Would you click?
Same message. Different destination. Which would you trust?
9 rounds, a matching pair of messages each. Reveal where the links really go, then pick the one you’d tap.
Every link wears a costume
Every day you tap links in DMs, texts, emails and search results. Every one of them has two parts, and you only see one.
The bit you see — the blue text or a button — is only a label. That’s the costume. Whoever creates the link can make that label say whatever they want. It doesn’t have to match where the link actually goes.
The real address is hidden underneath, and that’s what decides where you end up.
PayPal’s website is paypal.com. Does the address underneath match?
Look under the costume
In this game, tapping a link reveals where it goes. Outside the game, tapping usually opens it — so here’s how to look first.
On a phone, press and hold the link instead of tapping it. Check the real web address that appears. If you can’t see the whole address, choose Copy Link or Copy link address, then paste it somewhere without opening it.
On a computer, hover over the link without clicking and look for the web address in the bottom-left corner of the browser.
Try it yourself. See where this practice link really goes without opening it. You should see bbc.co.uk.
Find the main domain
An address can be long, but only one bit decides whose site it is: the main domain — the name together with its ending, such as netflix.com or amazon.co.uk. To find it, read the address right-to-left. Take this one:
https://apple.com.ios-update.io/signin
- Skip https:// and stop at the first single /. That leaves apple.com.ios-update.io.
- Find the ending at the far right: .io. Some endings have two parts, like .co.uk. Keep those together: in amazon.co.uk the ending is .co.uk and the name is amazon.
- Keep going left until you hit the next full stop. The bit between the two full stops is the name: ios-update. Name plus ending is the main domain: ios-update.io.
Anything further left is decoration. Putting apple.com in front doesn’t make it Apple’s.
Your turn. What’s the main domain of https://music.youtube.com/playlist/bus-mix? Decide, then tap to check.
youtube.com. Stop at the first /, find the ending .com, go left to the next full stop. The music. in front is decoration here too — this time it’s just a section of YouTube’s own site.
Four ways to disguise it
Lookalike letters
A letter swapped for one that looks the same — rn for m, 1 for l, 0 for o. Hardest to spot on a small screen.
Fake subdomain
The real brand stuck in front of a different main domain, like the ios-update.io one above.
Hyphenated brand
An extra word bolted on by a hyphen. snap-chat.com is not snapchat.com, and “secure” in a name secures nothing.
Wrong ending
Right name, wrong ending — .watch or .vip where the site you know uses .com.
Look back at the PayPal link: paypa1-login.secure-id.ru. Which tricks was it using? Decide, then tap to check.
Two at once. Its main domain is secure-id.ru, which isn’t PayPal at all — the brand was just stuck in front. And that brand was spelt with a 1 where the l should be.
Same message, two links. Tap each one to reveal where it really goes, then tap the real one again to pick it. No score on this one.
Spotify’s main domain is spotify.com. Look for the address whose main domain matches exactly.
Taking the costume off only tells you where the link goes. A familiar address doesn’t mean the message — or the page itself — is trustworthy.
If you don’t recognise the real address, or the message asks for a password, payment or code, don’t tap the link. Open the app or type the website address in yourself.
The habit Check where a link really goes before you tap. If it wants a login, a payment or a code, skip the link and go direct.
Pick the real link