5 min read · 1 small stepSkip to today’s step →

Type the address in yourself

A message says your account is locked? Skip the link. Open the app or type the address yourself: if the problem is real, it shows there too.

Built from people talking about opening links in emails, texts and QR codes, including a long argument over whether a click alone can harm your phone, and checked against current UK and US anti-phishing guidance. An argument about one video app's privacy that ran alongside is not part of it.

The message says there has been an unusual sign-in. Or a payment failed. Or your account will be closed in 24 hours, or a parcel is waiting. There is a button, and pressing it looks like the fastest way to make the worry stop.

When a message asks you to log in, pay, or check your account, do not use its link: open the app or type the website’s address yourself, and if something is really wrong, you will see it there too.

Some people give that rule, and it has an advantage over every other check: you do not have to work out whether the message is real. If it is real, the warning will be waiting when you log in your own way. If it is fake, you never went near the fake. Some people meet the obvious objection, that real companies do send real security alerts, with the same answer: even then, the safe response is to go to the site directly. Both the US Federal Trade Commission and the UK’s National Cyber Security Centre say the same thing in their own words: contact the company through a website or number you already know is real, not the details in the message.

The reason is what sits behind the link. One person puts the main risk plainly: not a virus, but a copy of the real login page, built to collect your password or card number. The copy can look exact. The words of a link can say one address and lead to another, one person warns, and another points out that real companies often send their emails from other companies’ addresses, so the sender line cannot settle it either. The National Cyber Security Centre lists the pressure these messages use: authority, urgency, emotion, something scarce, something in the news. One person’s default is to treat any message that demands urgent action as a scam until checked another way.

Hovering over a link, or pressing and holding it on a phone to see where it goes, is worth doing, and some people do it. It can show you a link is fake. It cannot prove a link is real, because look-alike addresses can pass a quick look, and some people argue exactly this; the decider they give is how much is at stake. So use it as a warning light and still go in your own way for anything that involves a password or money. One person adds a quiet tell worth knowing: if your password manager, or your phone’s saved passwords, does not offer to fill in your login, the page may be a fake. Another explains why: those tools only fill in on the real address.

The honest version about clicking

People argue about whether just opening a link or scanning a QR code can infect your phone. Here is where it comes out. Some people point out that on a current phone, opening a page does not usually install anything by itself: harm needs a rare flaw in the phone or browser, or needs you to download something, grant a permission, or type in your details. A fourth correction, also settled, keeps that honest: flaws that need no click at all do exist, and have been used to put spyware on people’s phones. And some people point out that browser flaws have, in the past, let a page do harm just by loading. Where people argue the two out, one side says such flaws are too rare and valuable to scatter through random codes and are kept for chosen targets; the other answers that their existence is reason enough for caution. The decider they give is who you are: for an ordinary person, the first side’s argument holds and the realistic danger is the fake page; for someone who is a chosen target, the second side’s does. The Federal Trade Commission’s warning covers both sides: a bad QR code can lead to a fake site that steals your login, or to malware.

What keeps you on the safe side of that line costs little. Keep your phone updated, which is the Commission’s advice and one person’s too. If your phone is too old to get updates any more, the reassurance above is weaker for you; what to do about that is not covered here. Do not tap “Allow” on anything a page you reached from a link asks for, and do not switch off your phone’s security settings, which one person warns raises the risk a great deal. For QR codes, one person notes that phone cameras now show the address before you open it, so read it first; the Commission warns that scammers stick their own codes over real ones on parking meters, and says not to scan a code in an email or text you were not expecting. One person adds that even a code that led somewhere safe yesterday can be pointed somewhere else today.

Who this is not enough for

If you get messages like these at work, your employer’s rule comes first. Some people say companies send fake phishing emails to test their staff, and one person was marked down by their IT department for opening a test link even after checking it, so if work says report and do not click, do that. And if you have reason to think someone may target you personally — because of your work, your politics or your public profile — the reassurance above about clicks is not written for you; people say plainly that the deciding question is whether you are a chosen target, and for you it may be yes. In the UK, the National Cyber Security Centre publishes guidance for high-risk individuals — people in political life, journalism, academia and the law — on protecting their accounts and devices.

Common questions

But some links I have to click. What about those?

There is one honest exception, and one person states it: some ordinary jobs, like a password reset or confirming a new account, only work through the link the site emails you. Some people made the same objection, and others here add that the risk is lower when you started the action yourself. So the rule is about who asked. A reset link you requested a minute ago, from the site you were just on, is expected. Some people put it simply: click a password reset only if you asked for it, and a confirmation email is safer if you have just signed up. Even then, look at the address in the browser before you type anything. And one person turns the exception into a warning sign: a real company does not send you a password reset out of nowhere, so one you did not ask for is a scam or a mistake. Leave the link alone; if you are worried, check the account through the app or a bookmark.

Can I paste a suspicious link into one of those link-checking sites?

You can, and people argue about it. One side uses them as a sensible check for a link you really need to open. Some people say the catch is that a scam link can carry a code unique to you, so checking the full link can tell the sender your address is live and opened; one person adds that some checking sites pass on details about your computer, and others say no checker catches everything. People's own decider leans one way: unless you truly need the link, avoiding it is safer. This page's version: if you do not need the link, you do not need to check it. If you do need to reach that account, go in through the app or a bookmark and the link never matters.

I already clicked, or typed my password. What now?

What to do next is not covered here; the agencies answer it. The UK's National Cyber Security Centre says: if you gave out a password, change it on every account that uses the same one; if you gave banking details, tell your bank; and if you lost money, tell your bank and report it to Report Fraud on 0300 123 2040 in England, Wales and Northern Ireland, or to Police Scotland on 101. In the United States, the Federal Trade Commission points to IdentityTheft.gov for the steps that match what you gave away, and says to update your security software and run a full scan. The page on this site about checking your email against the breach list goes through changing reused passwords and adding a second step to your login. The same rule covers calls, one person adds: never give details to a caller who rang you; hang up and ring back on a number you already know. To report the message itself: in the US, forward phishing emails to reportphishing@apwg.org and texts to 7726; in the UK, forward emails to report@phishing.gov.uk and texts to 7726; elsewhere, your national fraud or cyber-security agency.

Questions this step helps with

Same situation, another step

a quiet placeSit for a minuteA meadow, a river, and nothing you have to do. The field is always open — and the wind on this page already knows the way.

Drawn from the real, shared experience of thousands of people. Shared experience, not professional advice.

Heavy moment? Call or text 988 — or we’re here.

Close