Guide
How to check a link without clicking it
Do not start by asking, "does the link look real?"
Start with this:
Did you expect this message, from this sender, asking you to do this, through this link?
If the answer is no, do not click. Open the app or website yourself.
The link check
| Check | What to look for |
|---|---|
| Sender | Does it match older real messages? |
| Domain | Is it the exact official domain, not almost right? |
| Context | Were you expecting the package, invoice, login, or payment? |
| Request | Is it asking for password, code, card, or payment? |
| Urgency | Is the deadline doing the work? |
| Route | Can you do the same thing inside the official app? |
Almost right is still wrong
Scam links often use:
- Misspelled domains.
- Extra words before or after the brand.
- Link shorteners.
- Strange subdomains.
- Domains that end in a different country or company.
- Buttons where the real URL is hidden.
Do not try to fix the link. Type the official address yourself.
If the link came in an email attachment or invoice, the safer next read is how to check whether an email attachment is safe.
What to do instead of clicking
- Open the official app.
- Type the official website yourself.
- Use the phone number on your card, bill, or account page.
- Search the tracking number on the real courier site.
- Ask the sender through an existing thread or known number.
If you already clicked
If you clicked but did not type anything, close the page.
If you entered a password, code, card number, ID, or payment details, treat it as a recovery situation. Change the password from the real site, contact the bank or platform, and save screenshots.
Sources
- CISA, avoiding social engineering and phishing attacks: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
- FTC, recognizing and reporting spam text messages: https://consumer.ftc.gov/articles/how-recognize-and-report-spam-text-messages
- 7726 SMS scam reports research: https://arxiv.org/abs/2508.05276