← Back to Knowledge Center
KNOWLEDGE CENTER

Website Verification: Check the Destination

Network & Internet Securityen-NG
BEFORE YOU BEGIN

Understand the issue before you decide what to do.

This lesson is designed to explain the subject in practical terms so that you can understand not only what the risk is, but why it matters, how it can appear in real situations and what you can do to reduce your exposure.

Read the explanation carefully before acting on a suspicious message, request, transaction, account notification or other security-related situation.

FULL LESSON

Understanding the subject

Take your time with this explanation. The goal is not simply to recognise a warning sign, but to understand what is happening and make a safer decision when you encounter it.

A website is a destination, not proof.

A message can contain a familiar logo, a company name, a professional design or a link that looks almost exactly like one you know. What matters is where the link actually takes you and whether that destination is the legitimate service you intended to use.

Before entering a password, OTP, payment details, card information, recovery information or sensitive personal data, verify the destination.

The core habit is:

PAUSE → READ → IDENTIFY → CHECK → VERIFY → THEN ACT

1. WHAT WEBSITE VERIFICATION REALLY MEANS

Website verification means checking that the destination you are about to use is the legitimate service you intended to reach.

It is not simply asking:

"Does this page look real?"

Instead ask:

  • What exact domain am I on?
  • Who operates this domain?
  • Why did I arrive here?
  • Did I find this destination independently?
  • Does the destination match the organisation I intended to contact?
  • Is the request on the page consistent with the service?
  • Does independent evidence support the destination?

A convincing page can still be fraudulent.

2. WHY APPEARANCE IS NOT ENOUGH

Modern phishing pages can copy:

  • Logos
  • Colours
  • Fonts
  • Login layouts
  • Security language
  • Customer-support messages
  • Payment screens
  • Names of real organisations

A page may therefore look familiar while the destination is controlled by someone else.

Visual similarity is a clue, not proof.

3. THE DESTINATION IS THE IMPORTANT PART

When someone sends you a link, the message is not the destination.

The destination is the website your browser actually opens.

For sensitive actions, inspect the address shown by the browser.

Look beyond the first familiar word you see.

For example, an address might contain a trusted brand name somewhere inside a much larger domain. That does not automatically make the organisation the owner of the domain.

Slow down and identify the actual domain.

4. LEARN TO READ A DOMAIN

A domain can contain several parts.

EXAMPLE

secure.example.com

The important registered domain is example.com.

A different address such as:

example.com.security-check.example.net

is not the same destination.

The presence of the words "example.com" somewhere in the address does not make it an official example.com website.

5. LOOK FOR LOOKALIKE DOMAINS

Attackers may register domains that resemble legitimate organisations.

Examples of suspicious differences can include:

  • One extra letter
  • One missing letter
  • A substituted character
  • A different word added to the domain
  • A different top-level domain
  • Hyphenated versions designed to resemble the original
  • A domain using a familiar brand name with an unrelated ending

A tiny difference can change who controls the destination.

6. SUBDOMAINS CAN BE MISLEADING

A common mistake is seeing a trusted organisation's name at the beginning of an address and assuming the whole domain belongs to that organisation.

EXAMPLE

bank.example-security.com

does not mean the bank owns example-security.com.

Read the address from the right side of the relevant domain structure and identify the actual registered domain.

7. HTTPS IS NOT PROOF OF LEGITIMACY

A secure connection is useful, but HTTPS does not prove that a website belongs to the organisation you expect.

A fraudulent website can also use HTTPS.

Therefore:

HTTPS = encrypted connection

HTTPS ≠ proof that the website is legitimate

Do not stop verification simply because the browser shows a padlock or secure connection.

8. THE PADLOCK IS NOT A TRUST CERTIFICATE

The browser's security indicator tells you something about the connection.

It does not tell you:

  • Who created the website
  • Whether the organisation is genuine
  • Whether the offer is legitimate
  • Whether the page is phishing
  • Whether the person who sent the link is trustworthy

Use the address and independent verification as part of the decision.

