A link can take you to useful information, but it can also lead to a fake login page, scam website, harmful download or another unexpected destination.
In this lesson you will practise checking the context and destination of a link before deciding whether to open it.
Goal: inspect suspicious links safely, recognize common warning signs and use independent navigation instead of trusting a link automatically.
Before you start
Review How to Recognize Phishing Messages.
Also review How to Check Whether a Website Is Safe.
You do not need to open any suspicious website for this lesson.
The examples use reserved demonstration addresses rather than real suspicious sites.
Why check a link before opening it?
A link can look familiar while pointing somewhere unexpected.
Attackers can use links to send people to:
- fake login pages
- fraudulent payment pages
- impersonation websites
- malware downloads
- pages asking for personal information
The safest time to notice a problem is before interacting with the destination.
Start with the message around the link
Before examining the address, ask why the link arrived.
Consider:
- Was I expecting this message?
- Do I know the sender?
- Does the request match something I recently did?
- Is the message creating unusual urgency?
- Is it asking me to sign in, pay, download something or provide information?
A link becomes more suspicious when the surrounding request does not make sense.
Unexpected does not automatically mean malicious
Legitimate organizations sometimes send unexpected messages.
The important point is that an unexpected message deserves verification before you follow its instructions.
You do not need to decide whether the message is genuine by clicking its link.
Step 1: Pause before clicking
Do not let urgency choose for you.
If a message says that your account will close, your parcel cannot be delivered or your payment failed, give yourself time to check.
A few extra moments can prevent a much larger problem.
Step 2: Identify what the link claims to be
Read the visible link text and the surrounding message.
Ask what organization or service the link claims to represent.
For example, a message might claim that the link opens:
- your bank
- your email service
- a delivery company
- a school portal
- a social media account
Knowing the claimed destination gives you something to compare with the actual destination.
Visible link text is not always the destination
A page or message can display one piece of text while the underlying link points somewhere else.
For example, visible text might say:
Official account login
That wording tells you nothing by itself about the actual website address.
Step 3: Preview the destination without opening it when your device allows
Many desktop browsers and email applications can display a link destination when you place the pointer over a link without clicking it.
Many mobile devices provide a link preview or link information when you press and hold instead of opening the link normally.
The exact behaviour varies between applications and devices.
If your application does not provide a safe preview method that you understand, do not experiment with a suspicious link.
Use independent navigation instead.
Do not click merely to find out where a suspicious link goes
Opening the destination defeats the purpose of checking before opening it.
If the message already gives you reasons to distrust it, you do not need to visit the site to prove that it is fraudulent.
Step 4: Read the destination carefully
If you can inspect the destination safely, compare the complete website name with the organization you expected.
Look for:
- misspellings
- extra words
- unexpected numbers
- an unrelated website name
- an unfamiliar ending
Practice with a safe example
Suppose a message claims to come from a service whose known demonstration address is:
account.example.invalid
But the link preview shows:
accounthelp.example.invalid
Those are different addresses.
The familiar word account does not make them identical.
The invalid ending is reserved for examples and is not a real public destination.
Watch for familiar words in unfamiliar addresses
A suspicious address may contain the name of the company being impersonated.
For example:
banklogin.example.invalid
The word bank does not prove that a bank owns the address.
Judge the complete destination, not one familiar word.
Step 5: Compare with a route you already trust
If the link claims there is a problem with an account, you usually do not need the link at all.
Instead:
- close or ignore the suspicious message
- open the official application yourself
- use a trusted bookmark or website address you already know
- sign in through the normal route
- check whether the claimed problem actually exists
This is called independent navigation.
Independent navigation is one of the strongest everyday habits
It separates your verification process from the message that may be trying to deceive you.
If the message is genuine, the real account will normally allow you to see the issue through its normal interface.
If the message is fake, you have avoided its link.
Example: A delivery message
You receive a text saying:
Your parcel cannot be delivered. Confirm your address now.
There is a link.
You are expecting a parcel.
That does not make the link automatically safe.
