How to recognise and safely handle a suspicious email link before clicking it
Summary
This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email link before clicking it. Follow the steps below to fix the issue.
Common Causes
Phishing emails remain one of the most common ways cyber criminals target Australian small businesses and home offices. A single careless click on a malicious link can lead to stolen credentials, compromised email accounts, or ransomware. Before you click any link in an email, taking a few seconds to verify it can save you hours of recovery work. This guide walks you through how to spot suspicious links, inspect them safely, and report anything that looks off to the 220 support team.
Common signs of a suspicious email link
Criminals often disguise malicious links to look legitimate. Watch for these red flags:
- The display text says one thing but the actual URL points somewhere else (for example, the link reads
https://www.mybank.com.aubut hovering revealshttp://my-bank-secure-login.xyz). - The domain looks slightly misspelt, such as
micros0ft.com,go0gle.com, or220internett.com. - The link uses an unfamiliar or shortened domain, such as
bit.ly/3xYzortinyurl.com/abc123. - The email creates urgency, like "Your account will be closed in 24 hours" or "Verify your password immediately".
- The sender address does not match the organisation they claim to represent.
- You were not expecting the email, or it relates to a service you do not use.
Quick fix steps
- Stop. Do not click the link yet.
- Hover your mouse over the link on a desktop, or long-press on a mobile device, to preview the actual URL.
- Compare the previewed URL against the expected destination. Look carefully at the domain name.
- If anything looks unusual, do not click. Report the email instead.
- If you have already clicked and entered credentials, change the password immediately and open a ticket with 220.
How to preview a link without clicking it
On Windows (Outlook desktop, browsers, and most apps)
- Move your mouse pointer over the link without clicking.
- A small tooltip or status bar at the bottom of the window will display the actual URL.
- Read the full address, paying close attention to the domain directly before the first forward slash.
On macOS
- Hover the pointer over the link.
- The destination URL appears in a tooltip, or in the status bar along the bottom of the window.
- You can also right-click the link and choose Copy Link, then paste it into a text editor like TextEdit to inspect it safely.
On iPhone or iPad (Mail app)
- Touch and hold the link until a menu appears.
- Tap Copy, then paste it into the Notes app to view the full URL.
On Android (Gmail app)
- Touch and hold the link until a preview pop-up appears showing the destination URL.
- If no preview appears, tap the three-dot menu on the email and choose Show original to inspect the underlying links.
In Gmail on the web
- Hover over the link with your mouse.
- A small box will appear showing the actual URL.
- You can also click the three-dot menu at the top of the email and choose Show original to view all embedded links.
In Outlook on the web or new Outlook for Windows
- Hover over the link to reveal the destination URL in a tooltip.
- For a deeper inspection, open the message, click the three-dot menu, and choose View then View message source.
How to verify a link safely
Once you have the actual URL, use these checks before deciding to click:
- Read the domain from right to left. The true owner is the domain immediately before the country code or extension. For example, in
login.microsoftonline.com, the owner ismicrosoftonline.com, notlogin. - Check that the connection is secure. Legitimate sites handling logins will use
https://and show a padlock icon in your browser. Note that HTTPS alone does not guarantee a site is safe. - Search the domain in Google. If it is a known phishing site, it is often already reported.
- Ask yourself whether the sender would reasonably need to send you this link. If unsure, contact the sender through a known channel, not by replying to the email.
https://www.virustotal.com). Paste the link into the URL tab and run the scan. Do not use these services to scan links that contain your username or password.How to report a suspicious email
- Do not delete the email. The 220 team may need it for investigation.
- In Outlook, select the message, click the Home tab, then choose Report Message and select Phishing.
- In Gmail on the web, open the message, click the three-dot menu next to the reply button, and choose Report phishing.
- In Apple Mail on macOS, select the message, click the Message menu in the menu bar, and choose Forward as Attachment to your IT contact.
- Forward the original email as an attachment to your 220 support contact, or open a ticket through the support portal and attach the message.
What to do if you have already clicked the link
- Disconnect from the network if you entered credentials or downloaded a file. You can turn off Wi-Fi or unplug the network cable.
- Change the password for the affected account immediately, using a different device if possible.
- Turn on multi-factor authentication (MFA) if it is not already enabled.
- Run a full antivirus scan on the device.
- Check the account's recent activity or sign-in logs for unfamiliar sessions and sign them out.
- Notify the 220 support team by opening a ticket so we can review your environment and contain any further risk.
Preventing future phishing attempts
- Enable multi-factor authentication on all email, banking, and business-critical accounts.
- Use a reputable password manager. Password managers only auto-fill credentials on the exact domain they were saved for, which helps detect fake login pages.
- Keep your operating system, browser, and email client up to date so the latest phishing protections are active.
- Use the built-in phishing filter in Outlook or Gmail, and avoid disabling browser security warnings.
- Train your staff to recognise the signs covered in this article and to report anything suspicious quickly.
Still Having Issues?
💻 Open a Ticket