Free cybersecurity training for organizations of any size. Schedule yours today ›

Hover Before You Click: The 10-Second Habit That Stops Phishing

The Security BriefMay 6, 2026

Phishing works because people click first and check later. One ten-second hover trick reveals where a link really goes, before you click.

Here’s something that surprises a lot of people: every link in your inbox is wearing a costume. The words you see on screen (“View Invoice,” “Reset Your Password,” “Join Meeting”) are just a label. The real destination underneath can point anywhere on the internet. Scammers count on you never looking underneath.

Phishing attacks work for one simple reason: people click first and check later.

The good news? There’s a ten-second habit that flips the script: no software, no training course, no technical skill required.

How the scam works

A message lands in your inbox that looks like it came from someone you trust: your bank, Microsoft, a vendor, even a calendar invite for a meeting you weren’t expecting. Inside is a link with perfectly friendly text.

But the text of a link and the destination of a link are two different things. “yourbank.com” on screen can secretly point to a look-alike site the scammer set up last week. Click it, and you land on a login page that looks exactly like the real thing. You type in your email and password, and just like that, the attacker has your credentials. Some fake pages even forward you to the real website afterward, so you never notice anything happened.

The whole scheme depends on speed. We’re busy, the message looks routine, and clicking is automatic. The attacker only wins if you skip the check.

The hover check: see where a link really goes

Before you click any link in an email, hover your mouse over it. Don’t click, just hover. The actual destination will appear, usually in the bottom corner of your screen or in a small popup. On your phone, press and hold the link instead, and a preview of the real URL pops up.

That’s it. That’s the whole trick. Now you can see whether the link goes where it claims to go.

How to protect yourself

Here’s the full habit, start to finish:

  • Hover before you click. On a computer, rest your cursor on the link and read the real address that appears.
  • Press and hold on mobile. A long press shows you where the link actually leads, without opening it.
  • Scan for red flags. Misspellings, random strings of numbers, unfamiliar domains, or a web address that has nothing to do with the supposed sender are all warning signs.
  • Trust the “something feels weird” feeling. If a link looks off, don’t click it. No email is so urgent that it can’t wait ten seconds.
  • Verify it independently. Google the website’s name followed by the word “scam,” or search the URL directly in your browser before you do anything else.
  • Go straight to the source. When in doubt, skip the link entirely. Type the company’s web address yourself, use a saved bookmark, or call them at a number you already know.

Those ten seconds could save your login credentials, your accounts, and a really bad afternoon.

Make it a team habit

One person hovering over links is good. A whole office doing it automatically is what actually keeps a business safe, because attackers only need one rushed click to get in. Bring this up at your next team meeting, try it together on a real email, and it’ll become second nature fast.

At Vertical IT Solutions, we help businesses build exactly this kind of everyday security muscle, the simple habits that stop most attacks before they start. Curious where your company stands today? Take our free 60-second Security Score, or talk to our team. No pressure, no jargon, just straight answers.

Ready to get started?

Get a free quote, or talk to our team about your IT needs.