking

Do not let urgency choose for you.

If a message says that your account will close, your parcel cannot be delivered or your payment failed, give yourself time to check.

A few extra moments can prevent a much larger problem.

Step 2: Identify what the link claims to be

Read the visible link text and the surrounding message.

Ask what organization or service the link claims to represent.

For example, a message might claim that the link opens:

  • your bank
  • your email service
  • a delivery company
  • a school portal
  • a social media account

Knowing the claimed destination gives you something to compare with the actual destination.

Visible link text is not always the destination

A page or message can display one piece of text while the underlying link points somewhere else.

For example, visible text might say:

Official account login

That wording tells you nothing by itself about the actual website address.

Step 3: Preview the destination without opening it when your device allows

Many desktop browsers and email applications can display a link destination when you place the pointer over a link without clicking it.

Many mobile devices provide a link preview or link information when you press and hold instead of opening the link normally.

The exact behaviour varies between applications and devices.

If your application does not provide a safe preview method that you understand, do not experiment with a suspicious link.

Use independent navigation instead.

Do not click merely to find out where a suspicious link goes

Opening the destination defeats the purpose of checking before opening it.

If the message already gives you reasons to distrust it, you do not need to visit the site to prove that it is fraudulent.

Step 4: Read the destination carefully

If you can inspect the destination safely, compare the complete website name with the organization you expected.

Look for:

  • misspellings
  • extra words
  • unexpected numbers
  • an unrelated website name
  • an unfamiliar ending

Practice with a safe example

Suppose a message claims to come from a service whose known demonstration address is:

account.example.invalid

But the link preview shows:

accounthelp.example.invalid

Those are different addresses.

The familiar word account does not make them identical.

The invalid ending is reserved for examples and is not a real public destination.

Watch for familiar words in unfamiliar addresses

A suspicious address may contain the name of the company being impersonated.

For example:

banklogin.example.invalid

The word bank does not prove that a bank owns the address.

Judge the complete destination, not one familiar word.

Step 5: Compare with a route you already trust

If the link claims there is a problem with an account, you usually do not need the link at all.

Instead:

  1. close or ignore the suspicious message
  2. open the official application yourself
  3. use a trusted bookmark or website address you already know
  4. sign in through the normal route
  5. check whether the claimed problem actually exists

This is called independent navigation.

Independent navigation is one of the strongest everyday habits

It separates your verification process from the message that may be trying to deceive you.

If the message is genuine, the real account will normally allow you to see the issue through its normal interface.

If the message is fake, you have avoided its link.

Example: A delivery message

You receive a text saying:

Your parcel cannot be delivered. Confirm your address now.

There is a link.

You are expecting a parcel.

That does not make the link automatically safe.

Safer response

  1. do not use the text message link
  2. open the retailer or delivery service you already used
  3. find your order or tracking information there
  4. check whether there is really a delivery problem

Example: A bank alert

You receive a message saying that a suspicious transaction requires immediate verification.

The message contains a link to sign in.

Safer response

Open the bank's normal application or known website independently.

Do not sign in through the unexpected link.

If necessary, contact the bank using an official contact method you already know or obtain independently.

Example: A message from someone you know

A friend's account sends you an unusual link with very little explanation.

The account may be genuine, but it could also have been compromised.

Safer response

Ask the person through another conversation or contact method whether they intended to send it.

Do not assume that possession of a friend's account proves the message is safe.

Shortened links need extra context

Some services create short addresses that hide the final destination.

Shortened links have legitimate uses.

However, when a message is unexpected or requests a sensitive action, a hidden destination gives you less information for checking it.

Use independent navigation rather than opening an unexplained shortened link.

QR codes should be treated like links

A QR code can direct your device to a website.

It is not safe merely because it appears on paper, a poster, an email or a screen.

If your device shows the destination before opening it, inspect that destination.

If the code came through an unexpected message and asks for a sensitive action, use an independent route instead.

FTC guidance specifically warns that malicious QR codes can lead to spoofed sites or harmful software. :contentReference[oaicite:2]{index=2}

Do not scan an unexpected QR code just because a message says it is urgent

Urgency should make you more careful, not less careful.

Examples include QR codes claiming to:

  • fix a payment problem
  • unlock an account
  • receive a refund
  • confirm a delivery
  • avoid a penalty

Links in advertisements also deserve checking

An advertisement can appear in a familiar search engine or social platform and still lead to a fraudulent site.

Do not assume that a result is official simply because it appears near the top of a page.

For important services, a known address or trusted bookmark can be safer than guessing from search results.

Step 6: Ask what will happen after the click

Before opening a link, consider what the message expects you to do next.

Is it asking you to:

  • enter a password
  • enter an authentication code
  • provide card information
  • upload an identity document
  • download a file
  • install software
  • send money

The more sensitive the next action is, the more important verification becomes.

A login request raises the stakes

If a link will supposedly take you to a login page, ask whether you can reach the same account through its normal application or known website.

There is rarely a good reason to risk a suspicious link when an independent route exists.

A payment request raises the stakes too

Do not enter payment information simply because a message says an invoice, toll, delivery or subscription is overdue.

Verify the claimed debt or transaction through the genuine service first.

Downloads need a separate decision

A link may lead directly to a file rather than a web page.

Unexpected files can contain malicious software.

Do not download a file merely because its name looks familiar.

Verify the sender and the reason for the file first.

Browser protection can help, but it is not perfect

Modern browsers can warn about known phishing sites, harmful downloads and other dangerous destinations.

These protections are valuable.

However, a warning system may not know about every new fraudulent site immediately.