9. DO NOT TRUST A LINK BECAUSE THE MESSAGE LOOKS OFFICIAL

A message may contain:

  • A bank logo
  • A government logo
  • A company signature
  • A familiar name
  • A professional footer
  • An official-looking sender name

None of these proves that the supplied link is genuine.

Treat the link and the message as separate things to verify.

10. FIND THE OFFICIAL WEBSITE YOURSELF

For sensitive services, one of the safest habits is to avoid using the supplied link when independent verification is practical.

Instead:

  1. Open your browser yourself.
  2. Search for or enter the organisation's known official website.
  3. Confirm the correct domain.
  4. Navigate to the service from that official site.
  5. Compare the destination with the one you were sent.

This removes the supplied link from being your only source of truth.

11. USE A CONTACT CHANNEL YOU ALREADY TRUST

If the website concerns a bank, payment service, employer, government programme or business transaction, use an independently known contact method when necessary.

Do not use only the phone number or email address contained in the suspicious message.

Find the contact details from the organisation's established official website or another trusted source.

12. VERIFY THE PURPOSE OF THE LINK

Ask:

Why am I being sent this link?

Is it for:

  • Login?
  • Payment?
  • Account recovery?
  • Identity verification?
  • Grant registration?
  • Job application?
  • Delivery confirmation?
  • Password reset?
  • Document download?

A legitimate organisation may use links for these purposes.

The important question is whether this particular request is genuine.

13. MATCH THE DESTINATION TO THE PURPOSE

Suppose a message says it is from your bank.

The link takes you to a website with an unrelated domain.

That mismatch matters.

Suppose a supposed government programme directs you to a domain unrelated to the relevant government organisation.

That mismatch matters.

Suppose a company recruiter directs you to a personal-looking domain to upload identity documents.

That mismatch matters.

The destination should make sense for the organisation and the action requested.

14. NEVER ENTER SECRETS JUST TO "CHECK" A SITE

Do not test a suspicious website by entering:

  • Your password
  • OTP
  • PIN
  • Card details
  • Recovery code
  • Wallet recovery phrase
  • Security questions
  • Full identity information

Verification should happen before you disclose sensitive information.

15. PASSWORD MANAGER AUTOFILL CAN BE A WARNING SIGNAL

If you normally use a password manager, pay attention when your credentials do not autofill on a site where you expected them to.

This is not proof that the website is malicious.

It can be a useful reason to stop and inspect the destination.

Do not manually enter the password simply because autofill did not work.

16. BE CAREFUL WITH LOGIN LINKS

Login pages are especially valuable to attackers because they can capture credentials.

When a message says:

"Your account needs verification."

"Your password expires today."

"Unusual activity was detected."

"Click here to secure your account."

Do not let the message determine your destination.

Open the service independently and check for the claimed issue there.

17. BE CAREFUL WITH PASSWORD RESET LINKS

Password-reset messages deserve special attention.

If you did not request a reset, do not automatically click the link.

Open the service independently and check the account.

If you did request the reset, still confirm that the message and destination correspond to the service you intended to use.

18. BE CAREFUL WITH PAYMENT PAGES

A payment page can look completely professional and still be fraudulent.

Before entering card details or approving a payment:

  • Verify the organisation
  • Verify the domain
  • Confirm the amount
  • Confirm what you are paying for
  • Check whether the payment request is expected
  • Use an independently verified route where possible

Do not treat a polished payment screen as proof.

19. BE CAREFUL WITH BANKING LINKS

If you receive a banking link by SMS, email or messaging app, do not assume it is safe because the message mentions your bank.

For sensitive banking activity, open the bank's official app or official website yourself.

If the bank says there is an issue, verify it through the bank's established support channel.

20. BE CAREFUL WITH GOVERNMENT LINKS

Government branding can be copied.

If a message claims you must visit a government website to:

  • Receive a grant
  • Register for a programme
  • Confirm identity
  • Receive a payment
  • Apply for assistance
  • Update records

Find the relevant government organisation independently and confirm the programme and official website.

21. BE CAREFUL WITH JOB AND RECRUITMENT LINKS

Recruitment scams may send candidates to forms or portals that appear professional.

