What to do after clicking a suspicious link

Immediate steps if you clicked a link or entered information on a suspicious page.

By AlertaSpam Security Team. Published August 7, 2026

Clicking a bad link is common, and panicking makes it worse. What matters most is not that you clicked, but what happened after — did you just land on a page, or did you type something into it. The steps below are ordered by how much you actually did, from least to most serious.

Warning signs it was actually malicious

  • The page asked for a password, one-time code, or card number immediately, before showing any real content.
  • Your device slowed down, showed new pop-ups, or a browser extension appeared that you didn't install.
  • The page tried to auto-download a file, or prompted you to 'enable' something to continue.
  • The URL in your address bar isn't the domain you expected, even if the page visually looked right.

Step-by-step

  1. Close the page immediately. Don't interact with any further prompts on it.
  2. If you only viewed the page and entered nothing: run a security scan if your device offers one, and look up the domain on AlertaSpam to see what's known about it.
  3. If you entered a password: change it right away, but on the real site — typed by hand or via a bookmark you already trust, never through the suspicious link again. Change it anywhere else you reused it too.
  4. If you entered a one-time code or approved a push notification: assume the account may already be accessed. Check its recent login activity and sign out of sessions you don't recognize.
  5. If you entered payment details: contact your bank or card issuer immediately to flag the card and watch for unauthorized transactions.
  6. Turn on two-factor authentication on the affected account if you hadn't already — it's the single change that helps most after a password is exposed.
  7. Report the link on AlertaSpam so others researching the same domain or link see your experience reflected in its history.

What not to do

  • Don't click the same link again 'to check if it's real' — use the link checker instead, which never opens it on your device.
  • Don't wait to see if anything bad happens before changing a password you entered — change it first, regardless.
  • Don't ignore a reused password just because the account itself seems fine — the same credentials may already be for sale for other accounts.

Frequently asked questions

I clicked the link but the page never loaded — am I safe?

Usually yes, if you entered nothing and no file was downloaded. Still worth a quick security scan and checking the domain on AlertaSpam, since some pages act differently depending on your device or location.

Should I report this even if nothing seems to have happened?

Yes — a report with no financial loss still helps others recognize the same link before they click it, and AlertaSpam never treats a report as proof of anything on its own; it's one more signal among several.