BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 27 July 2026

Suspicious link in an email: how to check it in one minute

Suspicious link in an email? These five quick checks tell you within a minute whether it's safe to click — no need to call IT.

You get an email from a supplier, customer, or colleague with a link in it. Most of the time that's fine. Sometimes it's phishing. And increasingly, that malicious link is hidden behind a neat button or a shortened URL like bit.ly/xyz. How do you check a link quickly, without immediately calling IT?

Here's a practical five-step approach. Works on your phone and your laptop, and you don't need to install anything.

1. Don't click — hover first

On a laptop or desktop: hold your mouse over the link without clicking. In the bottom-left corner of your screen (or next to your cursor) you can see where the link actually leads. A button might say "View invoice", but the underlying URL could be something else entirely.

On your phone it works slightly differently: press and hold the link (don't tap). A preview will appear showing the full URL. See something odd? Close the preview and delete the email.

What to look out for

  • The domain directly before the first single slash. In https://invoices.client.nl.secure-portal.ru/login, the domain is secure-portal.ru, not client.nl.
  • Unusual country codes that don't match the sender (.ru, .top, .xyz, .zip).
  • Small typos: rnicrosoft.com instead of microsoft.com, or ing-secure.nl instead of ing.nl.

2. Expand shortened links

Links starting with bit.ly, tinyurl.com, t.co, or ow.ly hide their final destination. That's not automatically suspicious — marketing emails and social posts use them too. But in a business email about an invoice or login, a shortened link is a reason to be extra careful.

Want to see where a link leads without clicking it? Paste it into an unshortener such as unshorten.it or checkshorturl.com. You'll see the real destination and can judge whether it makes sense.

3. Check the IP address and domain owner

If you're unsure about a domain — for example invoices-portal-online.nl that you've never seen before — you can find out in thirty seconds which server it's running on and whether that fits a legitimate business. A real Dutch supplier doesn't suddenly host from an obscure server somewhere abroad.

With our IP lookup tool, paste the domain and instantly see which provider and country the server is in. Especially combined with the other signals, that gives a good indication.

4. Go to the website yourself — not via the email

This is the simplest and best trick: if an email tells you to log in to your bank, accounting package, KPN account, or parcel carrier, do not click the link. Open a new tab and type the address yourself. Or use the bookmark you already have.

If there really is a message waiting for you, you'll see it after logging in through your own account. Nothing there? Then the email was probably fake.

5. Not sure? Call or message the sender on a known number

A link that appears to come from a customer or supplier, but something feels off? Don't use the phone number in the email — that could be fake too. Use the number from your own contacts, from their website, or from a previous invoice. One short phone call can sometimes save thousands of euros in damages or a lost afternoon with a locked account.

What if you already clicked?

Stay calm. Clicking a link is not the same as being infected. It only becomes a real problem if you:

  1. then entered your login credentials on the fake page, or
  2. downloaded and opened a file.

In the first case: change the password for that account immediately (via the real site) and enable two-factor authentication if you hadn't already. In the second case: disconnect your laptop from the network and get someone with the right expertise to take a look.

Prevention is easier than clean-up

Most phishing emails are now so convincingly made that you can no longer spot them by typos alone. What does help:

  • Proper email security on the sending side, so that criminals can't simply send emails in your name to customers. That means SPF, DKIM, and DMARC.
  • Two-factor authentication on everything that matters: email, banking, accounting software, cloud storage. Even if someone does get hold of your password, they still won't be able to get in.
  • Clear office agreements: when in doubt, always check with someone, and never process an urgent payment based on an email alone.

Need help getting the basics right?

Want to make sure your email security (SPF, DKIM, DMARC) is properly configured, so scammers can't send emails in your name? Check out our email security service. And to quickly check a suspicious domain: IP lookup is free to use.

Onderwerpen

#phishing #Mkb Security #Mailbeveiliging #Veilig Werken #Verkorte Links

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →