Technology in terms you understand. Sign up for the Confident Computing newsletter for weekly solutions to make your life easier. Click here and get The Ask Leo! Guide to Staying Safe on the Internet — FREE Edition as my thank you for subscribing!

Why does my anti-malware software say a link is suspected phishing?


My AT&T web mail says this is a suspected phishing site in
regards to your newsletter. I still open and read it. Why would they
suspect a forged address?

Unfortunately, there’s a very legitimate way to craft links that also
happens to be easily confused with a technique used by phishing

It’s a difficult position for both the publisher, such as myself,
who wants to gather information, and the anti-malware software that
doesn’t want to inadvertently miss an actual phishing attempt. By
erring on the side of paranoia, the anti-malware software often reports
“false positives” – links that are “suspected” of being phishing
attempts, but really aren’t.

Let’s look at this in more detail, and how you can tell the


First, we need to understand just what a phishing attempt really is: it’s an attempt to make you think you’re about to visit legitimate site “A”, when in fact you’re about to be tricked into visiting some questionable site “B”.

Here’s an example I’ve used before:

It looks like that’ll take you eBay, doesn’t it? But by now, you can guess that it won’t. It’ll take you someplace else entirely. In most browsers, if you hover the mouse pointer over that link, you’ll see in the browser’s status line exactly where it will take you.

“You should always check the status line before taking links you’re not 100% sure of.”

You should always check the status line before taking links you’re not 100% sure of. Phishing? What’s Phishing? has more guidelines to stay safe.

This leads us to the first technique used to possibly identify phishing attempts: if the link looks like one URL, but in fact would take you to another URL, that’s suspect.

But not perfect.

The problem is that there are very legitimate reasons that this might be the case.

Let’s look at this example:

That link looks like it will take you to, and in fact it will. But if you hover over the link, it won’t show at all … it shows Since they don’t match, anti-phishing tests might label this as a suspected phishing attempt, even though it’s not.

Now the question you should be asking yourself is why would I send you to via a link that is off of my own domain? The answer is: so that I can tell that you went there.

“Click Tracking” allows publishers such as myself to gauge what’s popular and useful, and allows us to get a better feel for just how well we’re doing. It’s not used to track you specifically, but rather to see how many people are clicking on any given link. Without that “redirection” through I wouldn’t be able to tell how many people were finding that link to of interest.

For example, I can tell you that as I write this, 30 people clicked on a link to from my site in the last week. I have no idea who they are, but I don’t care – it’s the aggregate information that’s most useful. I can also tell you that it pales in comparison to the 1,735 people that clicked on the link to TweakUI, or the 996 people that clicked on a link to the PowerPoint Viewer in that same timeframe.

That’s additional data to help tell me what my visitors think is important.

But collecting it can confuse anti-phishing tools.

Which brings me to the newsletter and email in general.

Using click tracking on a website isn’t all that common; although it is certainly possible, legitimate and ultimately benign. Using click tracking in email is extremely common.

Once again, using click tracking legitimately allows publishers to understand whether they’re giving their recipients what they want. For example, if I send out a newsletter and no one clicks on any of the links – well, that must’ve been an pretty poor newsletter, and that’s something I need to know. On the other hand, if a specific bit of information is extremely popular, that’s good for me to know as well, as I can then tailor more or include additional content to meet that apparent interest.

But, as you’ve seen, that data collection effort can result in false-positive phishing warnings, as the links you see might not exactly match the links you’ll be routed through.

(As an aside specifically for Ask Leo! newsletter subscribers, links will typically route through, or a subdomain off of Ads may route through other domains that I will have vetted prior to publication.)

Lastly, this technique can be used several legitimate purposes:

  • Click tracking: as discussed above.

  • URL Shortening: services like and work in exactly this same fashion.

  • Change Protection: sometimes URLs change and pages move. Using a redirection as we’ve discussed here allows the target of the redirection to be changed in exactly one place.

So definitely pay attention to the warnings your anti-malware software is throwing at you, but don’t assume that it’s always correct. Use some common sense, and some knowledge, to gauge yourself if what you’re about to click on is legitimate or not.

Do this

Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.

I'll see you there!

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.