Phishing is the most common entry point for account takeover and fraud, and the link is the bait. Attackers register lookalike domains and disguise destinations to harvest credentials.
Red flags
- Typosquatting โ
paypa1.com,g00gle.com, or extra words likesecure-login-bank.com. - Homograph attacks โ letters from other alphabets that look identical to Latin characters.
- Mismatched display text โ the visible text says one thing, the actual
hrefpoints elsewhere. - Urgency and threats โ "your account will be closed in 24 hours."
- Newly registered domains impersonating established brands.
Check before you click
Hover to reveal the true destination, inspect the domain carefully, and when in doubt navigate to the site directly rather than via the link. You can also run the link through our URL checker, which examines domain age, redirects, TLS and reputation across multiple blocklists โ without you having to visit it.