Seven Things to Check Before You Click Any Link in Any Email

Seven Things to Check Before You Click Any Link in Any Email

Phishing emails no longer rely on obvious spelling mistakes or clumsy formatting. CISA warns that suspicious messages are probably phishing, and advises you not to click links or call numbers inside the message; Microsoft also notes that phishing can look legitimate while using spoofed sender addresses, and the FBI says scammers often use slight variations in email addresses and URLs to fool people.

Seven Things to Check Before You Click

1) Check the sender domain, not the display name
A message can show a trusted name while the actual address comes from somewhere else. The FBI specifically warns that scammers rely on slight differences in email addresses to fool victims, so the real test is the full address after the @ sign, not the name shown in your inbox.

2) Inspect the link destination before you click
Hover over the link on desktop, or press and hold on mobile, and read the actual destination domain. CISA and the FBI both recommend checking the URL carefully because phishing links often point to spoofed destinations that look convincing at first glance.

3) Treat urgency as a warning sign
Messages that demand immediate action, threaten suspension, or pressure you to “act now” are classic phishing patterns. CISA says urgent or alarming messages should make you pause, and Microsoft says phishing emails are designed to appear legitimate while still trying to steal information or money.

4) Ask whether the request matches normal process-
A real IT, finance, or support team usually follows a known process instead of pushing you to click a random link. The FBI notes that business email compromise messages often appear to come from a known source and make a legitimate request, which is exactly why they are so effective.

5) Watch for password, MFA, or verification-code requests-
If an email asks you to type your current password into a form, approve a login you did not start, or share a one-time code, stop immediately. Microsoft says it will never ask for your password in email, and the FBI says companies generally do not contact you to ask for your username or password.

6) Be suspicious of unexpected attachments and login pages
Phishing is not just about stealing credentials; CISA says criminals use harmful links, emails, and attachments to obtain information or infect devices. If you were not expecting a document, invoice, delivery notice, or account-warning page, verify it through another channel before opening anything.

7) Verify through a separate, trusted channel
Do not use the phone number, reply address, or link inside the suspicious email to verify the request. CISA advises that if a message could be real, you should not click any link or call any number in it, and the FBI recommends looking up the company’s number yourself and calling directly.

The 15-second rule

Before you click, ask yourself three questions: Who sent this? Where does the link really go? Does this request match normal business process? If any answer feels off, do not click. Open the company’s official website yourself, sign in from a bookmark you trust, or contact the organization through a known number.

Bottom line

The old advice of “look for bad spelling” is no longer enough. Modern phishing can look polished, personal, and professionally written, which is why the safest habit is to slow down, inspect the sender, inspect the destination, and verify every urgent request outside the email itself.

Leave a Reply

Your email address will not be published.