The absence of a warning is not proof that a link is safe.

Do not bypass a dangerous site warning casually

If your browser identifies a destination as dangerous, stop.

Do not enter personal information or credentials.

Use a trusted route to the organization instead.

HTTPS is not enough

A suspicious link may lead to a website using a protected HTTPS connection.

HTTPS protects information travelling between your browser and that website.

It does not prove that the website belongs to the organization you intended to visit.

Chrome's own guidance says that even with a secure connection you should check the site name in the address bar. :contentReference[oaicite:3]{index=3}

Step 7: Decide whether you need the link at all

This question simplifies many situations.

Can I complete this task without using this link?

If you can open the official application, use a trusted bookmark or contact the organization independently, the suspicious link may be unnecessary.

Practice activity 1: Account suspension

You receive an unexpected email saying:

Your streaming account will be suspended today. Sign in now.

The email contains a button.

What should you do?

Suggested answer

Do not use the button.

Open the streaming service independently through its normal application or website and check your account there.

Practice activity 2: Familiar sender

A classmate sends:

Look at this. Is this you?

A shortened link follows.

What should you do?

Suggested answer

Do not open it simply because the message came from a familiar account.

Confirm with the classmate through another trusted conversation that they intended to send the link.

Practice activity 3: Website mismatch

A message claims to lead to:

portal.example.invalid

Your safe preview shows:

portalverify.example.invalid

Are they the same destination?

Suggested answer

No.

They are different website addresses.

Do not assume that similar wording means the same organization owns both.

Practice activity 4: QR code

A poster says you must scan a QR code immediately to avoid an account penalty.

You were not expecting the request.

What is safer?

Suggested answer

Do not rely on the QR code.

Open the relevant organization through a known official route and check whether the claimed issue exists.

Practice activity 5: No browser warning

You inspect an unfamiliar link and your browser does not display a warning.

Does that prove the destination is trustworthy?

Suggested answer

No.

Browser protection can identify many known threats, but the absence of a warning does not prove that a new or unfamiliar website is legitimate.

Practice activity 6: Secure connection

A website uses HTTPS but its address is not the company you expected.

Should you enter your password?

Suggested answer

No.

A protected connection does not make the wrong destination correct.

If you accidentally opened a suspicious link

Do not continue simply because the page is already open.

Avoid entering information or downloading files.

If the browser or device displays a security warning, follow trusted security guidance.

NCSC advises people who opened a suspicious link or followed instructions to install software to run appropriate security checks on the device. :contentReference[oaicite:4]{index=4}

If you entered a password

If you believe you entered a password into a fraudulent page:

  1. open the genuine service independently
  2. change the compromised password
  3. replace it anywhere else it was reused
  4. review active sessions
  5. review multi factor authentication

If you entered financial information

Contact the relevant financial provider using its official contact method.

Explain what information may have been exposed and follow its fraud response instructions.

If you downloaded a suspicious file

Do not open or run it merely to see what it contains.

Use trusted security guidance for your device.

If the device belongs to a school or employer, follow its reporting process.

Common link checking mistakes

  • clicking first and checking later
  • trusting visible link text without checking the destination
  • trusting a link because the sender name looks familiar
  • assuming the first search result is official
  • assuming HTTPS proves the organization is genuine
  • opening a shortened link just to discover where it goes
  • scanning an unexpected QR code without checking context
  • ignoring urgency and pressure as warning signs
  • entering credentials when an independent route is available
  • assuming no browser warning means no risk

A practical link checking routine

Before opening an unfamiliar or sensitive link, use this sequence:

  1. Pause.
  2. Check whether the message was expected.
  3. Identify the organization the link claims to represent.
  4. Preview the destination safely if your application provides a method you understand.
  5. Read the complete destination carefully.
  6. Consider what the link will ask you to do.
  7. Use independent navigation when possible.
  8. Do not bypass browser danger warnings casually.
  9. Do not enter credentials or payment information when the destination is uncertain.

Quick decision guide

If a link is unexpected and asks for a password:

Do not use the link. Open the real service independently.

If a familiar contact sends an unusual unexplained link:

Verify with the person before opening it.

If a browser identifies the site as dangerous:

Do not continue to the site.

If you cannot determine where a shortened link goes safely:

Use another trusted route instead.

Self check

  1. Why can visible link text be misleading?
  2. Why is an unexpected message important context?
  3. What is independent navigation?
  4. Does HTTPS prove that a website belongs to the organization you expected?
  5. Why should a familiar sender not automatically make a link trustworthy?
  6. What should you do when a link asks you to sign in to an important account?

Suggested answers

  1. The displayed words and the actual destination can be different.
  2. Unexpected requests are a common part of phishing and deserve verification before action.
  3. It means reaching the real service through a route you already trust instead of using the suspicious link.
  4. No. HTTPS protects the connection but does not prove the identity or honesty of the website operator.
  5. The person's account may have been compromised or impersonated.
  6. Prefer opening the real account independently and check whether the claimed issue exists there.

Lesson summary

You do not need to open a suspicious link in order to investigate it.

Start with the context of the message and ask whether the request was expected.

Preview the destination safely when your device provides a method you understand, then compare the complete address with the service you expected.

Remember that shortened links, QR codes, familiar sender names, HTTPS and professional design do not prove that a destination is trustworthy.

For important accounts, payments and personal information, independent navigation is usually the safest practical choice.

Continue learning

Review How to Recognize Phishing Messages for the wider signs of phishing.

Review How to Check Whether a Website Is Safe for evaluating a website after reaching it through a trusted route.

Sources and further reading