Safe browsing
Where on the internet can you safely click, and where not? With a few rules of thumb you browse a lot more safely — at the office and at home.
Which of these two addresses really belongs to Microsoft: login.microsoft.com or microsoft.login-verify.com? And why?
Read the URL before you click
The web address tells you where you'll really end up. Look at the domain: that's the part right before the first single forward slash, read from the right. login.microsoft.com belongs to Microsoft; microsoft.login-verify.com does not — there, login-verify.com is the real domain. Also watch for swapped letters (rnicrosoft.com) and odd extensions.
- Hover your mouse over a link (or press and hold on your phone) to see the real destination.
- A padlock (https) only means the connection is encrypted — not that the site is trustworthy. Phishing sites have a padlock too.
- Go to important sites (bank, email, portals) via your own bookmarks or by typing the address yourself.
Where not to just click
Ads and sponsored search results
Criminals buy ads above the real search result, especially for software downloads. Scroll to the organic result or type the address yourself.
Pop-ups: "your computer is infected!"
Messages asking you to call a number or install something are a scam (tech support scam). Close the tab; never call such a number.
"Update your browser/codec" messages on websites
Browsers update themselves; sites that offer updates are almost always malicious.
Links in unexpected emails, chat messages or texts
See our recognising phishing training — the same rules apply to WhatsApp and text messages (smishing).
Shortened links (bit.ly and similar)
You can't see where you'll end up. From an unknown source: don't click.
Downloads and paying
✔ Do
- Download software from the maker's official site or the app store
- Check the file type before opening
- For webshops, check reviews and business registration details first
- Only log in if you navigated to the site yourself
✘ Don't
- Open an "invoice" ending in .exe, .js or .html
- Download via ads
- Pay at a shop you haven't checked
- Enter passwords after clicking through from an email
Your password manager is an extra alarm bell: if it doesn't automatically fill in your password on a familiar site, you're probably on a fake domain.
Browser hygiene
- Keep your browser up to date and use one as your default.
- Install as few extensions as possible, and only from the official store.
- Don't let your browser save passwords; your password manager does that better.
- Public wifi? Use a VPN or your phone's hotspot.
Clicked something wrong anyway?
Close the page, change any passwords you used, and report it immediately to your IT administrator or Tip ICT. Reporting quickly limits the damage — staying quiet makes it worse.
Test yourself
Learn more
- Veiliginternetten.nl — safe browsing in plain language (Dutch)
- Fraudehelpdesk.nl — check current scam types and fake shops (Dutch)
- Our recognising phishing training