Check links and attachments before you open them
Most phishing works through a link or a file, and both can be checked first.
Almost every phishing message asks you to click a link or open a file. You can inspect both before you touch them.
Links
- On a computer, hold the mouse over the link without clicking. The real address appears at the bottom of the window.
- On a phone, press and hold the link to preview the address.
- Find the first single slash in the address. The last part of the name just before it is the real owner. In login.microsoftonline.com/signin, the owner is microsoftonline.com. In microsoft.com.secure-check.net/signin, the owner is secure-check.net.
- Be careful with shortened links and QR codes, because you cannot see where they go.
Try it. Which of these addresses really belongs to Microsoft?
Attachments
- Be careful with any file you did not expect, even from someone you know.
- Web page files ending in .html or .htm, zip files and programs ending in .exe are common in scams.
- An invoice, voicemail or shared document that makes you sign in or enable content to see it is a warning sign.
Good to know
If you are unsure, do not open it. Go to the website yourself by typing its address, or ask the sender by phone.