Wide landscape photograph of rolling green hills under a soft overcast sky, with a narrow winding road leading toward distant mountains. Muted greens, pale blues, and earthy browns dominate the scene, conveying calm and open space.

Life in New Zealand, Unfiltered

A personal blog by Mardy — leaving Japan, chasing love, and building a life across the ocean.

How to spot a phishing lure hidden behind a Click here link

Almost every inbox in Australia carries a "Click here" button at some point during the week. It might sit inside a courier redelivery notice, a refund offer, or a calendar invite from a colleague. The phrasing has become so routine that fingers tap it before the brain has finished reading. That muscle memory is exactly what scammers count on when they wrap phishing inside a generic call to action and drop it into a sea of ordinary emails.

Australian losses to phishing have climbed sharply over the past few years, with the ACCC's Scamwatch recording hundreds of millions of dollars lost annually to text and email cons. The shift to remote work, the rollout of myGov, and the popularity of buy-now-pay-later platforms have all widened the surface area for attackers. The "Click here" wording is rarely a coincidence; it is a deliberate choice borrowed from the legitimate marketing playbooks that flood our screens every day.

Consider what a typical arvo at the desk looks like. An employee in a Melbourne office opens what looks like a payroll update from a known provider, taps the embedded link, and lands on a page that mirrors the real login almost perfectly. The same pattern plays out in Perth households, Brisbane cafés, and Adelaide workshops, where staff juggle phones, tablets, and laptops with little time to inspect every link.

Recognising the patterns behind these lures is the focus here. The aim is to give you a practical framework for reading a "Click here" prompt, judging the destination before you commit, and recovering if you have already tapped through.

Why Click here became a magnet for scammers

Marketing emails have trained an entire generation of internet users to equate "Click here" with progress. Buttons with that label have long dominated newsletter sign-ups, special offers, and PDF downloads. Phishing operators borrow the same wording because it works on autopilot; the reader is not really reading, they are following a familiar pattern.

The wording is also deliberately vague. A genuine order confirmation will usually name the product, the courier, or the merchant. A scam, by contrast, uses the universal "Click here" because it does not know which product or service you might respond to. That vagueness lets the same template be aimed at thousands of Australians at once.

The Australian Cyber Security Centre has repeatedly warned that the most successful phishing campaigns keep their language plain. Words like "verify", "update", "suspend", and "click here" travel across borders because they feel official yet urgent. When you see that combination in a message claiming to be from the ATO, Australia Post, or your telco, treat the link as guilty until proven innocent. A useful redirect link guide lays out how a single tap can bounce you through several servers before a fake page appears.

Anatomy of a suspicious redirect

Behind most deceptive "Click here" buttons sits a redirect chain. The link you see is rarely the link you finally reach. Attackers use URL shorteners, open redirects on compromised sites, and lookalike domains to bounce traffic through two or three hops before a credential-harvesting page loads. The browser only shows the final destination, so the inspection must happen earlier in the chain.

In Australia, a common pattern involves a domain registered overseas that resembles an Australian brand. A scam pretending to be from a Big Four bank might use a .com address with a misspelt subdomain, or a string of random characters that mimic a transaction reference. Hovering over a desktop link, or long-pressing it on a mobile device, reveals the true address.

Another layer to watch is the subdomain trick. A URL like "anz.com.au.security-alert.login.example.org" makes the genuine anz.com.au appear at the start, but the actual host is example.org. The eyes scan left to right, and scammers rely on that habit. Treat anything that places a familiar brand name in a position other than the true domain as a red flag.

Red flags Australians should watch for

Australian phishing attempts often borrow the branding of the ATO, myGov, Australia Post, and the major banks. A real message from these organisations will address you by name and will direct you to log in through a bookmark or a typed URL, not through a button in an email. Generic greetings such as "Dear customer" paired with "Click here to confirm your details" should always raise suspicion.

Local tone can also be a giveaway. Genuine Australian communications tend to read in plain English without dramatic threats, while phishing messages often mix American spellings with oddly formal language. A note that warns of "immediate suspension" or "criminal prosecution" within twenty-four hours is using fear, not procedure. Slowing down helps, particularly with messages purporting to come from Telstra, Optus, or the NDIS, all of which have been impersonated in recent waves of scams.

A second pass should look at the metadata. Check the sender's full email address, not just the display name. A message claiming to be from "ANZ" but coming from a free webmail account is a clear sign of trouble. If you want a structured walkthrough of what an unfinished or suspicious page looks like, the guide on placeholder sites describes the tell-tale signs of a domain that exists only to host a single deceptive link.

