5 rules to help you identify phishing links before clicking.
Online scams are becoming increasingly sophisticated, especially with the help of AI. However, by following just five simple rules, you can avoid most malicious links.
The internet offers many conveniences in life, but it has also become a favorable environment for cybercriminals to carry out fraudulent activities. With just a cleverly disguised malicious link, attackers can steal passwords, personal information, bank account details, or install malware on victims' devices.

In the context of increasingly sophisticated scams aided by artificial intelligence (AI), vigilance against any unfamiliar links is more important than ever. However, most scams can still be prevented if users remain calm and perform a few simple checks before clicking.
Here are five principles you should follow whenever you receive a suspicious link.
1. Stay calm, don't let emotions get the better of you.
Most scams exploit the psychology of their victims rather than technological vulnerabilities.
Scammers often create messages that frighten or overexcite recipients, such as notifications of account suspension, data theft, urgent payment requests, or large prize winnings. These messages share a common characteristic: they always create a sense of urgency, compelling users to act immediately.
If you receive such an email or message, the first thing to do is stop and calmly consider it. Don't rush to click on any links when you're anxious or overly excited.
When you think clearly, you'll easily spot inconsistencies or unusual signs in the content that scammers intentionally create.
2. Carefully check the sender and email address.
One of the simplest yet most effective ways to detect phishing emails is to check the sender's address.
Many phishing emails use display names that resemble those of reputable banks, schools, government agencies, or businesses to build trust. However, the actual email address behind it is often a random string of characters or an unrelated domain name.
Even if the address contains the organization's name, users still need to be careful. Scammers often just change a few characters or add dots or hyphens to make it look like a real address.
If you've ever received official emails from that organization before, reopen the old emails to compare the sender's address. This is a quick way to spot any discrepancies.
3. Don't overlook spelling and grammar errors.
The content of emails or messages is also an important indicator of a scam.
Many fake messages contain spelling errors, awkward sentence structure, or unprofessional language. This is rare for organizations like banks, schools, or large businesses, as official announcements are usually thoroughly checked before being sent.

Today, AI generation can help malicious actors create more professional-looking emails, but they still have their own characteristics. Some content may be too rigid, robotic, or distinctly different from the organization's familiar communication style.
If the wording in the email seems different from notifications you've received before, consider it a warning sign.
4. Hover your mouse over the link to check its authenticity before clicking.
Even if an email seems trustworthy, you shouldn't rush to open any links that come with it.
On most computer browsers, simply hovering your mouse cursor over a link without clicking will show the actual URL in the bottom corner of the browser window.
If the link leads to the official website, the address will usually clearly display the organization's domain name. Conversely, if the URL is a long, confusing string of characters or contains misspelled words, it could be a sign of a fake website.
Checking URLs in this way is perfectly safe. The link only starts to pose a risk when you actually click on it and visit the website.
5. Verify with an acquaintance through another communication channel.
Many scams nowadays exploit the accounts of friends or relatives to spread malicious links.
If you receive an unusual message from an acquaintance with a strange link, don't immediately believe they're the sender.
Instead, try contacting them through a different method, such as calling, messaging via another app, or asking directly to verify.
If they confirm they didn't send that message, it's highly likely their account has been impersonated or compromised. Reporting it early not only helps you avoid becoming a victim but also allows your acquaintances to protect their accounts in time.
Online phishing tools are becoming increasingly sophisticated, especially as AI helps attackers create more convincing-looking emails and messages. However, the majority of attacks still rely on exploiting users' psychology and lack of vigilance.
By simply taking a few dozen seconds to calmly check the sender, content, link address, and verify information when necessary, you can avoid most online scams and protect your accounts and personal data.


