
Phishing attacks rely on malicious links disguised as legitimate URLs, and knowing how to check phishing links takes a few seconds once it becomes a habit. This checklist walks through the steps in order, from reading the real domain to scanning the URL and reporting anything that still looks off, so you can protect your personal and corporate data.
Key takeaways
- Hover over every link and read the real domain, checking for lookalike characters, odd TLDs and shortened URLs before you click.
- HTTPS and a padlock only mean the connection is encrypted, so they never prove a site is safe on their own.
- When a link still looks doubtful, do not click it and report it. Security teams can build that habit with phishing simulations and a simple reporting process.
Check Phishing Link Checklist: 9 Steps Before You Click
Run through these steps in order whenever a link feels unexpected. Most phishing links fail at one of the first five.
- Hover over the link and read the real domain.
- Check for lookalike characters in the domain.
- Check the top-level domain (TLD).
- Expand shortened URLs before you open them.
- Check HTTPS, but do not trust it alone.
- Check the sender and the context of the message.
- Run the URL through a URL scanner.
- Do not click or enter credentials if you are still unsure.
- When in doubt, report it.
1. Be Cautious with Suspicious URLs
The first step in checking a potential phishing link is to be cautious. If you receive an unexpected email or message containing a link, avoid clicking it immediately. Cybercriminals often use seemingly legitimate messages to lure you into clicking on harmful URLs.
Hover Over the Link: Instead of clicking, hover your mouse over the link to reveal its full URL. This allows you to inspect the link’s actual destination. The real domain is the part right before the first single slash, so "paypal.com.secure-login.example" belongs to "secure-login.example", not to PayPal.
Check for Lookalike Characters: Look for misspellings, numbers replacing letters (e.g., "faceb00k.com" instead of "facebook.com"), "rn" posing as "m", or unusual characters that imitate Latin letters. Domains starting with "xn--" use special characters and deserve a closer look.
Check the TLD: Read the ending of the domain. A familiar brand name paired with an unexpected TLD, such as a well-known company on a cheap or unrelated extension, is a common sign of a fake site.
Shortened URLs: Be wary of shortened URLs, like those created with services such as Bitly or TinyURL. These links can obscure the final destination, making it difficult to assess their safety. Use online tools to expand shortened URLs before deciding whether to proceed.
HTTPS Is Not Proof of Safety: A padlock only shows that the connection to the site is encrypted. Attackers can get HTTPS certificates for their own fake domains, so use it as one signal and never as the final answer.
Check the Sender Context: Ask whether you expected this message. Urgency, a sender address that does not match the company, or a request to log in or pay right away are all warning signs. When in doubt, confirm through another channel, such as the official website or a phone number you already know.
The same checks apply to links hidden behind a QR code. See how QR code phishing works and why it is hard to spot.
2. Use Tools to Check Phishing Links
For those who want to add an extra layer of security, there are tools available that can help identify phishing links. One such tool is URLScan, which allows you to inspect URLs for malicious content without having to visit the link. Other options include VirusTotal and the Google Safe Browsing site status check.
How URLScan Works
Submit the URL: Enter the suspicious URL into URLScan's search field. The tool will scan the link, check its destination, and provide a detailed report on whether the URL is likely safe or malicious.
Analyze the Results: URLScan provides information about the link, including its IP address, hosting details, and any security warnings. This analysis can help you make an informed decision about whether the URL is safe to visit.
A clean scan result is not a guarantee, because newly created phishing pages can go unflagged for a while. Public scanners can also publish the scan, so never submit links that contain personal tokens, such as password reset or login links. While tools like URLScan can be valuable, remember that they should complement, rather than replace, professional cybersecurity practices and training.
3. Leave Verification to the Experts
While there are methods to check phishing links, identifying sophisticated phishing attempts is often best left to cybersecurity professionals. Attackers use advanced techniques to mimic legitimate websites, making it challenging for the average user to distinguish between safe and malicious links.
If you come across a link that raises suspicion:
Do Not Click: Avoid clicking on the link. Even if the URL looks partially legitimate, cybercriminals may create URLs that closely resemble trusted websites.
Report It: Report the suspicious link to your IT or cybersecurity team immediately, using your company's reporting button or channel. Experts can verify the link's safety and take the necessary actions to protect the organization.
For Security Teams: Train Employees on the Checklist
A checklist only works if employees use it under pressure. Security teams can build that habit in four moves:
Share the checklist as a one-page card. Pin it in your intranet and reference it in onboarding and awareness sessions.
Run phishing simulations that test each step. Send campaigns with lookalike domains, shortened links and QR codes, so employees practice the exact checks in the checklist.
Make reporting a single click. A report button in the mail client removes friction, and employees should get a quick confirmation that their report was received.
Measure the report rate and the time to report. Click rate alone hides progress. How many employees report a suspicious link, and how fast, shows whether the habit is sticking.
Each phishing simulation gives you these numbers per team, so you can follow the trend and focus training where it is needed.
Final Thoughts
Phishing attacks are increasingly sophisticated, making it more important than ever to know how to check phishing links effectively. Always be cautious with suspicious URLs, hover to inspect links before clicking, and be careful with shortened URLs. When the checklist leaves you unsure, report the link and let your security team verify it.
Frequently Asked Questions
-
Hover over the link to read the real domain, look for lookalike characters and unusual TLDs, expand any shortened URL, and consider whether you expected the message. If the link is still doubtful, scan it with a URL scanner or report it to your IT or security team without clicking.
-
No. HTTPS only means the connection to the site is encrypted. Attackers can obtain HTTPS certificates for fake domains, so a padlock is not proof that a site is legitimate.
-
Yes, in most cases. Scanners such as URLScan and VirusTotal load the page from their own servers, so you do not visit it yourself. Avoid submitting links that contain personal tokens, like password reset links, because some scanners make results public.
-
Close the page without entering anything and report it to your IT or security team right away. If you typed a password, change it immediately and tell the team so they can check for any further impact.
-
Share a short checklist, run regular phishing simulations that use lookalike domains and shortened links, and give employees a one-click way to report. Track the report rate and the time to report to measure progress.
Train your team to check every link
Turn this checklist into a daily reflex. Arsen runs realistic phishing simulations with lookalike domains, shortened links and QR codes, then shows you how many employees report them. Explore the phishing simulation platform or evaluate your company with a phishing test.