Safer response
- do not use the text message link
- open the retailer or delivery service you already used
- find your order or tracking information there
- check whether there is really a delivery problem
Example: A bank alert
You receive a message saying that a suspicious transaction requires immediate verification.
The message contains a link to sign in.
Safer response
Open the bank's normal application or known website independently.
Do not sign in through the unexpected link.
If necessary, contact the bank using an official contact method you already know or obtain independently.
Example: A message from someone you know
A friend's account sends you an unusual link with very little explanation.
The account may be genuine, but it could also have been compromised.
Safer response
Ask the person through another conversation or contact method whether they intended to send it.
Do not assume that possession of a friend's account proves the message is safe.
Shortened links need extra context
Some services create short addresses that hide the final destination.
Shortened links have legitimate uses.
However, when a message is unexpected or requests a sensitive action, a hidden destination gives you less information for checking it.
Use independent navigation rather than opening an unexplained shortened link.
QR codes should be treated like links
A QR code can direct your device to a website.
It is not safe merely because it appears on paper, a poster, an email or a screen.
If your device shows the destination before opening it, inspect that destination.
If the code came through an unexpected message and asks for a sensitive action, use an independent route instead.
FTC guidance specifically warns that malicious QR codes can lead to spoofed sites or harmful software. :contentReference[oaicite:2]{index=2}
Do not scan an unexpected QR code just because a message says it is urgent
Urgency should make you more careful, not less careful.
Examples include QR codes claiming to:
- fix a payment problem
- unlock an account
- receive a refund
- confirm a delivery
- avoid a penalty
Links in advertisements also deserve checking
An advertisement can appear in a familiar search engine or social platform and still lead to a fraudulent site.
Do not assume that a result is official simply because it appears near the top of a page.
For important services, a known address or trusted bookmark can be safer than guessing from search results.
Step 6: Ask what will happen after the click
Before opening a link, consider what the message expects you to do next.
Is it asking you to:
- enter a password
- enter an authentication code
- provide card information
- upload an identity document
- download a file
- install software
- send money
The more sensitive the next action is, the more important verification becomes.
A login request raises the stakes
If a link will supposedly take you to a login page, ask whether you can reach the same account through its normal application or known website.
There is rarely a good reason to risk a suspicious link when an independent route exists.
A payment request raises the stakes too
Do not enter payment information simply because a message says an invoice, toll, delivery or subscription is overdue.
Verify the claimed debt or transaction through the genuine service first.
Downloads need a separate decision
A link may lead directly to a file rather than a web page.
Unexpected files can contain malicious software.
Do not download a file merely because its name looks familiar.
Verify the sender and the reason for the file first.
Browser protection can help, but it is not perfect
Modern browsers can warn about known phishing sites, harmful downloads and other dangerous destinations.
These protections are valuable.
However, a warning system may not know about every new fraudulent site immediately.
The absence of a warning is not proof that a link is safe.
Do not bypass a dangerous site warning casually
If your browser identifies a destination as dangerous, stop.
Do not enter personal information or credentials.
Use a trusted route to the organization instead.
HTTPS is not enough
A suspicious link may lead to a website using a protected HTTPS connection.
HTTPS protects information travelling between your browser and that website.
It does not prove that the website belongs to the organization you intended to visit.
Chrome's own guidance says that even with a secure connection you should check the site name in the address bar. :contentReference[oaicite:3]{index=3}
Step 7: Decide whether you need the link at all
This question simplifies many situations.
Can I complete this task without using this link?
If you can open the official application, use a trusted bookmark or contact the organization independently, the suspicious link may be unnecessary.
Practice activity 1: Account suspension
You receive an unexpected email saying:
Your streaming account will be suspended today. Sign in now.
The email contains a button.
What should you do?
Suggested answer
Do not use the button.
Open the streaming service independently through its normal application or website and check your account there.
Practice activity 2: Familiar sender
A classmate sends:
Look at this. Is this you?
A shortened link follows.
What should you do?
Suggested answer
Do not open it simply because the message came from a familiar account.
Confirm with the classmate through another trusted conversation that they intended to send the link.
Practice activity 3: Website mismatch
A message claims to lead to:
portal.example.invalid
Your safe preview shows:
portalverify.example.invalid
Are they the same destination?
