Aregueifa

Where does that link really lead

A link looks innocent enough. A few words in blue, a tidy web address, a familiar logo beside it, and you tap without thinking. Yet beneath the surface of that single click lies a small chain of decisions made by servers, marketers, ad networks and occasionally bad actors. The page that loads may be the one you expected, or it may be something quite different wearing a similar name.

Australia has become one of the most connected societies on the planet, with adults spending close to six hours a day online according to recent regional studies. That volume of clicking makes it easy to forget how little we know about each step between our finger and the final destination. Understanding the path is no longer just a curiosity for web developers. It is a practical skill for anyone who banks, shops, scrolls or pays a bill through a browser or smartphone.

The mechanics behind a simple click

When you tap a hyperlink, your device sends a request to a server, which then replies with the content you see. Sometimes that reply is the page itself. More often it is an instruction of the kind known as a redirect, where the server tells the browser, "actually, look over here." A single link can bounce through two, three or even five different addresses before a page finally paints on your screen.

These hops are not always sinister. Content management systems use them when a page has been renamed. News sites use them when a story moves from one section to another. Login portals rely on them to send you back to where you started after you have signed in. A redirect is, in many cases, the plumbing of a working website rather than a trick.

The trouble begins when that plumbing becomes invisible. A redirect can rewrite the address bar so that what you see at the end no longer reflects the route you travelled. It can also pass information about you along the chain, which is where tracking starts to overlap with transparency.

Tracking codes and the long string you didn't notice

Look closely at many links and you will find a tail of punctuation that has nothing to do with the article, product or page you wanted. Symbols such as ?, &, utm_, fbclid or gclid signal that the link has been decorated with a tracking parameter. Each parameter is a small label telling the destination site who sent you, which campaign you came from, what device you used and sometimes even which suburb you are browsing from.

Marketers love this data because it shows whether a campaign on a particular platform is paying off. A café in Brisbane running a promoted post can see whether clicks came from Instagram users in Queensland or from a Google search in Adelaide. Publishers rely on it to attribute revenue across multiple channels. In Australia, where digital ad spend has grown well past fifteen billion dollars a year, the practice is woven deep into commercial life.

For users, the trade-off is convenience in exchange for information. The link still works and the content still appears, but the journey has been recorded. Sites that use the same domain and simply append a query string are technically still sending you to the same place. Sites that swap the domain entirely are doing something more visible, even if the average tap rarely pauses long enough to notice.

When the label doesn't match the destination

Anchor text is the visible, clickable phrase that sits inside a link. The destination, known as the href, is the actual address it points to. They are supposed to match, and most of the time they do. Search engines have spent decades punishing sites where they do not, so the incentives for honest labelling are strong.

Mistakes and mischief still slip through. A headline promising one story can quietly point to a paid landing page. A button reading "Continue to my account" can route through an affiliate network that logs the referral before passing you on. An offer advertised in a Facebook group can lead to a domain registered only days earlier, often in a country with little connection to the brand it imitates.

Australian readers see plenty of examples. Subscription traps often use a brand name as the anchor and a lookalike domain as the address. Even genuine publishers sometimes send readers through link shorteners, which hide the destination behind a tidy bit.ly or t.co address. The result is a small but real gap between what a link promises and what it delivers. A reader hunting for fresh sports updates might find themselves passing through a redirect chain before the real page ever appears, which is why services such as latest sports news occasionally surface as plain links rather than dressed-up buttons.

Hidden redirects across Australian networks

Local infrastructure can add its own layer of surprise. The major telcos, including Telstra, Optus and TPG, have historically used transparent proxies to compress images, cache pages and filter known malicious domains. Most of the time this speeds things up. Occasionally it rewrites a request without warning, especially on older mobile connections or on captive Wi-Fi networks in places such as airports and cafés.

Public Wi-Fi in places like Melbourne's Bourke Street mall or the Sydney CBD often runs through splash pages that intercept the first request. Type a URL and you may see the venue's login screen rather than the site you wanted. Once you accept the terms, the original request resumes. It is a form of redirect, although an entirely lawful one.

More troubling are the cases that slip past filters. The Australian Cyber Security Centre regularly warns that phishing kits rotate domains quickly, sometimes every few hours, to stay ahead of blocklists. A link that was safe in the morning can be harmful by the afternoon. A redirect that looked normal yesterday can be hijacking credentials today.

Scams, phishing and the regulators watching them

Australia's regulatory environment treats misleading links seriously. The Australian Competition and Consumer Commission, through its Scamwatch portal, recorded losses of more than two billion dollars in a single recent year, with phishing and online shopping scams dominating the figures. Scamwatch publishes examples almost daily, often including the exact wording used to lure victims.

The eSafety Commissioner focuses on harmful content rather than financial fraud, but its guidance on checking links overlaps with consumer protection. The Office of the Australian Information Commissioner administers the Privacy Act 1988 and the Notifiable Data Breaches scheme, which requires organisations to tell you when your data has been exposed. Hidden redirects that quietly capture information can fall under that regime when they involve Australian companies.

Banks have also tightened their stance. The big four, Commonwealth Bank, ANZ, Westpac and NAB, will rarely include a clickable link inside an SMS. Instead they direct customers to type the address themselves or open the official app. That small habit, unglamorous as it sounds, removes most of the risk associated with disguised destinations.

Checking a link before you tap

A few habits make the journey safer without turning every click into an investigation. On a desktop, hover over the anchor text and the actual address appears in the corner of the browser. On a phone, a long press often reveals the destination in a pop-up. Reading the domain carefully, including the bit before the final dot, is the single most reliable check.

Link preview tools, built into many modern email clients and chat apps, do similar work without extra effort. They show a card with the page title, description and image before you commit. If the preview does not match the message, the link is worth a second look. Browser extensions can shorten the visible chain and flag known redirect-heavy domains, which is handy for anyone who reads newsletters or follows social media links throughout the working day.

None of this requires technical skill. It is closer to the habit of checking a street number before stepping into a building, or glancing at a taxi plate before climbing in. Links are the doorways of the modern web, and like any doorway they deserve a quick look before you walk through.