Phishing or scam link
How to spot phishing links
A phishing link is a link designed to trick you into giving up information, installing something, paying a scammer, or opening a fake sign-in page.
What it is
A phishing link is a link designed to trick you into giving up information, installing something, paying a scammer, or opening a fake sign-in page.
Why it matters
Phishing is one of the most common ways attackers get passwords, payment information, MFA codes, and remote access. The link may look normal while the destination is built to steal trust.
Warning signs
- The message creates urgency, fear, curiosity, or a reward.
- The sender asks you to sign in, pay, verify, update, download, or approve something.
- The link destination is unfamiliar, shortened, misspelled, or unrelated to the claimed sender.
- The page asks for credentials, payment details, MFA codes, recovery codes, or remote access.
What to do
- Stop before signing in or downloading anything.
- Check the sender, visible link text, and actual destination domain.
- Open the real service manually from a bookmark, password manager, or typed address.
- Report the message to your IT contact, email provider, or the service being impersonated.
- If you already entered credentials, change the password from the real site and revoke active sessions.
Examples
Risky: A text says your account will close today unless you sign in through a short link.
Safer: Open the company site from your own bookmark or typed address and check notifications there.
Risky: An invoice email says to download a new viewer before you can see the bill.
Safer: Call the vendor using a known number or open the vendor portal directly.
Common mistakes
- Trusting a logo, brand color, or professional-looking design by itself.
- Assuming a link is safe because it arrived from a known person whose account may be compromised.
- Signing in from the link instead of opening the service from a saved bookmark.
Key takeaway: Do not use the link as your source of truth. Use a known-good path to the account, vendor, or person instead.