Inspect the message, reveal the true destination and use layered defensive checks before deciding whether to visit.
Pause before opening the address
A suspicious link is safest while it remains unclicked. Do not paste it into a normal browser tab, sign in through it or forward it to someone else for a second opinion. Copy the address as text only if that can be done without opening it.
Check the destination, not the display text
Look for misspelled brand names, unexpected subdomains, encoded paths, shortened links and a mismatch between the message and the destination. HTTPS only means the connection can be encrypted; it does not prove the operator is trustworthy.
Use more than one signal
URL Radar checks reputation, redirects, page content, infrastructure, scripts and selected isolated-browser behaviour. Treat its result as evidence, not a guarantee. A new or highly targeted page may have little public reputation history.
Verify through a trusted route
If the message claims to be from a bank, delivery company, employer or cloud service, open the organisation’s known app or type its official address yourself. Contact the sender through a channel you already trust.
If you already clicked
Close the page. If you entered a password, change it from a clean device and review active sessions. If you entered payment details, contact the payment provider. If you ran a command or downloaded a file, disconnect the device from sensitive networks and ask security staff for help.
Further reading: CISA phishing guidance.