Mismatched link text
When a link says one site but opens another
A mismatched link happens when the words on the page say one destination, but the actual link target points somewhere else.
What it is
A mismatched link happens when the words on the page say one destination, but the actual link target points somewhere else.
Why it matters
Attackers often hide the real destination behind familiar words. Some legitimate tools use redirects too, but a mismatch should be treated as a verification step before trust.
Warning signs
- The text says one organization, but the actual link opens another domain.
- The link uses a redirector, tracking URL, or shortened URL that hides the final destination.
- The visible text is a familiar brand, but the destination is a file host or unknown site.
- The destination asks for sign-in after a redirect.
What to do
- Hover, long-press, or use your browser's link preview before opening.
- Compare the actual domain to the organization named on the page.
- Avoid entering credentials after redirects unless you intentionally navigated there.
- If the mismatch came from an internal document, ask the sender to confirm through another channel.
Examples
Risky: The page says microsoft.com, but the actual link goes to an unrelated domain.
Safer: Use Microsoft from your bookmark, password manager, or typed address.
Risky: A button says View payroll, but the link opens a file-sharing domain you do not use.
Safer: Ask payroll or HR through a known channel before opening it.
Common mistakes
- Reading only the blue text instead of checking where it actually goes.
- Assuming every marketing redirect is safe.
- Following a link because the sender appears internal.
Key takeaway: The clickable destination matters more than the visible words. Treat a mismatch as a reason to pause.