Do not judge a link only by the text you can see. Attackers can make link labels look familiar while sending you somewhere else.
Preview the real destination
On desktop, hover over the link and inspect the destination shown by the browser. On mobile, use a long press where appropriate rather than opening immediately.
Check the domain carefully
Look at the registered domain, not just familiar words elsewhere in the address. If a message claims to be from a bank or service, open the provider’s known website or app independently instead of following the message link.
Use trusted security guidance
For phishing guidance, see the UK National Cyber Security Centre. In the US, the FTC phishing guidance is also useful.
