URLs · PHISHING · WEB BROWSING
How to check a website before clicking: a complete guide
Knowing how to check a website helps before entering credentials, making a payment or downloading a file. Banking, government and business pages can be convincingly imitated.
Appearance alone is not enough: consider the address, context and technical signals together. These steps help assess a link without treating a reassuring clue as a guarantee.
1. Inspect the URL
Before opening a link, inspect its full address in your email app’s preview or copy it without opening it. Compare the domain with a known reference address. A genuine site can also be compromised: its name alone cannot guarantee safety.
Spot typosquatting
Look for a replaced letter, an extra hyphen or similar-looking characters. Fictional example: “examp1e.com” uses the digit 1 instead of the letter l in “example.com”. A reassuring prefix such as “secure” proves nothing.
Separate the domain from subdomains
In “connexion.microsoft.365-secure-login.example”, “connexion” and “microsoft” are subdomains: the illustrative domain is “365-secure-login.example”, not Microsoft’s domain. First identify the hostname after “https://”, then the registered domain. Suffixes can contain several parts, such as “co.uk”: taking the last two labels does not always work.
Inspect shortened links
A shortener hides the initial destination. Have the link and its redirects checked before opening it. Revealing a destination does not automatically make it trustworthy, and it may vary with context.
2. HTTPS protects the connection, not the site’s honesty
HTTPS encrypts data in transit between browser and server and helps protect its integrity. It does not certify the operator’s intentions. A phishing site can obtain a valid certificate and use HTTPS.
A secure-connection indicator is therefore not enough. Conversely, do not bypass a certificate warning or submit sensitive data over an unprotected connection.
3. Use a website scanner and URL checker
A website checker helps combine clues that are difficult to review manually. Depending on the module and available sources, an online website scan can provide evidence about:
Domain reputation
Is the domain or URL flagged by the threat sources consulted? No report does not prove a site is safe, particularly when it is new.
Age and context
Recent registration is a clue to consider alongside the claimed identity and purpose, when registration data is available. It is not proof of fraud or a verdict on its own.
Redirects and technical signals
Review destination changes, lookalike domains and observable inconsistencies. Shared hosting, a CDN or private registration details are not enough to classify a site as malicious.
Do not submit links containing passwords, sign-in tokens or confidential information. Analysis time varies and no scanner covers every threat.
4. What to do when in doubt
Stop interacting with the page
Do not enter data, approve requests or download documents. Close the tab if you have already opened it.
Find an official channel
Use a trusted bookmark, your internal directory or an official address you already use. Do not rely on links or phone numbers supplied by the suspicious message.
Report your concern to IT
Share the address and context through your reporting channel without encouraging colleagues to open the link. IT can assess the threat and decide on appropriate blocking measures.
Already entered a password or downloaded a file? Alert IT and use the “I clicked” response guide to choose next steps for your situation.
I clicked: what should I do?Make checking links a daily habit.
Automated analysis helps you pause when faced with an urgent request and make a better-informed decision. It reduces some uncertainty without eliminating all risk.
Check a suspicious URLUsing your account’s free credits, within the available allowance.
Pilot terms and pricing are agreed before it starts.