Suspicious Link Response Checklist: What to Do Before You Click
Unexpected links create pressure to act before thinking. This checklist turns that moment into a short verification process that protects accounts, payments and personal information.
Pause before interacting
Urgency is a common social-engineering tactic. A message may claim that an account will close, a package cannot be delivered or a payment is waiting. Do not use the link or QR code as the starting point for verification.
Instead, open the official app, type a known address or use a trusted bookmark. If the claim is real, it will usually be visible after you sign in through the normal route.
- Do not enter a password, verification code or card number after following an unexpected link.
- Do not download a file solely because a message says it is urgent.
- Keep the original message until you have completed the review.
Read the destination, not just the label
A link label can say one thing while the destination goes somewhere else. On a desktop browser, inspect the displayed address before opening it. On a phone, use the official service or ask a trusted person to help verify the exact domain.
Look for spelling changes, extra words, unusual subdomains and domains that do not match the organisation being claimed. A valid HTTPS padlock protects the connection; it does not confirm that the operator is legitimate.
Review public URL structure, redirects and technical context before choosing a safe next step.
Verify the request independently
Use contact details you already know, not phone numbers or reply addresses supplied in the message. For a bank, delivery company, employer or government service, use its official website or mobile application to check whether a request is genuine.
If the message claims to come from a colleague or supplier, use a separate known channel to confirm it. Do not reply directly to a suspicious thread asking whether it is real.
- Compare sender and reply-to addresses.
- Check whether the timing and request make sense.
- Ask the organisation to confirm through a known channel.
- Share work-related messages with the security or support team.
Treat technical signals as context
Domain age, HTTPS, DNS records, IP ownership and reputation sources can help build context. None of them gives a final answer on its own. Legitimate services can be new, and fraudulent services can use normal hosting, certificates and branding.
Use multiple signals with the actual behaviour of the message. A request for money, credentials, recovery codes or remote access deserves extra caution even if some technical signals look ordinary.
Review public domain and DNS context as one part of an independent verification process.
If you already clicked
Clicking a link does not automatically mean an account is compromised. The next action matters. If you entered a password, change it through the official site immediately, sign out other sessions where possible and enable multi-factor authentication. If you entered payment information, contact the card issuer using the number on the card.
Record the URL, time and screenshots if this is a work incident. Report it promptly so the organisation can protect other users and investigate related activity.
- Change exposed passwords from a trusted device.
- Review account recovery details and active sessions.
- Contact financial providers through known numbers if payment details were shared.
- Report the message and retain evidence.
Use this checklist as a starting point
- Pause and use a known official route instead of the unexpected link.
- Inspect the exact domain and verify the request independently.
- Use technical signals as supporting context, not proof.
- Act quickly if credentials or payment information were entered.
- Report suspicious work messages through the appropriate channel.