Suggested answer
No.
They are different website addresses.
Do not assume that similar wording means the same organization owns both.
Practice activity 4: QR code
A poster says you must scan a QR code immediately to avoid an account penalty.
You were not expecting the request.
What is safer?
Suggested answer
Do not rely on the QR code.
Open the relevant organization through a known official route and check whether the claimed issue exists.
Practice activity 5: No browser warning
You inspect an unfamiliar link and your browser does not display a warning.
Does that prove the destination is trustworthy?
Suggested answer
No.
Browser protection can identify many known threats, but the absence of a warning does not prove that a new or unfamiliar website is legitimate.
Practice activity 6: Secure connection
A website uses HTTPS but its address is not the company you expected.
Should you enter your password?
Suggested answer
No.
A protected connection does not make the wrong destination correct.
If you accidentally opened a suspicious link
Do not continue simply because the page is already open.
Avoid entering information or downloading files.
If the browser or device displays a security warning, follow trusted security guidance.
NCSC advises people who opened a suspicious link or followed instructions to install software to run appropriate security checks on the device. :contentReference[oaicite:4]{index=4}
If you entered a password
If you believe you entered a password into a fraudulent page:
- open the genuine service independently
- change the compromised password
- replace it anywhere else it was reused
- review active sessions
- review multi factor authentication
If you entered financial information
Contact the relevant financial provider using its official contact method.
Explain what information may have been exposed and follow its fraud response instructions.
If you downloaded a suspicious file
Do not open or run it merely to see what it contains.
Use trusted security guidance for your device.
If the device belongs to a school or employer, follow its reporting process.
Common link checking mistakes
- clicking first and checking later
- trusting visible link text without checking the destination
- trusting a link because the sender name looks familiar
- assuming the first search result is official
- assuming HTTPS proves the organization is genuine
- opening a shortened link just to discover where it goes
- scanning an unexpected QR code without checking context
- ignoring urgency and pressure as warning signs
- entering credentials when an independent route is available
- assuming no browser warning means no risk
A practical link checking routine
Before opening an unfamiliar or sensitive link, use this sequence:
- Pause.
- Check whether the message was expected.
- Identify the organization the link claims to represent.
- Preview the destination safely if your application provides a method you understand.
- Read the complete destination carefully.
- Consider what the link will ask you to do.
- Use independent navigation when possible.
- Do not bypass browser danger warnings casually.
- Do not enter credentials or payment information when the destination is uncertain.
Quick decision guide
If a link is unexpected and asks for a password:
Do not use the link. Open the real service independently.
If a familiar contact sends an unusual unexplained link:
Verify with the person before opening it.
If a browser identifies the site as dangerous:
Do not continue to the site.
If you cannot determine where a shortened link goes safely:
Use another trusted route instead.
Self check
- Why can visible link text be misleading?
- Why is an unexpected message important context?
- What is independent navigation?
- Does HTTPS prove that a website belongs to the organization you expected?
- Why should a familiar sender not automatically make a link trustworthy?
- What should you do when a link asks you to sign in to an important account?
Suggested answers
- The displayed words and the actual destination can be different.
- Unexpected requests are a common part of phishing and deserve verification before action.
- It means reaching the real service through a route you already trust instead of using the suspicious link.
- No. HTTPS protects the connection but does not prove the identity or honesty of the website operator.
- The person's account may have been compromised or impersonated.
- Prefer opening the real account independently and check whether the claimed issue exists there.
Lesson summary
You do not need to open a suspicious link in order to investigate it.
Start with the context of the message and ask whether the request was expected.
Preview the destination safely when your device provides a method you understand, then compare the complete address with the service you expected.
Remember that shortened links, QR codes, familiar sender names, HTTPS and professional design do not prove that a destination is trustworthy.
For important accounts, payments and personal information, independent navigation is usually the safest practical choice.
Continue learning
Review How to Recognize Phishing Messages for the wider signs of phishing.
Review How to Check Whether a Website Is Safe for evaluating a website after reaching it through a trusted route.