Reading the URL before you click

URLs are the most reliable evidence of where a "Click here" button will actually take you, but they reward a careful eye. Start from the right side of the address and work leftward. The true top-level domain, such as .com.au or .gov.au, sits at the far right and tells you the country and type of organisation. Anything to the left is a subdomain, and subdomains can be named freely by whoever owns the main domain.

Phishers exploit that freedom by stacking familiar words on top of unrelated domains. A link like "login.myaccount.com.au.malicious-site.net" actually belongs to malicious-site.net. The .com.au in the middle is just decoration. Training yourself to scan for the segment immediately before the top-level domain, and to ignore everything that comes before it, will catch most of these attempts.

Mobile screens make this harder, since long addresses get truncated. On a phone, long-press the link to copy the full URL, then paste it into a notes app where you can read it in full. The comparison below summarises what a legitimate link looks like next to a typical phishing counterpart.

Feature Legitimate Link Phishing Link
Top-level domain Matches the brand, e.g. anz.com.au Foreign or unrelated, e.g. .ru, .top, .click
Subdomain structure Brand at the far right, simple path Brand placed inside a longer chain, often random characters
Use of HTTPS Present with valid certificate Present but issued to a different organisation
Spelling Correct, including double letters and hyphens Off by a letter, e.g. commbank vs commbanlk
Path and parameters Short, descriptive, and stable Long, encoded, or filled with tracking IDs
Purpose of domain Hosts many pages for that brand Registered for one purpose

Tools and habits that build defences

A few small habits dramatically reduce the odds of a successful phish. Bookmark the login pages you actually use, from internet banking to myGov, and reach them through those bookmarks rather than through links in messages. Most Australian banks now offer in-app security alerts that mirror suspicious activity, so the app is often a safer source of truth than any SMS link.

Enable multi-factor authentication on every account that offers it. An authenticator app or a hardware security key adds a second wall that survives a leaked password. Password managers also help in a subtle but powerful way: they refuse to autofill credentials on a site whose URL does not match the saved entry, which means a fake "Click here" landing page will not be filled in automatically.

Keep your devices current and use the built-in safe-browsing features in modern browsers. Both Chrome and Safari now flag known phishing sites before the page fully loads, and most mail apps will move obvious scams into a junk folder. None of these tools are perfect on their own, but layered together they make a casual "Click here" lure far less likely to succeed.

What to do if you have already clicked

If a tap on a "Click here" link has already happened, stay calm and act quickly. Close the browser tab without entering any information, then disconnect from the network if you suspect malware has been delivered. Run a full scan with your security software, and clear the browser cache so any tracking parameters stored locally are removed.

If you entered a password, change it straight away from a clean device and a typed URL. Contact your bank if the account is financial, and notify your IT team if the device was a work laptop. Australians can also report the incident to Scamwatch and, where identity documents may have been exposed, to the Australian Cyber Security Centre through ReportCyber.

Watch your accounts for the following weeks, not just the first day. Some phishing kits collect credentials quietly and only use them later, often outside business hours to delay detection. Review bank statements, credit reports, and any services linked to the exposed email. If a service offers a session-revocation feature, use it to sign out of all devices at once.

Building a Click here safety routine at home and work

Defending against a "Click here" lure works best when it becomes routine rather than a special event. Set a personal rule that any link arriving by SMS, email, or social media gets verified before it is opened, and share that rule with everyone in the household. Family members in regional towns, where connectivity may be slower and pop-ups harder to dismiss, benefit from a clear script: read the sender, read the URL, and only proceed if both make sense.

In the workplace, treat link awareness as part of the same hygiene as locking your screen when you walk away. Encourage colleagues to forward suspicious messages to a shared mailbox for review rather than debating them in chat. Run a short refresher each quarter, using real-world examples reported by Scamwatch, and reward people who flag a fake rather than treating it as an error.

A small dose of healthy scepticism goes a long way. A genuine organisation will never object if you type its web address into a browser instead of tapping its button, and a real courier will leave a card in your letterbox if a delivery cannot be made. Treat every "Click here" as a polite request that still needs your eyes before it gets your finger. The same patient reading habit is useful elsewhere on the web, where a gentler read on an unrelated subject still rewards the kind of attention that protects you from phishing.

Bookmark this guide, share it with one person today, and turn the habit of reading before you click into something you do without thinking. Tomorrow's scammers will keep refining their craft, but a quick daily check costs nothing and protects everything that matters.