Link Safety Checklist: 60 Seconds to Spot a Risky Email Link

A practical checklist you can use in under a minute to verify suspicious email links before clicking them.

Online Privacy & Link Safety~4 min readAugust 13, 2026By qz-l editorial team
#link safety#phishing#email safety#cybersecurity#checklist
Looking for related guides? Start with the qz-l Learning Center and explore more tutorials in this topic cluster.

Link Safety Checklist: 60 Seconds to Spot a Risky Email Link

A suspicious email usually does not look suspicious at first glance. It looks urgent, familiar, and useful. That is exactly why a fast checklist helps.

Use this guide whenever an email asks you to click a link, confirm a payment, verify an account, or open a document. You can run the whole check in about 60 seconds.

The 60-second checklist

1. Pause before you click

If the email creates urgency, stop for a moment. Scammers rely on fast reactions. A few extra seconds can prevent a costly mistake.

Ask yourself:

  • Did I expect this email?
  • Does the request make sense?
  • Is the sender asking me to act immediately?

If the message pushes urgency, treat it as higher risk.

2. Check the sender address, not just the name

The display name can be copied. The actual email address is harder to fake convincingly.

Look for:

  • odd domains
  • extra characters
  • strange spelling
  • a different reply-to address

If the sender domain does not match the real service, do not trust the message.

3. Inspect the real link destination

The button text is not the URL. A button can say "Continue" or "Withdraw" while hiding a completely different destination.

Before opening:

  • hover over the link on desktop
  • long-press the link on mobile
  • read the full destination domain

If the destination domain looks unrelated, stop.

4. Compare the domain with the official site

A real company email should send you to its real domain or to a clearly expected trusted subdomain.

Watch for:

  • random letters or numbers in the domain
  • unrelated top-level domains
  • misspellings of a brand name
  • domains that imitate a known company

Design can be copied. Domain ownership matters more.

5. Ask whether the request belongs in email at all

Some actions do not belong in an email link:

  • entering a password
  • entering a one-time code
  • confirming bank details
  • withdrawing money
  • approving a payment you did not initiate

If the request feels unusual, verify through the official app or website instead.

6. Open the official app or site manually

Do not use the email link to confirm the message. Open the service directly by typing the address yourself or using the app.

Then check:

  • account notifications
  • transaction history
  • message inbox
  • order status

If the email is real, you will see the same activity inside the official account.

Red flags that should slow you down

Treat the email as suspicious if it includes any of these:

  • an unfamiliar sender address
  • grammar that feels slightly off
  • a deadline or countdown
  • a payment or refund that seems too fast
  • an instruction to "act now"
  • a login page that does not match the official domain
  • a request for sensitive data through a link

One red flag may be enough to justify checking again. Multiple red flags mean you should stop.

What to do if the email looks fake

If you suspect the email is malicious:

  1. Do not click the link.
  2. Do not reply to the sender.
  3. Mark the message as phishing or spam.
  4. Delete it if you no longer need it.
  5. If the message claims to be from a real service, contact that service through its official website.

What to do if you already clicked

If you clicked the link but did not enter anything:

  • close the page
  • do not download files
  • do not continue browsing the fake site

If you entered a password or code:

  • change your password immediately
  • enable two-factor authentication
  • sign out of other sessions
  • review recovery options

If you entered card or bank information:

  • contact your bank or card provider
  • monitor activity closely
  • replace the card if necessary
  • report the scam to the impersonated service

A simple rule to remember

If a message involves money, access, or urgency, do not trust the first click.

Pause. Check the sender. Check the domain. Verify in the official app or site. Then decide.

Why this habit matters

Most phishing attacks succeed because the user is rushed. A short checklist changes the default behavior. It turns a reflex into a decision.

That is enough to block many scams before they become real problems.

Final reminder

You do not need to become a security expert to stay safer. You only need one repeatable habit:

Think before every link, especially when the email tries to rush you.

Related reading

Related Posts

How to Spot a Fraud Email Link Before You Click

A practical guide to identifying phishing emails, suspicious links, and fake payment pages before they can steal your money or account access.

Stop, Check, Verify: The Simplest Rule for Clicking Links Safely

A short closing guide that ties together the safest habit for handling email links, suspicious pages, and urgent messages.

Kijiji Scam Alert: A Fake Payment Email with a Fraud Link

A real phishing attempt after posting a Kijiji ad, how the fake page looked convincing, and a practical checklist to avoid scam links.