Mouse-Over: The Most Important Internet Skill!

A great many of the scams that pour into our email in-boxes can be exposed by the simplest of techniques… a “mouse-over

A mouse-over is the practice of placing your mouse over any link WITHOUT clicking it. Every web browser, and nearly all email, instant message programs and other applications, will show you where that link really leads to by showing the address (called a URL) in the lower left corner of the window. (However, this does not happen on phones or iPads! Mousing-over on these devices is not easy and comes with risks.)

Look at these examples.  In each case, the link in the email said one thing but a mouse-over revealed something entirely different. For example, in this first email, the link in the email shows you that it points to usps.com, the United States Postal Service. But when we placed our mouse over that link, without clicking, look at what was displayed in the lower left corner of that screenshot! It doesn’t point to usps.com!

Here’s another example. This email misleads the recipients into believing it came from the US Social Security Administration (ssa.gov). However, this email came from a scammer’s domain called mysocialsecurityupdatealerts[.]com.  When we moused-over both of the links in this email, such as “View Your Secure Message,” we discovered that the link would NOT send us to ssa.gov! It was designed to send us to a scammer’s domain called stateclaim-ssacloudportal[.]com. Not a safe link to click!

It is so easy to disguise links that appear in our emails, in our web browsers, and even in instant/direct messages in our apps. It is also remarkably easy to disguise links that appear within applications like Skype and Instagram, or within chat windows on social networking sites.

Try this test of your mouse-over skills. Which of the following four links, actually points to the location suggested by the link text?

  1. www.cnn.com
  2. www.americanexpress.com
  3. www.facebook.com
  4. www.bankofamerica.com

Hopefully you now see how easy it is to mouse-over and look at the destination of a link BEFORE you click it.  Make it a habit to always mouse-over before clicking.

Sometimes, deciphering links gets a bit trickier but some common sense can help you figure out what is likely to be safe and what is very risky!  Try mousing-over these choices and figure out which lead to the legitimate website and which do not:

  1. www.paypal.com
  2. www.ups.com
  3. www.Linkedin.com
  4. www.linkedin.com

ANSWER:
Link #1 points to www.paypai.com, not paypal.com. Scam!
Link #2 points to wwwapps.ups.com/Tracking.  “wwwapps” is actually a legitimate sub-domain used by UPS for tracking packages.  This link is
legit (though it doesn’t point to any particular package being tracked).
Link #3 points to bounce.linkedin.com. “bounce” is a also a legitimate sub-domain used by LinkedIn.
Link #4 points to www.linkedln.com, not linkedin.com (L was substituted for i). Scam!

Although it takes a bit of practice to recognize legitimate links from scams, it really isn’t that hard! You can do it! Just remember that many websites use sub-domains and that’s OK. The sub-domain is the name that appears just in front of the name of the business (domain) name, and separated by a period. There can be more than one sub-domain, each separated by a period. For example, the word in bold is a subdomain: “deals.amazon.com” or “fares.aa.com” (aa = American Airlines).  Both of these are legitimate links. However, for each pair below the first address (in red) is a scam domain and the second (in blue) is legit, so look carefully!

  1. www.credit-card-support.info/americanexpress.html vs. www.travel.americanexpress.com
  2. www.Chase-Bank-Online.com/chasebank.php vs. chaseonline.chase.com
  3. www.irsgov.info vs. www.eftps.gov
  4. www.usps.com-serviceacct.us vs. store.usps.com

Now remember to mouse-over links BEFORE you click them!  Watch a video that also explains this in detail here!

NOTE: The Daily Scam works hard to protect the privacy of those who have been targeted and victimized by scammers. That is why personal information in our images is routinely blurred out.