Spotting suspicious redirect links before you click
Australians have learned to expect dodgy messages. A text about a missed AusPost delivery, an email claiming your myGov account needs verification, or a LinkedIn pitch from someone you have never met can all be wrapped around a single tap-to-open link. The Australian Competition and Consumer Commission's Scamwatch has logged hundreds of thousands of reports in recent years, and link-based scams make up a sizeable chunk of them. Knowing how to read a hyperlink without clicking it is now a routine digital skill, like looking both ways at a Melbourne tram stop.
A redirect link is not a single destination but a chain of small instructions. When you tap one, your browser or app asks the first server where to go, that server points to another, and the bouncing can continue through three, four, or more hops before a final page renders. Legitimate marketers use this technique for tracking, regional content, and short URL services. Scammers use it for the same reason, which is why a "redirect link" sits in a grey zone: the technology is neutral, the intent behind it varies wildly.
The Australian landscape carries its own patterns. Text-message scams pretending to be from Australia Post, Linkt, or a major telco like Telstra or Optus routinely lead through redirect chains hosted on URL shorteners or compromised WordPress blogs. Email phishing campaigns impersonating the ATO, myGov, or the big four banks (CBA, Westpac, ANZ, NAB) lean on the same playbook. Even Services Australia has issued warnings about fake Centrelink links bouncing through intermediary domains. Recognising the local flavour of these cons makes it easier to spot when something feels off.
The good news is that almost every link can be inspected before you commit to opening it. With a mix of careful inspection, a few built-in tools, and some Australian-specific verification habits, the chances of landing on a malicious page drop sharply.
What a redirect chain actually does
When a hyperlink is published as a clean "https://example.com.au/promo", the user usually reaches the destination in one step. When it has been wrapped or shortened, the underlying target can be much longer, and the path can hop through several unrelated domains on the way. Each hop is a server returning an HTTP 3xx status code telling the browser "go somewhere else". The browser follows obediently, sometimes across different countries and infrastructure companies. From the user's perspective, the page simply loads.
Scammers exploit this behaviour for two reasons. First, the final malicious URL rarely appears in the message you receive, so spam filters that scan the visible text see nothing alarming. Second, intermediate domains can be swapped out within minutes, letting the same short link point to different phishing pages over its lifetime. A campaign targeting Bendigo customers one week can pivot to Macquarie Bank customers the next, simply by changing where the final hop resolves.
Australian banks and government services occasionally use legitimate redirects too. A CBA marketing email might route through a tracking domain before reaching commbank.com.au, and a Service NSW reminder can pass through an SMS gateway before the final URL appears. The presence of a redirect is therefore not, on its own, proof of a scam. What matters is whether the final destination matches the brand the message claims to represent, and whether the path itself looks reasonable for the organisation involved.
URL red flags worth memorising
The quickest sanity check happens before any tool is launched. Look at the visible link, the hover preview, or the long-press menu on a phone, and run it through a short mental checklist. Domains that impersonate well-known Australian brands with subtle typos, such as commbanlk.com.au or ato-gov.au, are obvious warning signs. So are domains that swap the country-code TLD for something cheaper, like anz-update-login.top instead of anz.com.au.
auDA, the body that administers Australian domain names, has strict eligibility rules for .com.au, .net.au, and similar namespaces. That means a legitimate Australian business will almost always use a .com.au or .au address rather than a free TLD. If you receive a message that claims to come from a Sydney-based retailer but the link points to a .tk, .xyz, or .click domain, treat it as suspicious. A genuine link to Myer or Bunnings will resolve to myer.com.au or bunnings.com.au, not a creative spelling of those names on an offshore registry.
Shorteners such as bit.ly, tinyurl, and ow.ly add another layer of opacity. They are widely used by small businesses, community groups on Facebook, and even by Brisbane City Council for campaign material, so a shortened link is not automatically bad. The risk rises when the sender is unknown, the surrounding message urges urgency, or the short URL has been newly minted. Many shorteners now offer a preview function, where appending a plus sign to the URL reveals the destination without clicking through. Using that preview is a low-cost habit worth forming.
The hover test and mobile equivalents
On a desktop browser, the single most useful habit is to hover the cursor over any link before clicking. The actual destination appears in the bottom-left corner of the window, and any mismatch between the displayed label and the true URL becomes immediately obvious. An email that reads "Click here to view your ATO statement" but resolves to an unrelated .ru domain is a giveaway, and it costs nothing to spot.
