What to do after clicking a suspicious link
Immediate steps if you clicked a link or entered information on a suspicious page.
By AlertaSpam Security Team. Published August 7, 2026
Clicking a bad link is common, and panicking makes it worse. What matters most is not that you clicked, but what happened after — did you just land on a page, or did you type something into it. The steps below are ordered by how much you actually did, from least to most serious.
Warning signs it was actually malicious
- The page asked for a password, one-time code, or card number immediately, before showing any real content.
- Your device slowed down, showed new pop-ups, or a browser extension appeared that you didn't install.
- The page tried to auto-download a file, or prompted you to 'enable' something to continue.
- The URL in your address bar isn't the domain you expected, even if the page visually looked right.
Step-by-step
- Close the page immediately. Don't interact with any further prompts on it.
- If you only viewed the page and entered nothing: run a security scan if your device offers one, and look up the domain on AlertaSpam to see what's known about it.
- If you entered a password: change it right away, but on the real site — typed by hand or via a bookmark you already trust, never through the suspicious link again. Change it anywhere else you reused it too.
- If you entered a one-time code or approved a push notification: assume the account may already be accessed. Check its recent login activity and sign out of sessions you don't recognize.
- If you entered payment details: contact your bank or card issuer immediately to flag the card and watch for unauthorized transactions.
- Turn on two-factor authentication on the affected account if you hadn't already — it's the single change that helps most after a password is exposed.
- Report the link on AlertaSpam so others researching the same domain or link see your experience reflected in its history.
What not to do
- Don't click the same link again 'to check if it's real' — use the link checker instead, which never opens it on your device.
- Don't wait to see if anything bad happens before changing a password you entered — change it first, regardless.
- Don't ignore a reused password just because the account itself seems fine — the same credentials may already be for sale for other accounts.
Frequently asked questions
I clicked the link but the page never loaded — am I safe?
Usually yes, if you entered nothing and no file was downloaded. Still worth a quick security scan and checking the domain on AlertaSpam, since some pages act differently depending on your device or location.
Should I report this even if nothing seems to have happened?
Yes — a report with no financial loss still helps others recognize the same link before they click it, and AlertaSpam never treats a report as proof of anything on its own; it's one more signal among several.
