Browsing, Clicking and Downloading SafelyUpdated: 2026
Learn to identify suspicious sites, avoid booby-trapped links, and download without risk.
By the end of this module, you'll be able toβ¦
- Read and analyze a URL to identify a site's true owner
- Recognize the visual signs of a suspicious or fraudulent site
- Download files without risking a malware install
- Configure your browser's essential security settings
The risks of web browsing
Marc searches for a movie on Google. He clicks the first non-ad result. The site prompts him to "update Adobe Flash to watch". He installs the update. It wasn't Adobe Flash β it was a Trojan.
Web browsing exposes you to several risks: fraudulent sites that steal your information, malicious downloads, booby-trapped ads (malvertising), and phishing forms. The good news: a few simple habits let you avoid the vast majority of these traps.
How to spot a suspicious site
β Visual warning signs
- The URL in the address bar doesn't match the site shown
- No HTTPS padlock β note: the padlock alone doesn't guarantee a site is legitimate
- Poor-quality design, spelling mistakes, blurry images
- Aggressive pop-ups as soon as you land on the page
- Requests for personal information with no valid reason
- Offers too good to be true (a $1 iPhone, etc.)
A phishing site can easily have a valid HTTPS certificate. The padlock means the connection is encrypted β not that the site is honest. Always check the domain name.
Understanding URLs and domain names
The domain rule is the single most important skill in this module. In a URL, the true owner is identified by the domain β the part right before the first "/" after "https://".
β Typosquatting techniques to know
- Swapped letter: paypai.com instead of paypal.com
- Added domain: rbc.security.com (the real domain is "security.com")
- Different extension: amazon.net instead of amazon.com
- Similar characters: googlΓ©.com with a unicode "Γ©"
The dangers of shortened links
Short links (bit.ly, tinyurl.com, etc.) hide the real destination. A shortened link can lead you anywhere β legitimate or malicious β without you being able to tell before clicking.
β How to check a short link
- Add a "+" to the end of a bit.ly link to see the destination (e.g., bit.ly/xxx+)
- Use checkshorturl.com or unshorten.it to check before clicking
- On mobile, press and hold the link to see the full URL
- If in doubt, don't click β look for the information directly on the official site
Safe downloads
β Safe download rules
- Download from the manufacturer's official site β not third-party sites or search engines
- Be wary of "Download" buttons that don't match what you're looking for
- Check the extension: a .exe or .dmg file downloaded from an email is almost always suspect
- Scan with your antivirus before running any downloaded file
- For free software: read the reviews, and uncheck bundled extra software during install
β Sites to avoid for downloads
- Sites offering paid software for free ("cracks", "keygens")
- Unofficial mirror sites hosting popular software
- Torrent sites for commercial software
Attachments β vigilance and best practices
Attachments are one of the most common infection vectors. The basic rule: never open an attachment you weren't expecting, even if it appears to come from someone you know.
β Particularly risky file types
- .exe, .msi, .bat, .cmd β Windows executables
- .docm, .xlsm β Office documents with macros (only enable macros if you're certain)
- .iso, .img β disk images that can contain malicious programs
- .zip, .rar containing executable files
- .pdf with active JavaScript (rare but possible)
Essential browser security settings
β Settings to check in Chrome/Firefox/Edge/Safari
- Enable automatic browser updates
- Enable "Safe Browsing" β offered by Chrome and Firefox
- Disable pop-ups: Settings β Privacy β Pop-up blocking
- Review installed extensions β remove anything you don't use or didn't install yourself
- Enable "Ask before accessing" for microphone, camera, and location
Browser extensions β opportunities and risks
Browser extensions have access to everything you do online β sites visited, forms filled out, sometimes passwords. A malicious extension is malware in its own right.
β Good security extensions
- uBlock Origin β ad and tracker blocker (open source, free)
- Bitwarden β password manager (official, open source)
- HTTPS Everywhere β forces HTTPS (built into modern browsers)
β Signs of a dangerous extension
- It asks for access to "all websites" for no apparent reason
- Few reviews, unknown publisher, store URL outside the official Chrome/Firefox Store
- It was installed without you remembering doing so
Safe online shopping
β Golden rules for online shopping
- Check the URL β you're really on amazon.ca, not amazon-promo.net
- Look up the seller's reviews (Google + a third-party site like Trustpilot)
- Pay by credit card (protected) rather than debit or wire transfer
- Be wary of offers too good to be true
- Avoid shopping over unsecured public Wi-Fi
- Check your bank statement after every online purchase
Checks to make before any action
Before clicking a link, opening a file, or filling out a form, ask yourself these 4 questions:
If not, be wary β especially for attachments and links.
Check the URL β not just the displayed name.
Urgency is a manipulation tool β slow down.
Go directly to the official site or call the organization.
URL Inspector β Legitimate or suspicious?
Simulated example for educational purposes β the brands mentioned are not affiliated with ObjectifCyber.
Analyze each URL. Click "Legitimate" or "Suspicious" for each, then read the explanation.
https://paypaI.com/secure/login
https://desjardins.com/accesD/authentification
https://amazon.ca.promo-deals.net/offer
https://www.canada.ca/en/revenue-agency/
http://montreal-wine-shop.com/checkout
Module quiz
Test what you've learned with 4 questions.
See also