Before uploading:

  • Identity documents
  • Bank information
  • Passport photographs
  • Certificates
  • Login credentials

verify the employer, vacancy and application destination independently.

A real job opportunity still requires destination verification.

22. BE CAREFUL WITH DELIVERY AND PACKAGE LINKS

A message may claim:

"Your parcel is waiting."

"Pay the delivery fee."

"Confirm your address."

"Track your package here."

Do not let the existence of a delivery you actually expect remove your caution.

Find the delivery company independently and use its official tracking or support route.

23. BE CAREFUL WITH SOCIAL MEDIA ADVERTISEMENTS

An advertisement can lead to a website that looks professional.

The fact that it appeared on a major platform does not automatically establish that the destination is legitimate.

Before entering payment or identity information, verify the business and destination independently.

24. SHORTENED LINKS NEED EXTRA CARE

Shortened links can hide the final destination.

They are not automatically malicious, but they make visual inspection harder.

For sensitive actions, it is better to navigate to the organisation independently rather than relying on an unfamiliar shortened link.

25. QR CODES ARE ALSO LINKS

A QR code does not become trustworthy simply because you scanned it instead of tapping a URL.

A QR code can direct you to a fraudulent website just like a normal link.

After scanning, inspect the destination before entering sensitive information.

26. CHECK THE DOMAIN BEFORE YOU SIGN IN

Make this a routine:

STOP before entering credentials.

LOOK at the address.

IDENTIFY the actual domain.

COMPARE it with the organisation's legitimate domain.

VERIFY through an independent source.

ONLY THEN continue.

27. DO NOT LET SEARCH RESULTS DO ALL THE VERIFICATION

Search engines can help you find an organisation's website, but advertisements and misleading results can sometimes appear before the result you expected.

Check the domain carefully.

For high-risk actions, use a known official address, bookmark, official app or independently established route when available.

28. BOOKMARK IMPORTANT SERVICES

For services you use regularly, consider using:

  • A trusted bookmark
  • The official mobile application
  • A manually verified address
  • A password manager's verified domain association

This can reduce reliance on links received through messages.

Keep bookmarks updated and verify them when necessary.

29. USE THE VERIFY BEFORE YOU TRUST ANALYZER AS AN ADDITIONAL CHECK

The platform's Analyzer can provide another signal when you are evaluating a URL.

Use it as an additional verification layer, not as permission to ignore obvious warning signs.

A tool result does not replace basic judgment.

For sensitive actions, combine:

  • Destination inspection
  • Independent verification
  • Context checking
  • Appropriate technical checks

30. A URL SCAN IS NOT THE SAME AS TRUST

A tool may identify known indicators, but no automated result should be interpreted as a guarantee that a website is safe for every possible purpose.

If the domain is unexpected, the request is suspicious, or the organisation cannot be independently verified, stop.

31. WATCH FOR PRESSURE

Website scams often create urgency:

"Act now."

"Your account will close."

"Your payment will fail."

"Your opportunity expires today."

"Confirm within 10 minutes."

"Your parcel will be returned."

Urgency is not evidence.

Slow down enough to verify the destination.

32. WATCH FOR SECRECY

Be cautious when someone says:

"Do not tell anyone."

"Use this special link."

"Do not open the official website."

"Only this link will work."

"Do not contact support."

A legitimate process should not normally require you to abandon independent verification.

33. WATCH FOR DESTINATION MISMATCHES

Stop when:

  • The organisation name does not match the domain
  • The domain looks newly or unusually constructed
  • The page redirects through unexpected domains
  • The link destination differs from what the message describes
  • The website requests information unrelated to its stated purpose
  • The sender insists you use the supplied link
  • The page asks for secrets that the service normally does not require

One warning sign may deserve investigation. Several together should increase caution significantly.

34. REAL EXAMPLE: BANK ACCOUNT ALERT

You receive:

"Your account has been restricted. Click here to restore access."

The message contains the bank's logo.

Do not click and enter your password.

Open your bank's official app or official website yourself.

