Home › Knowledgebase › KB-482

How to recognise and safely handle a suspicious email link before clicking it

Summary

This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email link before clicking it. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Phishing emails remain one of the most common ways cyber criminals target Australian small businesses and home offices. A single careless click on a malicious link can lead to stolen credentials, compromised email accounts, or ransomware. Before you click any link in an email, taking a few seconds to verify it can save you hours of recovery work. This guide walks you through how to spot suspicious links, inspect them safely, and report anything that looks off to the 220 support team.

Common signs of a suspicious email link

Criminals often disguise malicious links to look legitimate. Watch for these red flags:

If a link asks you to log in to an account, never enter your password unless you are 100% certain the email is genuine. When in doubt, open a new browser tab and navigate to the service directly by typing the address yourself.

Quick fix steps

  1. Stop. Do not click the link yet.
  2. Hover your mouse over the link on a desktop, or long-press on a mobile device, to preview the actual URL.
  3. Compare the previewed URL against the expected destination. Look carefully at the domain name.
  4. If anything looks unusual, do not click. Report the email instead.
  5. If you have already clicked and entered credentials, change the password immediately and open a ticket with 220.

How to preview a link without clicking it

On Windows (Outlook desktop, browsers, and most apps)

  1. Move your mouse pointer over the link without clicking.
  2. A small tooltip or status bar at the bottom of the window will display the actual URL.
  3. Read the full address, paying close attention to the domain directly before the first forward slash.

On macOS

  1. Hover the pointer over the link.
  2. The destination URL appears in a tooltip, or in the status bar along the bottom of the window.
  3. You can also right-click the link and choose Copy Link, then paste it into a text editor like TextEdit to inspect it safely.

On iPhone or iPad (Mail app)

  1. Touch and hold the link until a menu appears.
  2. Tap Copy, then paste it into the Notes app to view the full URL.

On Android (Gmail app)

  1. Touch and hold the link until a preview pop-up appears showing the destination URL.
  2. If no preview appears, tap the three-dot menu on the email and choose Show original to inspect the underlying links.

In Gmail on the web

  1. Hover over the link with your mouse.
  2. A small box will appear showing the actual URL.
  3. You can also click the three-dot menu at the top of the email and choose Show original to view all embedded links.

In Outlook on the web or new Outlook for Windows

  1. Hover over the link to reveal the destination URL in a tooltip.
  2. For a deeper inspection, open the message, click the three-dot menu, and choose View then View message source.

How to verify a link safely

Once you have the actual URL, use these checks before deciding to click:

If you want a second opinion before clicking, you can submit the URL to a free scanning service such as VirusTotal (https://www.virustotal.com). Paste the link into the URL tab and run the scan. Do not use these services to scan links that contain your username or password.

How to report a suspicious email

  1. Do not delete the email. The 220 team may need it for investigation.
  2. In Outlook, select the message, click the Home tab, then choose Report Message and select Phishing.
  3. In Gmail on the web, open the message, click the three-dot menu next to the reply button, and choose Report phishing.
  4. In Apple Mail on macOS, select the message, click the Message menu in the menu bar, and choose Forward as Attachment to your IT contact.
  5. Forward the original email as an attachment to your 220 support contact, or open a ticket through the support portal and attach the message.
Never forward a suspicious email as an inline forward. Use the "Forward as Attachment" option so the original headers and hidden content are preserved for analysis.

What to do if you have already clicked the link

  1. Disconnect from the network if you entered credentials or downloaded a file. You can turn off Wi-Fi or unplug the network cable.
  2. Change the password for the affected account immediately, using a different device if possible.
  3. Turn on multi-factor authentication (MFA) if it is not already enabled.
  4. Run a full antivirus scan on the device.
  5. Check the account's recent activity or sign-in logs for unfamiliar sessions and sign them out.
  6. Notify the 220 support team by opening a ticket so we can review your environment and contain any further risk.

Preventing future phishing attempts

If you would like a refresher on securing your Windows login credentials after a phishing incident, see our guide on Password reset (Windows login).

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket