BRYME TECH
SEPTEMBER 2026 · THE TOOL DESKPractical technology. No theatre.
THE BRYME

Practical guide · verified against the real thing

How to spot a suspicious link before you tap it

In one line: The checklist that catches most phishing links in ten seconds — and what to do if you already tapped.

Phishing links do not look dangerous — that is the entire point. They look like your bank, your delivery company, your boss. What gives them away is not the words around them but the address itself, and ten seconds of checking catches most of them.

The ten-second check

On a computer, rest your pointer on the link and read the address that appears at the corner of the browser — the real destination, not the underlined words. On a phone, press and hold the link until a preview pops up. Then read the domain from right to left: the part immediately before the first single slash is the only part that matters. secure.bryme.example.com belongs to example.com. bryme.example.secure-login.ru does not belong to anyone you trust.

The patterns that repeat

Lookalike spellings — rn for m, 0 for o, a dot slipped into a famous name. Rushed domains — a real bank does not register netflix-billing-alert.xyz this morning. Emotion before thought — the message needs you to act now, worry later; urgent language is the product. And the wrong channel: your parcel company does not text you a payment link for a fee you never owed.

Shorteners and buttons

A shortened link (bit.ly and friends) hides its destination by design. That is legitimate in a presentation and suspicious in a payment text. Do not visit to find out — most shortener sites offer a preview mode by adding a plus sign to the address, and messaging apps increasingly show destination previews on long-press.

If you already tapped

Tapping alone rarely causes harm; the damage starts when you type. If you entered a password on a fake page, change it on the real site now, and anywhere you reused it — which is exactly why the password-manager habit matters. If you entered card details, call the bank. If nothing was typed, close the page and move on; drive-by phone attacks at consumer scale are rare and target specific flaws, but keep the phone updated anyway.

The habit that beats the checklist

Go to sites, do not arrive at them. For anything involving money or logins, open the app or type the address yourself — the message can be a notification, never the front door. For assistants that summarise or rewrite text, our data-training settings guide covers a different leak: what your pasted text teaches the model.

Sources

Next

Related on this desk.