MYTHOSAI

Email and domains / PRACTICAL GUIDE

Inspect the real domain in an email link

Separate a convincing label, subdomain and redirect from the service you intended to visit.

Before you start

A desktop email application with link preview or hover information; no need to open the link.

Read the destination in the right order

A link's visible words can say account support while the underlying address points elsewhere. Domain components can also be arranged to resemble a known service. In https://login.bank.example.attacker.test/help, the destination is under attacker.test. The familiar words before it are subdomains, not proof that your bank owns the address.

Use a harmless sample or a message you are authorised to review. Do not open a suspicious link simply to discover where it eventually redirects.

Inspect without signing in

  1. Hover over the link in a desktop client or use the application's documented preview feature. Compare the actual destination with the displayed label.
  2. Identify the hostname and the domain boundary. Watch for spelling changes, unexpected suffixes and internationalised characters that resemble familiar letters. Domain structure can be more complicated than always counting two labels from the right.
  3. Treat shortened or tracking links as incomplete evidence. They may hide the final destination. Use a known bookmark or the genuine app to check the claimed account event instead.
  4. For a sensitive action, navigate independently and verify whether the request exists in the real service. Do not enter credentials or upload documents into a page reached only through an unverified message.

Verify the conclusion carefully

A mismatch is useful evidence that the request needs further checking. A match is not a guarantee of safety: a legitimate site can host a malicious user page, and a real account can be compromised. Combine destination analysis with the requested action and the sender's verified context.

Avoid creating an exposure during analysis

Do not paste private reset links or invitation tokens into a public URL-scanning service. Those addresses can contain working credentials or confidential identifiers. If your organisation has an approved analyser, follow its data-handling process and know what it shares.

Practise with safe examples

Write a small comparison using reserved example domains. Describe which hostname would receive the connection and why. The useful skill is interpreting the address, not memorising a list of suspicious words. When the destination is ambiguous or hidden, independent navigation is often the fastest safe way to check the request without expanding the link at all.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.