If there is a genuine restriction, you should be able to investigate it through the bank's trusted channel.

35. REAL EXAMPLE: FAKE PAYMENT PAGE

A seller sends a payment link and says:

"Pay here quickly so I can reserve the item."

Before paying, confirm:

  • The seller
  • The business
  • The destination
  • The amount
  • The payment method

If the payment page belongs to an unexpected domain, stop and verify.

36. REAL EXAMPLE: PASSWORD RESET MESSAGE

You receive an unexpected password-reset message.

Do not use the supplied link.

Open the service yourself and check your account.

If you did not request a reset, review the account's security activity and follow the service's official security guidance.

37. REAL EXAMPLE: GOVERNMENT GRANT

A social-media message claims you qualify for a government intervention programme and provides a registration link.

Do not trust the government logo.

Find the responsible government organisation independently.

Confirm the programme, official domain and application process before entering information.

38. REAL EXAMPLE: JOB APPLICATION PORTAL

A recruiter sends a link to upload your NIN, bank details and identity documents before an interview.

Do not upload the documents simply because the page looks professional.

Verify the employer, vacancy, recruiter and application portal independently.

39. REAL EXAMPLE: DELIVERY MESSAGE

You receive a message saying your parcel cannot be delivered until you confirm your address through a link.

Instead of using the supplied link, find the delivery company's official website yourself and verify the tracking information.

40. REAL EXAMPLE: SOCIAL MEDIA PROMOTION

An advert promises an unusually cheap product and links to a professional-looking store.

Before paying:

  • Check the exact domain
  • Verify the business independently
  • Look for established contact information
  • Confirm the payment destination
  • Consider whether the offer makes sense

Do not let a discount create urgency.

41. WHAT TO DO WHEN YOU CANNOT VERIFY THE DESTINATION

If you cannot establish that the website is legitimate:

Do not sign in.

Do not enter payment information.

Do not enter OTPs.

Do not upload identity documents.

Do not provide recovery information.

Do not download software from it.

Leave the page and use an independently verified route.

Uncertainty is a reason to pause, not a reason to proceed.

42. WHAT TO DO IF YOU ALREADY ENTERED INFORMATION

If you entered a password, payment information or another sensitive secret into a suspicious website, respond quickly.

Depending on what was exposed:

  • Change the affected password through the legitimate service
  • Review active sessions
  • Enable or strengthen MFA
  • Contact your bank or payment provider through its official channel if financial information was exposed
  • Monitor relevant accounts
  • Preserve useful evidence
  • Report the suspicious site or incident through appropriate channels

Do not use the suspicious website's own "support" link to fix the problem.

43. DO NOT LET A SECOND MESSAGE TRIGGER A SECOND SCAM

After someone interacts with a phishing website, criminals may send follow-up messages claiming to offer:

  • Account recovery
  • Refunds
  • Technical support
  • Security assistance
  • Compensation

Verify anyone offering help independently.

The original incident does not make the follow-up contact trustworthy.

44. WEBSITE VERIFICATION TEST

Before entering sensitive information, ask:

  1. WHERE AM I?

What is the exact domain?

  1. WHO OWNS THE DESTINATION?

Does the domain correspond to the organisation I intend to use?

  1. WHY AM I HERE?

What brought me to this page?

  1. WHAT AM I BEING ASKED TO DO?

Login, pay, upload documents, download software or provide information?

  1. DID I FIND IT INDEPENDENTLY?

Could I reach the same service through the organisation's official website or app?

  1. DOES THE REQUEST MAKE SENSE?

Is the information being requested appropriate for the stated purpose?

  1. HAVE I CHECKED THE SIGNALS?

Have I inspected the domain and, where appropriate, used an additional verification tool?

If important answers remain unclear, stop.

45. THE FIVE-SECOND DESTINATION CHECK

Before a sensitive action, make the following pause:

LOOK → READ → COMPARE → VERIFY → ACT

LOOK at the address.

READ the actual domain.

COMPARE it with the organisation's legitimate destination.

VERIFY independently.

ACT only when the evidence supports the destination.

