Recognising A Phishing Link
Launch library · evergreen read

Phishing links rely on close resemblance rather than exact matching, using a domain name that looks right at a casual glance, an extra word, a swapped letter, an unfamiliar ending, while the linked page itself is often a convincing copy of a genuine login screen someone recognises instantly, right down to matching colours, logos and layout copied carefully from the original.
Hovering over a link before clicking, or checking the actual address carefully once a page has loaded, is the single most reliable habit here, since the visible link text can say anything at all regardless of where it actually leads once clicked. Genuine organisations rarely need to ask for login details through a link sent in a message.
When a link seems even slightly off in any way, the safer route is typing the known address directly into a browser rather than clicking through blindly, sidestepping the impersonation entirely while still reaching the genuine service safely on its own established terms, without any need to trust the questionable link at all.