Opening a suspicious link merely to inspect it can expose the browser to tracking, a deceptive login or a malicious download. Most verification can happen without visiting the destination.
Read the actual host name
On desktop, hover without clicking; on mobile, press and hold to preview. In accounts.example.com.attacker.test, the controlling domain is attacker.test, not the familiar words at the beginning.
Watch for visual substitutions
Misspellings, extra hyphens, uncommon endings and Unicode look-alike characters can imitate a brand. A padlock only means the connection to that domain is encrypted; it does not make the domain legitimate.
Verify the task, not the link
- Open the official app or use a saved bookmark.
- Check the account's notification or billing page.
- Contact the sender through a separate known channel.
- Submit workplace messages to the security team's analysis system.
Use scanners with restraint
A reputation service may help with a public, non-sensitive URL. Do not upload private password-reset, document-share or internal company links to a public scanner because the URL itself may grant access or expose information.
The safest link check often avoids the link entirely. If the claimed action is real, it should also be visible inside the independently reached account.
Redirects require the final destination
A legitimate-looking tracking domain can redirect elsewhere. Workplace analysis tools can expand redirects in an isolated environment, but ordinary users should avoid the chain and reach the claimed service directly. URL shorteners remove the most useful visual clue.
Handle document links as credentials
Some share links contain access tokens. Posting them publicly to ask whether they are safe can expose the document. Send sensitive links only through the organization's approved security channel.
Decode without disclosing private tokens
Short links and tracking redirects can hide the final host. A local URL parser or an organization's approved analysis tool is safer than visiting the link. Password-reset, file-share and invitation URLs may contain bearer tokens, so do not paste them into a public reputation service.
Apply the registrable-domain test
Read from the first slash backward and identify the domain controlled by the site. Familiar words in the path or subdomain do not change ownership. Internationalized domains need extra care because visually similar characters may come from different alphabets.
Even a clean reputation result is only historical evidence. A new phishing site may have no record yet, and a compromised legitimate site may change after scanning. Confirm the requested action inside the official account.
Read ownership from the registered domain
Start at the first slash and read the hostname from right to left. Familiar words in a subdomain or path do not change who controls the registered domain. Check for misspellings, unusual character sets and an unexpected top-level domain. A padlock only confirms encryption to that hostname.
Shorteners and marketing redirects hide the final destination. Ordinary users should avoid the chain and open the claimed service through a bookmark or typed address. Security teams can expand redirects in an isolated environment that records every hop.
Do not leak access tokens while checking
Password-reset, document-sharing and invitation links may contain a bearer token. Pasting one into a public scanner can give that service access to the resource. Redact or analyse sensitive URLs locally and use the organization's approved reporting channel.
A clean reputation result is historical evidence, not a guarantee. New phishing domains and newly compromised legitimate pages may have no warnings. Confirm the requested action inside the official account before entering credentials or approving a payment.