Module 06 / 15
🌐

Browsing, Clicking and Downloading SafelyUpdated: 2026

Learn to identify suspicious sites, avoid booby-trapped links, and download without risk.

⏱️ ~25 min
πŸ“š 10 lessons
🎯 Beginner
🎯 Module objective

By the end of this module, you'll be able to…

  • Read and analyze a URL to identify a site's true owner
  • Recognize the visual signs of a suspicious or fraudulent site
  • Download files without risking a malware install
  • Configure your browser's essential security settings
1

The risks of web browsing

Scenario

Marc searches for a movie on Google. He clicks the first non-ad result. The site prompts him to "update Adobe Flash to watch". He installs the update. It wasn't Adobe Flash β€” it was a Trojan.

Web browsing exposes you to several risks: fraudulent sites that steal your information, malicious downloads, booby-trapped ads (malvertising), and phishing forms. The good news: a few simple habits let you avoid the vast majority of these traps.

2

How to spot a suspicious site

βœ— Visual warning signs

  • The URL in the address bar doesn't match the site shown
  • No HTTPS padlock β€” note: the padlock alone doesn't guarantee a site is legitimate
  • Poor-quality design, spelling mistakes, blurry images
  • Aggressive pop-ups as soon as you land on the page
  • Requests for personal information with no valid reason
  • Offers too good to be true (a $1 iPhone, etc.)
ℹ️
The HTTPS padlock doesn't guarantee a site is legitimate.

A phishing site can easily have a valid HTTPS certificate. The padlock means the connection is encrypted β€” not that the site is honest. Always check the domain name.

3

Understanding URLs and domain names

The domain rule is the single most important skill in this module. In a URL, the true owner is identified by the domain β€” the part right before the first "/" after "https://".

URL analysis example:
https://rbc-security-alert.com/confirm?client=you
↑ Real domain: rbc-security-alert.com β€” NOT rbc.com β€” Fraudulent site!
https://rbc.com/security/confirm
↑ Real domain: rbc.com β€” Legitimate site βœ“

βœ“ Typosquatting techniques to know

  • Swapped letter: paypai.com instead of paypal.com
  • Added domain: rbc.security.com (the real domain is "security.com")
  • Different extension: amazon.net instead of amazon.com
  • Similar characters: googlΓ©.com with a unicode "Γ©"
4

The dangers of shortened links

Short links (bit.ly, tinyurl.com, etc.) hide the real destination. A shortened link can lead you anywhere β€” legitimate or malicious β€” without you being able to tell before clicking.

βœ“ How to check a short link

  • Add a "+" to the end of a bit.ly link to see the destination (e.g., bit.ly/xxx+)
  • Use checkshorturl.com or unshorten.it to check before clicking
  • On mobile, press and hold the link to see the full URL
  • If in doubt, don't click β€” look for the information directly on the official site
5

Safe downloads

βœ“ Safe download rules

  • Download from the manufacturer's official site β€” not third-party sites or search engines
  • Be wary of "Download" buttons that don't match what you're looking for
  • Check the extension: a .exe or .dmg file downloaded from an email is almost always suspect
  • Scan with your antivirus before running any downloaded file
  • For free software: read the reviews, and uncheck bundled extra software during install

βœ— Sites to avoid for downloads

  • Sites offering paid software for free ("cracks", "keygens")
  • Unofficial mirror sites hosting popular software
  • Torrent sites for commercial software
6

Attachments β€” vigilance and best practices

Attachments are one of the most common infection vectors. The basic rule: never open an attachment you weren't expecting, even if it appears to come from someone you know.

βœ— Particularly risky file types

  • .exe, .msi, .bat, .cmd β€” Windows executables
  • .docm, .xlsm β€” Office documents with macros (only enable macros if you're certain)
  • .iso, .img β€” disk images that can contain malicious programs
  • .zip, .rar containing executable files
  • .pdf with active JavaScript (rare but possible)
Key takeaway"I wasn't expecting this file β†’ I don't open it without checking."
7

Essential browser security settings

βœ“ Settings to check in Chrome/Firefox/Edge/Safari

  • Enable automatic browser updates
  • Enable "Safe Browsing" β€” offered by Chrome and Firefox
  • Disable pop-ups: Settings β†’ Privacy β†’ Pop-up blocking
  • Review installed extensions β€” remove anything you don't use or didn't install yourself
  • Enable "Ask before accessing" for microphone, camera, and location
8

Browser extensions β€” opportunities and risks

Browser extensions have access to everything you do online β€” sites visited, forms filled out, sometimes passwords. A malicious extension is malware in its own right.

βœ“ Good security extensions

  • uBlock Origin β€” ad and tracker blocker (open source, free)
  • Bitwarden β€” password manager (official, open source)
  • HTTPS Everywhere β€” forces HTTPS (built into modern browsers)

βœ— Signs of a dangerous extension

  • It asks for access to "all websites" for no apparent reason
  • Few reviews, unknown publisher, store URL outside the official Chrome/Firefox Store
  • It was installed without you remembering doing so
9

Safe online shopping

βœ“ Golden rules for online shopping

  • Check the URL β€” you're really on amazon.ca, not amazon-promo.net
  • Look up the seller's reviews (Google + a third-party site like Trustpilot)
  • Pay by credit card (protected) rather than debit or wire transfer
  • Be wary of offers too good to be true
  • Avoid shopping over unsecured public Wi-Fi
  • Check your bank statement after every online purchase
10

Checks to make before any action

Before clicking a link, opening a file, or filling out a form, ask yourself these 4 questions:

❓
Was I expecting this?

If not, be wary β€” especially for attachments and links.

πŸ”
Is the domain exact?

Check the URL β€” not just the displayed name.

⚑
Is there artificial urgency?

Urgency is a manipulation tool β€” slow down.

πŸ’¬
Can I check another way?

Go directly to the official site or call the organization.

Interactive demo

URL Inspector β€” Legitimate or suspicious?

Simulated example for educational purposes β€” the brands mentioned are not affiliated with ObjectifCyber.

Analyze each URL. Click "Legitimate" or "Suspicious" for each, then read the explanation.

https://paypaI.com/secure/login
https://desjardins.com/accesD/authentification
https://amazon.ca.promo-deals.net/offer
https://www.canada.ca/en/revenue-agency/
http://montreal-wine-shop.com/checkout

Module quiz

Test what you've learned with 4 questions.

See also