46. COMMON MISTAKES

Mistake 1: "It has HTTPS."

HTTPS protects the connection. It does not prove who owns the website.

Mistake 2: "The logo looks exactly right."

A logo can be copied.

Mistake 3: "The message came from someone I know."

Their account may be compromised, or the message may have been forwarded.

Mistake 4: "Google showed me the website."

Search results still require domain verification.

Mistake 5: "The website has a padlock."

A padlock is not proof of legitimacy.

Mistake 6: "The domain contains the bank's name."

The trusted name may appear in a larger unrelated domain.

Mistake 7: "The page knows my name."

Personal details can be obtained from many sources and do not prove the destination is legitimate.

Mistake 8: "The site looks professional."

Professional design is easy to imitate.

47. A ROUTINE FOR EVERY HIGH-RISK LINK

Use:

PAUSE → OPEN INDEPENDENTLY → INSPECT DOMAIN → MATCH PURPOSE → VERIFY ORGANISATION → CHECK REQUEST → USE ADDITIONAL TOOLS → ACT

This routine is especially useful for:

  • Banking
  • Payments
  • Email accounts
  • Social media
  • Government services
  • Job applications
  • Shopping
  • Crypto services
  • Password resets
  • Identity verification

48. YOUR PERSONAL WEBSITE-SAFETY RULE

For routine browsing, you may encounter many links every day.

For high-risk actions, adopt a stronger rule:

Do not enter sensitive information into a destination you have not independently verified.

This single habit reduces the chance that a convincing message will decide where you disclose your information.

49. NIGERIAN CONTEXT

Website-based scams in Nigeria can arrive through SMS, WhatsApp, social media, email and online advertisements.

A message may imitate:

  • A bank
  • A government programme
  • A telecommunications provider
  • A recruitment organisation
  • A delivery company
  • A payment service
  • An online investment platform
  • A familiar business

The communication channel may be familiar.

The destination still needs to be verified.

When money, identity information, credentials or account access are involved, independently finding the organisation's official destination is often safer than following a received link.

50. FINAL WEBSITE VERIFICATION CHECKLIST

Before entering sensitive information:

☐ I checked the exact web address.

☐ I identified the actual domain.

☐ I did not rely only on the logo or page design.

☐ I understand why I am on this page.

☐ I independently verified the organisation when appropriate.

☐ I compared the destination with the organisation's legitimate website or app.

☐ I checked whether the request makes sense.

☐ I did not treat HTTPS or the padlock as proof of legitimacy.

☐ I did not enter passwords, OTPs or payment information just to test the site.

☐ I used the VERIFY BEFORE YOU TRUST Analyzer where appropriate as an additional check.

☐ If I could not verify the destination, I stopped.

THE WEBSITE VERIFICATION HABIT

Do not think:

"The page looks official."

Think:

"Where am I? Who controls this destination? How do I know?"

Then:

LOOK → READ → COMPARE → VERIFY → ACT

A familiar brand can be copied.

A convincing page can be fake.

A secure connection can still lead to the wrong destination.

VERIFY BEFORE YOU TRUST.

APPLY WHAT YOU LEARNED

Turn understanding into a security habit.

Knowing the definition is only the beginning. The real value of cybersecurity education is being able to recognise the situation and make a safer decision when it happens to you.

How should you use what you learned?

Understanding a cybersecurity concept is useful only when it changes how you make decisions. When you encounter a similar situation in real life, slow down and identify what is being requested before you respond.

Ask yourself who is making the request, what they are asking you to do, what information or access is involved, and whether the request can be independently verified.

Do not allow urgency, fear, authority, familiarity or the promise of a reward to replace independent verification.

What if I still do not understand something?

Cybersecurity concepts can sometimes involve technical terms or situations that are difficult to interpret from a single lesson. If something is unclear, do not guess when the decision could affect your money, identity, account access, device or sensitive information.

You can seek further guidance through the consultancy channel. Explain the situation clearly, but never include passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A convincing message, familiar name, professional appearance or urgent request is not proof of legitimacy. Verify the important facts independently before taking an action that could be difficult to reverse.