Phishing Defence

How to avoid phishing: read a link like a security engineer

Phishing is 90% of successful account takeovers. Learn the four checks a security engineer runs on every suspicious link — and the safe replacements for the risky habits.

ScoreReview UK Newsroom Published 20 March 2026 10 min read Safety
How to avoid phishing: read a link like a security engineer
Safety — ScoreReview UK Newsroom
Discuss

Phishing does not require sophistication; it requires haste. Every successful phishing attack exploits a moment where the target scans a link instead of reading it. This guide walks through the exact four checks a security engineer performs before clicking any unexpected link, the browser and account settings that stop the majority of attacks, and the recovery playbook if you already clicked.

Check 1 — Read the domain right-to-left

The real domain is the last two labels before the first single slash. In https://accounts.google.com.security-alert.co/login the real domain is security-alert.co — not google.com. Attackers stack subdomains to hide the true destination. Always read right to left, starting at the first slash.

  • Ignore everything before the last two labels
  • Watch for hyphens joining brand names (paypal-secure.com)
  • Watch for country-code lookalikes (.co, .cm, .co.uk)
  • Watch for Cyrillic and Greek homoglyphs (аpple.com)

Check 2 — Hover before you click

On desktop, hover reveals the real URL in the browser status bar. On mobile, long-press to preview. If the visible text says 'gov.uk' but the preview shows anything else, do not tap. HTML links can display any text over any target — the text is a suggestion, not a fact.

Check 3 — Match the sender to the ask

Legitimate senders match the ask to the channel. Your bank will not email you a login link. HMRC will not text you a refund link. Netflix will not text you about a suspended payment. When the channel and the ask do not match the sender's normal behaviour, treat the message as hostile until proven otherwise.

Check 4 — Refuse the urgency

Every phishing message manufactures urgency: 'account will be closed', 'parcel returned', 'fine doubles today'. Urgency is the payload, not a side effect. If a message would not be urgent from a stranger, it is not urgent from anyone. Close the message, open the real app, check the real account status.

The three settings that stop most phishing

Turn on multi-factor authentication with an authenticator app (not SMS) on email, banking and social accounts. Install a browser password manager that only auto-fills on the real domain — if it does not offer to fill, you are not on the real site. Enable phishing and malware protection in your browser settings.

What to do if you already clicked

Change the password on the affected account first, from a different device if possible. Sign out all other sessions in the account's security page. Enable MFA immediately if not already on. Watch the account for 30 days and report any unrecognised activity. If banking details were entered, call your bank on the number from your card.

Business-targeted phishing (spear-phishing)

Attackers scrape LinkedIn, invoices and press releases to craft messages that name a real colleague and a real project. Verify any payment-detail change out-of-band — call the person on their known number, do not reply to the email. A verification call costs one minute; a redirected supplier payment costs an average of £64,000.

Reporting phishing usefully

Forward suspicious emails to report@phishing.gov.uk (UK). Forward suspicious texts to 7726 (free). Report scam websites to the National Cyber Security Centre. Each report feeds threat-intelligence feeds that browsers and email providers use to block the same attack on other targets.

FAQ

Are password managers safe to use?

Yes — the leading managers have not been breached in ways that exposed user vaults, and the phishing-resistance benefit (only autofilling on the real domain) outweighs the theoretical risk. Enable MFA on the manager itself.

Is SMS multi-factor authentication good enough?

It is far better than none, but SIM-swap attacks defeat it. Move critical accounts (email, banking, primary social) to an authenticator app or hardware key. Keep SMS as a fallback.

Keep reading

Trending#DMCC#CMA#compliance#UK law#moderation#GDPR#data protection#retention#AI#reply automation#brand voice#sentiment#analytics#hospitality

Discussion (2)

Comments are stored locally on your device for this demo. Be respectful — no spam, no personal attacks.

  • Priya S.· 2 days ago

    Really practical breakdown — the four-part reply structure is now on our till-side crib sheet. Thank you.

  • Dan (Cannock Plumbing)· 5 days ago

    Went from 12 reviews to 47 in three months following almost exactly this playbook. It works.