Security guides

How to Identify a Phishing Link

Check hostnames, message context, login forms and redirects for signs that a link is impersonating a trusted organisation.

The strongest phishing judgement comes from combining destination, message context, page behaviour and independent verification.

Start with the hostname

Read from right to left around the registered domain. A brand name placed in a subdomain or path does not make that company the owner. Watch for substituted characters, extra words, unfamiliar country domains and link shorteners.

Compare the request with normal behaviour

Unexpected password resets, invoices, shared documents and urgent account warnings are common lures. Be cautious when the message creates pressure, asks for a one-time code or sends you to a login page you did not request.

Inspect the page signals

Do not rely on appearance alone

Logos and polished layouts are easy to copy. Certificate padlocks and valid TLS are also available to attackers. Verify the request by navigating independently to the organisation’s official site or app.

Further reading: CISA phishing guidance.

Continue learning

Explore the detection catalogue.

Browse detectionsCheck a link