Test a Suspicious Link Without Risking Your Computer
Someone sent you a link you do not trust. Here is how to look at it safely, without risking the computer you actually work on.
Step 1. The Golden Rule: Never Test a Suspect Link on a Machine You Care About
A bad link does not usually announce itself. It can quietly install something, lift the passwords your browser has saved, or lock up your files until you pay. You will not get a warning, and you will not see it happen. By the time you notice, the damage is done.
So the rule is simple. If you would be upset to lose it, do not open the link on it. That covers your main computer, your work laptop, and anything holding files you cannot replace.
This is not paranoia. It is basic hygiene, in the same way you would not open a stranger's parcel on your living room floor. You can still look at what is inside. You just choose where.
Step 2. Why Opening It On Your Phone Is The Worst Option
This one runs against instinct, but it matters. Many people reach for the phone because it feels disposable. It is not. Your phone holds your email, your banking app, your photos, your two factor codes, and a long list of saved logins.
It is often the single most valuable device you own, and it is the hardest one to inspect or clean once something is on it. You cannot easily wipe it without losing things you need, and you cannot see what it is doing.
So do not test on the phone. Set aside a machine that holds nothing you would miss, and use that instead.
Step 3. Set Up a Free Isolated Environment
The safest place to open a bad link is a machine that is not your machine. In plain terms, a virtual machine is a computer inside your computer. It runs in its own window, has its own operating system, and by default cannot reach your real files.
Here is the concrete approach. Download a free hypervisor, either VirtualBox or VMware Workstation Player. Create a new virtual machine and install a fresh operating system inside it. Keep it separate from everything you care about and use it for one purpose only, testing links.
The first setup takes about an hour. After that it is done, and you can reuse the same machine again and again. A cheap or old computer that is not used for anything else also works, and for many people it is simpler. The point is isolation, not the method.
Step 4. Take a Snapshot Before You Open Anything
A snapshot is a saved picture of the machine at a moment in time. You take one, and later you can rewind to it. Everything that happened in between is simply gone.
Take the snapshot while the machine is clean and unused, before you have opened anything. Then open the link. When you are finished, rewind to the snapshot and the machine is clean again, exactly as if nothing had happened.
Take the snapshot before, every single time, and give it an obvious name such as clean before test. If you forget once, you cannot trust the machine afterwards, and you have to start over.
Step 5. The Rules of Safe Testing
These rules are what keep the testing environment safe. Follow all of them, every time.
- 1.Do not log into anything real. No email, no bank, no social accounts, nothing that belongs to you.
- 2.Use no personal details. Nothing with your real name, address, phone number, or date of birth.
- 3.Do not enter any password, not even a fake one, on a page you do not trust.
- 4.Keep the machine's network access minimal, and switch it off entirely if you can. Many links still reveal their target without a live connection.
- 5.Never connect this machine to your home network shares or your printers. Isolation is the whole point.
- 6.Do not install your password manager in it. It would hand over everything you are trying to protect.
- 7.Treat everything inside it as contaminated at all times, including files you think look harmless.
Step 6. What To Look For Once It Opens
Now you watch, calmly, and you take notes. Here is what to observe.
- •What does the page actually ask you to do?
- •Does it ask for a password where the real service would not?
- •Where does it redirect you, and does that destination look right?
- •Does it try to download a file, and what is that file called?
- •What is the real web address in the address bar, compared with what the page claims to be?
- •Does it look rushed, or use a slightly wrong logo, colour, or wording?
Write down what you saw while it is fresh. Notes in writing are what let you report it properly, and they help you recognise the same trick next time.
Step 7. When To Stop, And How To Report It
If it asks you to install software, close it. That is where you stop. Do not chase it further, and do not try to outsmart it.
If it is a phishing attempt, report it. Forward the original email to the UK National Cyber Security Centre's Suspicious Email Reporting Service at [email protected], and tell the company that was impersonated so they can warn others.
If you want to test another link afterwards, delete the virtual machine and build a fresh one, or rewind to your clean snapshot. Do not reuse a machine that has already opened something suspect.
The value here is knowing, not engaging. You wanted to see what it does, and now you have. That is enough.
Tips
- •An old laptop with nothing important on it is a perfect test machine.
- •Always snapshot before you open, every single time.
- •Never test on the phone that holds your bank.
- •If the link came by email, report it even if you are unsure.
- •The safest suspicious link is one you let someone else open.
- •Knowing what a scam looks like teaches you to spot the next one.
Need More Help?
StarCaller Academy offers 1-to-1 sessions to help you with any of these topics and more.