Mobile devices require a slightly different approach. In most email apps, including the default iOS Mail and Gmail on Android, long-pressing a link brings up a menu that includes the full URL. The behaviour is similar in Outlook mobile, Spark Mail, and the in-app browsers of major Australian banking apps such as CommBank and ANZ. Some apps show only a truncated version with an ellipsis, in which case tapping "Copy" and pasting into a notes app reveals the rest. It is a small detour that pays for itself the first time it stops a phishing attempt.
There is one important nuance: the destination shown in the preview may itself be the first hop in a chain. Even if the preview looks legitimate, the actual landing page could be different. That is why combining the hover or long-press check with a quick mental comparison of the visible brand and the actual domain is essential. If the two do not match, do not tap, no matter how convincing the rest of the message seems.
Built-in browser and email protections
Modern browsers and email clients do a lot of silent work in the background. Google Safe Browsing, Microsoft SmartScreen, and Apple's fraud warning systems all maintain blocklists of known phishing and malware domains. When a user navigates to a flagged URL, a full-page interstitial appears, warning that the site has been reported as deceptive. These protections are imperfect; a freshly registered scam domain can slip past them for hours or even days, but they catch the vast majority of repeat offenders.
Australian internet users on the big three mobile networks, Telstra, Optus, and Vodafone (TPG), often benefit from carrier-level spam filters that strip known scam URLs from SMS messages before they reach the handset. Messages still get through, especially when sent from individual mobile numbers rather than shortcodes, but the baseline level of filtering is meaningful. Pairing that carrier filtering with an updated browser and a current operating system gives layered coverage against most mass-market campaigns.
For people who want to go further, a few browser extensions add visible link annotations or run third-party reputation checks against every URL on a page. These tools are useful, but they also add a small privacy cost, since your browsing history may be shared with the extension provider. A lighter alternative is to use an external checker only when a specific link raises doubt, rather than installing software that inspects everything by default. A focused resource like an online link checker can answer a single question without changing the rest of your browsing setup.
Manual verification when still in doubt
Sometimes the URL looks plausible, the preview matches the brand, and the message has no obvious grammatical red flags. In those cases, the safest move is to skip the link entirely and reach the claimed destination through a route you trust. Open a new browser tab, type the address of the bank, retailer, or government agency directly, and navigate from there. If the message concerned a real account issue, it will usually be visible once you log in through the official site.
Phone verification is the next layer of protection. Australian banks will never object to being called on their publicly listed number for confirmation. The number on the back of a debit card, on a recent paper statement, or on the official website is the right one to use. Numbers supplied inside the suspicious message should be ignored, since scammers often run their own call centres with convincing menus and hold music. The same applies to myGov, the ATO, and Centrelink, all of which publish their contact details on the official .gov.au domain.
Reporting the message also helps the wider community. Scamwatch accepts reports online and via the phone number 1300 795 995, and the ACMA handles spam complaints through its own portal. Forwarding suspicious SMS messages to 0429 999 888 will alert the telcos and contribute to blocking similar campaigns in the future. Anyone curious about how the same patterns appear across the Tasman can find a practical New Zealand guide that covers many of the same techniques in a slightly different regulatory context.
| Indicator | Risk level | Example |
|---|---|---|
| Misspelled brand in domain | High | commbannk-login.com |
| Free TLD with login theme | High | mygov-update.tk |
| Numeric IP address used as URL | High | http://203.0.113.45/ato |
| URL shortener from unknown sender | Medium | bit.ly/3xK9qZm |
| Legitimate .com.au on familiar brand | Low | westpac.com.au |
| Long, parameter-heavy but on-brand URL | Low | commbank.com.au/ibanking/login?... |
The table above is a starting reference, not a definitive rulebook. Some high-risk patterns occasionally appear in legitimate campaigns, especially when a small business uses a free domain for a one-off landing page. Conversely, a well-crafted scam can mimic every visible element of a genuine link. Treat the indicators as probabilities, not certainties, and combine them with the verification habits outlined earlier.
A few extra seconds of inspection can prevent weeks of dealing with a compromised account. Make the hover, the long-press, or the manual destination check a non-negotiable part of how you handle any link that arrives unexpectedly. Share the habit with younger relatives, with older family members who manage their own bills, and with anyone in your Sydney, Perth, or Hobart office who still trusts every "Hi Mum" message that lands in their inbox. The redirect chain only works if you click, and a thoughtful pause breaks the entire chain before it begins.