Highlighted wordsare glossary terms — tap one for a plain-language definition.
Most attacks start with a click. Knowing how to read a URL and recognize a scam is one of the highest-leverage skills in digital hygiene.
Read the URL like a label
Look for HTTPSWhat it means: A protected connection between your browser and a website. It encrypts the connection but does not prove that the website itself is trustworthy.Example: The padlock and “https://” shown in your address bar.What to do: Read the domain spelling carefully, not just the padlock.Important: Scam sites use HTTPS too — the padlock is not a trust badge.What does this mean?, the padlock icon, and the real domain. Attackers love lookalike domains (paypa1.com, micros0ft.support).
- Confirm the URL starts with https://.
- Click the padlock to inspect the certificate.
- Use Google Safe Browsing or VirusTotal to vet a URL.
Recognize phishing
Legitimate companies will not ask for passwords or sensitive data over email. Urgency, threats, and 'too good to be true' offers are red flags.
- Don't click links in unsolicited emails.
- Hover to preview a link before clicking.
- Verify by visiting the site directly in your browser.
Let phishing-resistant sign-in do the checking
NIST Special Publication 800-63B calls an authenticator phishing-resistant when it is cryptographically bound to the real website address. Passkeys and security keys simply refuse to work on a lookalike domain, so even a convincing fake page gets nothing. A typed password or a six-digit code, by contrast, can be relayed to the real site by an attacker in real time — which is why 'the code arrived, so it must be legit' is not a safe assumption.
- Set up a PasskeyWhat it means: A phishing-resistant way to sign in using cryptographic credentials stored or managed by a trusted device or credential provider, instead of typing a reusable password.Example: Unlocking an account with your fingerprint, face, or device PIN — nothing to type.What to do: Consider a passkey when an important account offers one, starting with your email.Important: Keep a device lock and a backup sign-in method in case you lose the device.What does this mean? or Security keyWhat it means: A physical FIDO-compatible device used to provide strong, phishing-resistant authentication.Example: A small USB or tap-to-approve key you use when signing in.What to do: Register two keys: one for daily use and one kept in a safe place.Important: Among the strongest practical options — no method makes an account impossible to compromise.What does this mean? wherever it's offered — it removes the judgment call.
- Never type a one-time code into a page you reached from a link or a phone call.
- If your Password managerWhat it means: Software that generates, stores, and fills unique account passwords, and may also manage passkeys or other credentials.Example: The manager generating and filling a 20-character password you never have to recall.What to do: Set one up and move your email, banking, and cloud passwords into it first.Important: Protect it with one strong passphrase plus MFA, and never share that passphrase.What does this mean? doesn't auto-fill, treat it as a domain mismatch warning.
- Nobody legitimate will ever ask you to read out an Multifactor authenticationWhat it means: Using more than one type of authentication evidence before an account grants access.Example: Entering your password and then approving the login through an authenticator app.What to do: Turn it on first for your email, financial, social-media, and cloud accounts.Important: Never give an unexpected login code to someone who contacts you.What does this mean? code.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary