Clear, practical technology insights
Recognize Phishing and ScamsLesson 5 of 15

Inspect links and files safely

A link can display one address while opening another, and a file can use an innocent-looking name while carrying executable content. Safe inspection happens before the click or launch. You do not need to prove that an item is malicious; you only need enough evidence to choose a safer path, such as opening the known website independently, asking the sender through another channel or deleting the file. This lesson focuses on low-risk checks that do not upload sensitive documents to public scanning services.

10 min Beginner Recognize Phishing and ScamsReviewed 2026-07-30 00:00:00
Learning objectives

What you will learn

  • Reveal a link destination without opening it.
  • Read the registrable domain and detect lookalike names.
  • Check file type and extension before execution.
  • Respond safely to browser and antivirus warnings.
Before you start

What you need

  • A desktop browser or mail client for a harmless test.
  • File-name extensions enabled when inspecting downloads.

Read the real destination

Google Chrome warns about phishing, malware and social-engineering sites and recommends not visiting pages marked dangerous.

Chrome also notes that a secure connection protects data in transit but does not prove that the site itself is trustworthy; users must still verify the site name.

Hovering can reveal the destination on desktop. On mobile, a long press may show a preview, but do not proceed if the interface gives no safe way to inspect. Read the domain from right to left: the important registered name appears immediately before the public suffix, while words added on the left are subdomains.

Safe inspection flow from displayed link to real domain, file type and trusted opening decision.
Inspect the destination and file type before the browser or operating system executes anything.

Compare the domain and path

Look for swapped letters, added words, unusual top-level domains, encoded characters and a trusted brand name placed only in a subdomain or URL path. Shortened links conceal the destination; do not expand them through an unknown public service when the original URL may contain private tokens.

  1. 1

    Reveal or copy the destination without opening it.

  2. 2

    Paste it into a plain local text editor, not the browser address bar.

  3. 3

    Identify the host name before the first slash.

  4. 4

    Read the host from right to left and locate the registered domain.

  5. 5

    Compare it with a known official domain from a bookmark or independent search.

Inspect files before execution

Enable file-name extensions so that invoice.pdf.exe is not mistaken for a PDF. Treat executables, scripts, macro-enabled documents, disk images and password-protected archives as higher risk. A familiar icon can be forged. If a business document is unexpected, verify the sender and purpose before opening it.

Do not upload confidential, medical, financial or work files to public malware scanners unless policy explicitly permits it. Hash-only reputation checks still need careful interpretation because a new malicious file may have no reputation.

  1. 1

    Save the file without opening it only when policy allows.

  2. 2

    Check the full name, extension and source.

  3. 3

    Review the browser download warning and Windows Security status.

  4. 4

    Verify the request through a trusted channel.

  5. 5

    Use the organization sandbox or security team for sensitive work files.

  6. 6

    Delete the file if its purpose cannot be verified.

Treat security warnings as evidence

Chrome may block dangerous downloads, and Microsoft Defender may quarantine or flag files. Attackers often instruct victims to disable protection, click “keep anyway” or add an exclusion. Do not follow those instructions. Quarantine is safer than Allow when you are uncertain.

  1. 1

    Stop when a full-page browser or antivirus warning appears.

  2. 2

    Capture the warning text without exposing sensitive data.

  3. 3

    Close the page or delete the download.

  4. 4

    Update the browser and security intelligence.

  5. 5

    Report the source if it came through email, chat or an advertisement.

Verification checklist
  • The official domain was verified independently.
  • The file extension and purpose are known.
  • No warning was bypassed merely to complete the task.
Hands-on practice

Inspect a harmless training link and file name

Use examples that do not point to live suspicious content.

  1. 1

    Compare a displayed label with a different sample destination.

  2. 2

    Mark the registered domain.

  3. 3

    Identify a double-extension file name.

  4. 4

    Write the trusted alternative route to the service.

  5. 5

    Record the action you would take if a warning appeared.

Common mistakes to avoid

  • Clicking first and inspecting after the page loads.
  • Assuming HTTPS proves legitimacy.
  • Uploading sensitive files to public scanners.
  • Overriding browser or antivirus warnings on an attacker instruction.
Lesson recap

Key takeaways

  • The destination and file type matter more than appearance.
  • You rarely need to prove malware before choosing not to open it.
  • Security warnings should change the plan, not be bypassed.

Frequently asked questions

Is hovering over a link completely safe?

It normally reveals the destination without navigation, but use a current client and avoid interactions when the interface is unfamiliar. A trusted independent route is still safer.

Can a PDF be dangerous?

Any complex file format can contain harmful content or exploit vulnerable software. Verify the source, keep readers updated and avoid unexpected files.

Evidence and updates

Sources and further reading

  1. Manage warnings about unsafe sitesGoogle Chrome Help
  2. Check if a site connection is secureGoogle Chrome Help
  3. Google Chrome blocks some downloadsGoogle Chrome Help
  4. Protection history in Windows SecurityMicrosoft Support
Finish this lesson

Ready to continue?

Mark the lesson complete so your Learning Path progress stays current on this device.