All lessons

Phishing or scam link

How to spot phishing links

A phishing link is a link designed to trick you into giving up information, installing something, paying a scammer, or opening a fake sign-in page.

beginnerphishingurl phishing
What Happens If You Click a Bad Link? · Ask Leo!

What it is

A phishing link is a link designed to trick you into giving up information, installing something, paying a scammer, or opening a fake sign-in page.

Why it matters

Phishing is one of the most common ways attackers get passwords, payment information, MFA codes, and remote access. The link may look normal while the destination is built to steal trust.

Warning signs

  • The message creates urgency, fear, curiosity, or a reward.
  • The sender asks you to sign in, pay, verify, update, download, or approve something.
  • The link destination is unfamiliar, shortened, misspelled, or unrelated to the claimed sender.
  • The page asks for credentials, payment details, MFA codes, recovery codes, or remote access.

What to do

  1. Stop before signing in or downloading anything.
  2. Check the sender, visible link text, and actual destination domain.
  3. Open the real service manually from a bookmark, password manager, or typed address.
  4. Report the message to your IT contact, email provider, or the service being impersonated.
  5. If you already entered credentials, change the password from the real site and revoke active sessions.

Examples

Risky: A text says your account will close today unless you sign in through a short link.

Safer: Open the company site from your own bookmark or typed address and check notifications there.

Risky: An invoice email says to download a new viewer before you can see the bill.

Safer: Call the vendor using a known number or open the vendor portal directly.

Common mistakes

  • Trusting a logo, brand color, or professional-looking design by itself.
  • Assuming a link is safe because it arrived from a known person whose account may be compromised.
  • Signing in from the link instead of opening the service from a saved bookmark.

Key takeaway: Do not use the link as your source of truth. Use a known-good path to the account, vendor, or person instead.

Check what stuck

1. You see a "Phishing or scam link" warning. What is the right response?
2. Which of these is a genuine warning sign?