Skip to main content
All lessons
Lesson 1Scams & Social Engineering pathway

Safe Browsing & Scams

Spot the traps before you click

Highlighted wordsare glossary terms — tap one for a plain-language definition.

Most attacks start with a click. Knowing how to read a URL and recognize a scam is one of the highest-leverage skills in digital hygiene.

Read the URL like a label

Look for , the padlock icon, and the real domain. Attackers love lookalike domains (paypa1.com, micros0ft.support).

  • Confirm the URL starts with https://.
  • Click the padlock to inspect the certificate.
  • Use Google Safe Browsing or VirusTotal to vet a URL.

Recognize phishing

Legitimate companies will not ask for passwords or sensitive data over email. Urgency, threats, and 'too good to be true' offers are red flags.

  • Don't click links in unsolicited emails.
  • Hover to preview a link before clicking.
  • Verify by visiting the site directly in your browser.

Let phishing-resistant sign-in do the checking

NIST Special Publication 800-63B calls an authenticator phishing-resistant when it is cryptographically bound to the real website address. Passkeys and security keys simply refuse to work on a lookalike domain, so even a convincing fake page gets nothing. A typed password or a six-digit code, by contrast, can be relayed to the real site by an attacker in real time — which is why 'the code arrived, so it must be legit' is not a safe assumption.

  • Set up a or wherever it's offered — it removes the judgment call.
  • Never type a one-time code into a page you reached from a link or a phone call.
  • If your doesn't auto-fill, treat it as a domain mismatch warning.
  • Nobody legitimate will ever ask you to read out an code.

Brought to you by NorthBridge

Unfamiliar term? Open the Digital Safety Glossary