⚠️ TRAINING DEMO — Security Awareness Training Material

🚩 Suspicious Link Red Flags

Before clicking any link, check these warning signs. Click each item to mark it as understood.

0 / 10 items reviewed
1. The domain doesn't match the real site
Attackers register lookalike domains. Always check the FULL domain — not just the page title or logo.
linkedin-verify.com ≠ linkedin.com  |  paypa1.com ≠ paypal.com
2. The link came unsolicited via email, WhatsApp, or SMS
Legitimate companies rarely send urgent action links via messaging apps. Treat unsolicited links as suspicious by default.
3. The URL uses HTTP, not HTTPS
No padlock in the browser = no encryption. Any page asking for login credentials must use HTTPS.
http://bank-login.xyz ← never enter credentials here
4. The message creates urgency or fear
"Your account will be suspended in 24 hours" — this is manipulation. Urgency bypasses rational thinking. Pause and verify independently.
5. The page asks for more info than necessary
A job application asking for your full address, phone, and resume upfront before any interview is a red flag. Real processes are staged.
6. The page asks for location permission
Legitimate job sites, banks, and services do not need GPS access. Any page requesting geolocation without a clear reason is suspicious.
7. The sender's email domain doesn't match the company
Check the actual email address, not just the display name. "Amazon" can be the name, but the address reveals the truth.
From: Amazon <[email protected]> ← fake
8. There's no privacy policy or contact information
Legitimate sites collecting personal data are legally required to have a privacy policy. If it's missing, leave immediately.
9. Your password manager doesn't autofill
Password managers autofill based on the exact domain. If it doesn't offer to fill — you're not on the real site. This is one of the strongest signals.
10. You weren't expecting this message
If you didn't initiate the action (password reset, job application, prize), treat the link as suspicious. Verify by going directly to the site.
🎣 See a Phishing Page → 🔍 Browser Fingerprinting → ← Main Demo