Lesson 3 of 7, about 3 minutes

Check links and attachments before you open them

Most phishing works through a link or a file, and both can be checked first.

Almost every phishing message asks you to click a link or open a file. You can inspect both before you touch them.

Links

  • On a computer, hold the mouse over the link without clicking. The real address appears at the bottom of the window.
  • On a phone, press and hold the link to preview the address.
  • Find the first single slash in the address. The last part of the name just before it is the real owner. In login.microsoftonline.com/signin, the owner is microsoftonline.com. In microsoft.com.secure-check.net/signin, the owner is secure-check.net.
  • Be careful with shortened links and QR codes, because you cannot see where they go.

Try it. Which of these addresses really belongs to Microsoft?

Attachments

  • Be careful with any file you did not expect, even from someone you know.
  • Web page files ending in .html or .htm, zip files and programs ending in .exe are common in scams.
  • An invoice, voicemail or shared document that makes you sign in or enable content to see it is a warning sign.
Good to know

If you are unsure, do not open it. Go to the website yourself by typing its address, or ask the sender by phone.