A Google Docs phishing link may look like a shared file but open a copied sign-in page, request unnecessary app access or send you to a download outside Google. If you were not expecting the share, check Google Drive directly before opening it.
This guide shows a realistic example, specific warning signs, recovery steps and official reporting routes.
Last reviewed: 18 July 2026. Author: ScanLens. Source review: official guidance listed below.
Do not open it from the email if you do not recognise the sender, the file title is alarming, or the message asks you to sign in again through an unexpected page. Go to Google Drive manually and check sharing activity from there.
Never click suspicious links directly. The safest move is to copy the URL and scan it first with a phishing link checker or scam URL scanner.
This article page does not run direct API scans because public scanning requires verification. Clicking the button opens the main ScanLens web scanner, where you can check if a link is safe before opening it.
Google provides help pages for reporting abusive Docs, Drive files and suspicious account activity. Use the official Google Help links if you need account recovery or want to report a specific document.
If a message says your account has a problem, never solve it through the link inside the message. Go to the official site manually or use a scanner first.
Even a safe-looking domain can be used for redirection, imitation, or social engineering.
Example: "Payroll document shared with you - review before 5pm" followed by a button labelled Open in Docs. The button leads to a lookalike sign-in page on an unrelated domain.
A familiar Google logo does not prove the destination is Google. Check the address bar and open Drive directly.
This guide is part of the Account scams hub. Use the category page to compare similar scams and warning signs.
View Account scamsCheck the destination without opening it, confirm the sender separately and look for the file by opening Google Drive directly. A sign-in request should use an expected Google domain.
Change it from the real Google Account page, review security activity and sessions, and remove third-party access you do not recognise.
ScanLens can check suspicious URLs, highlight risky patterns, and give you a fast verdict before you open a link.
Browse all scam types in one place.
View all scam examples