A simple guide to safer clicking · 安全点击简明指南

A link is not always
what it says it is.

链接显示的内容,不一定是真实的去向。

Before you click, pause and check where the link really goes.

点击之前,请先停一下,检查链接的真实去向。

Lesson 1 · 第一课

Displayed text ≠ real destination

显示文字 ≠ 真实去向

These blue links are intentionally fake demonstrations.Every website link below says one thing but opens encyapps.com. The email link above says “president@example.com” but creates a message to ency98@gmail.com.以下蓝色链接是故意制作的假链接演示。下面每个网站链接显示的是一个熟悉的网站,但点击后都会打开 encyapps.com。上面的邮件链接显示“president@example.com”,但实际会创建一封发给 ency98@gmail.com 的邮件。

Click to see it happen · 点击查看实际效果

Familiar names. Unexpected destination.

熟悉的名称,意想不到的去向。

FAKE DEMO LINKS: The text above is not the destination. Every link opens encyapps.com. · 假链接演示:以上文字不是真实去向,每个链接都会打开 encyapps.com。

Try this: On a computer, hover over a link without clicking. The true address usually appears at the bottom of the browser.
试一试:在电脑上,将鼠标停在链接上但不要点击。真实地址通常会显示在浏览器底部。

Lesson 2 · 第二课

Look closely. One character can change everything.

仔细看,一个字符就可能改变一切。

Expected · 正确Look-alike · 仿冒What changed? · 有什么不同?
paypal.com× paypaI.com

The last character is a capital I, not a lowercase l.
最后一个字符是大写 I,不是小写 l。

google.com× g00gle.com

Two letter o’s were replaced with zeroes.
两个字母 o 被替换成了数字 0。

apple.com× аррӏе.com

Some letters are from another alphabet but look similar.
部分字母来自另一种字母表,但外形很相似。

chase.com× chase-secure.com

Extra words can make a different, unofficial domain.
多出的单词会形成一个不同的非官方网站。

amazon.com× amazom.com

The letter n was replaced with the letter m.
字母 n 被替换成了字母 m。

ncsecu.org× ncsecu-login.com

The real SECU address ends in .org, not this added-word .com.
真正的 SECU 地址以 .org 结尾,而不是这个带有额外单词的 .com 地址。

baidu.com× baí du.com

Accents, spaces, or tiny character changes are warning signs.
重音符号、空格或细微字符变化都是警告信号。

taobao.com× ta0bao.com

The first letter o was replaced with a zero.
第一个字母 o 被替换成了数字 0。

These are visual examples only. Do not type or visit the look-alike addresses. · 以上仅为视觉示例,请勿输入或访问仿冒地址。

Before you click · 点击之前

Stop. Look. Check.

停一下。看清楚。再核实。

  1. 1

    Pause if the message feels urgent.

    Scammers create panic: “Act now,” “Your account is locked,” or “You won a prize.”

    如果信息让您感到紧迫,请先停一下。骗子常说:“立即行动”、“您的账户已被锁定”或“您中奖了”。

  2. 2

    Check the entire address.

    Look for misspellings, extra words, strange endings, and @ signs in web links.

    检查完整地址,注意拼写错误、多余单词、奇怪的域名结尾,以及网页链接中的 @ 符号。

  3. 3

    Open the official site yourself.

    Use a saved bookmark or type the known address. Do not use the message’s link.

    使用已保存的书签或亲自输入已知的官方网址,不要点击信息中的链接。

  4. 4

    Ask someone you trust.

    Never share a password, verification code, bank PIN, or remote access to your device.

    请向您信任的人求助。切勿透露密码、验证码、银行卡密码,也不要让陌生人远程控制您的设备。