Pepelen
← Scam Defense: How to Keep Your Money

Lesson

Lesson 7. How to read a link in five seconds

Find the real domain in an address and tell it apart from a subdomain and a look-alike spelling, without following the link.

1 / 8

Reading an address from right to left

Reading an address from right to left

A link looks long and confusing, but one short part decides it: the site name. Find the first single slash after hxxps:// . Everything to its left is the site name; everything to its right is the path inside the site, where the owner can write anything. Now read the name right to left: the real name is the last two parts, split by a dot. Let's take it apart: say your bank is called Northwind Bank, and its site is bank-northwind.com. You get hxxps://bank-northwind.secure-signin-acct.com/pay . The first slash comes before pay; to its left is bank-northwind.secure-signin-acct.com. Read it right to left: com, secure-signin-acct. The real site name is secure-signin-acct.com, which has nothing to do with the bank. The familiar word on the left is just a prefix: anyone can add it. Length means nothing: real sites have long addresses too. The padlock and https prove nothing either: they only mean the connection is encrypted, and fake sites have them too. Two things can't be read by eye. One is look-alike letters: a Latin a and a Cyrillic a look the same on screen. The other is a short link: the site name is hidden, so there's nothing to read. Either way, don't trust your eyes: go through your own route, from a bookmark or the official app. On a phone you can see the address before tapping: press and hold the link to see it in full.
Lesson notes
Reading an address from right to left
A link looks long and confusing, but one short part decides it: the site name. Find the first single slash after hxxps:// . Everything to its left is the site name; everything to its right is the path inside the site, where the owner can write anything. Now read the name right to left: the real name is the last two parts, split by a dot. Let's take it apart: say your bank is called Northwind Bank, and its site is bank-northwind.com. You get hxxps://bank-northwind.secure-signin-acct.com/pay . The first slash comes before pay; to its left is bank-northwind.secure-signin-acct.com. Read it right to left: com, secure-signin-acct. The real site name is secure-signin-acct.com, which has nothing to do with the bank. The familiar word on the left is just a prefix: anyone can add it. Length means nothing: real sites have long addresses too. The padlock and https prove nothing either: they only mean the connection is encrypted, and fake sites have them too. Two things can't be read by eye. One is look-alike letters: a Latin a and a Cyrillic a look the same on screen. The other is a short link: the site name is hidden, so there's nothing to read. Either way, don't trust your eyes: go through your own route, from a bookmark or the official app. On a phone you can see the address before tapping: press and hold the link to see it in full.
Lesson 7. How to read a link in five seconds — Scam Defense: How to Keep Your Money