How to Check if a Link Is Safe
A single tap on the wrong link can lead to a fake login page or a page that harvests your details. This step-by-step guide is for anyone who wants a repeatable habit for checking a link before clicking, in an email, a text, or a DM. The steps take seconds, work on both phone and computer, and catch the majority of malicious links.
How we check this: Reflects how CISA and browser-security guidance describe inspecting URLs and domains before clicking. · Last reviewed: 2026-08
Step 1, Reveal the real destination before tapping
The words in a link are just a label; they can say anything. What matters is where the link actually points. On a computer, hover your mouse over the link without clicking and read the true address that appears in the corner of the screen. On a phone, press and hold the link until a preview menu pops up showing the full URL, then dismiss it without opening.
Compare what you see to what the link claims to be. If a link labeled with your bank's name resolves to a random domain, a misspelled one, or a link-shortener you cannot see through, that mismatch is your answer. Never rely on the display text alone.
Step 2, Read the domain, not the whole URL
URLs can be long and confusing, and scammers pad them with familiar words to reassure you. The only part that determines where you actually go is the core domain, the name immediately to the left of the first single slash. In an address like account-verify.paypa1-support.example/login, the core domain is paypa1-support.com, not "paypal" or "account" or "login" tucked elsewhere in the string.
So find the domain and judge that. Words before it (subdomains like login.secure.) and everything after the slash (paths and parameters) can be set to anything and prove nothing. If the core domain is not the company's real, official one, the rest of the URL does not matter.
Step 3, Watch for lookalikes and typosquatting
Once you are reading the domain, look closely for small tricks. Typosquatting swaps or adds characters that pass at a glance, a zero for the letter O, a one for a lowercase L, an extra letter, a hyphen, or a different ending like .co instead of .com. Others attach the real brand as a subdomain of a domain they own, so the familiar name appears but the true domain is something else entirely.
Read the domain slowly, character by character, especially on a small screen. If anything is off, a substituted letter, an unexpected ending, the brand name in the wrong position, treat the link as unsafe. Scammers count on you skimming.
A few concrete patterns come up again and again. Extra words joined by hyphens around a brand name (paypal-secure-login) are a classic dressing-up trick; the real domain almost never needs them. Unusual endings.info, .top, .xyz, or a country code, attached to a household-name brand should raise an eyebrow. And a name that is technically the brand but sits as a subdomain of something unfamiliar (paypal-account-check.example resolves to account-check.com) is designed to reassure you while sending you somewhere else entirely. None of these are proof by themselves, but any of them is reason enough to stop and reach the company through its front door instead.
Step 4, Watch for the context clues around the link
A link never arrives alone. It comes wrapped in a message, and the wrapping tells you a lot. Ask who sent it and whether you expected it. A link in an unsolicited text, a surprise email, or a DM from someone you just met deserves far more suspicion than one you specifically requested, like a password reset you just triggered yourself moments ago.
Then read the pressure. Malicious links are almost always paired with urgency and a reason you must click right now: an account will be suspended, a package will be returned, a payment failed, a limited offer expires. Legitimate services rarely force an instant click through an unfamiliar link to avoid a penalty. If the surrounding message is rushing you or the link is the only way to "fix" a sudden problem, treat the link itself as suspect no matter how the domain looks.
Also be cautious with shortened links (bit.ly and similar) that hide the true destination entirely. When you cannot see where a shortened link goes, you cannot inspect it, and that opacity is itself a reason to be wary, especially in an unexpected message.
Step 5, When in doubt, don't click, go direct instead
You do not have to click a link to get where it claims to lead. If a message says there is a problem with your account, a package, or a bill, reach the real thing yourself: open the company's official app, or type its website into your browser directly. Any genuine notice will be waiting for you inside your account through that trusted path, and if it is not there, the message was not real.
This one habit defuses most link-based scams, because it removes the scammer's link from the equation entirely. When you are unsure, the safe default is not to click, a link you never open cannot harm you. There is no downside to reaching a company through its front door instead of a link someone sent you, and it turns a risky judgment call into a safe, automatic routine.
Step 6, Get a second opinion, and a note on QR codes
If you have inspected a link and still are not sure, get help before you commit. You can paste the link into Hunch, which flags the signal categories it recognizes, a lookalike domain, an urgent tone, or a credential or payment request, so you have more to go on than a gut feeling.
One more thing: a QR code is just a link you cannot read with your eyes. When you scan one, your phone usually shows the destination URL before opening it, pause and apply the earlier steps to that URL exactly as you would any other link. Be especially wary of QR codes on stickers placed over real ones, in unexpected emails, or on parking and payment signs, since a scammer can cover a legitimate code with their own.
Why this matters: the whole point of checking a link is to keep you off a page that looks real but is not. Most credential theft and card fraud starts with a single tap onto a convincing fake, so the seconds you spend inspecting a link are well spent. Build these steps into a habit and they stop feeling like effort. They become an automatic pause that protects you.
FAQ
How do I see where a link really goes without clicking it?
On a computer, hover your mouse over the link and read the address that appears in the corner. On a phone, press and hold the link to preview the full URL, then dismiss it without opening.
Which part of a URL actually matters?
The core domain, the name immediately to the left of the first single slash. Words before it and everything after the slash can be set to anything, so only the core domain tells you where you truly land.
Does HTTPS or a padlock mean a site is safe?
No. The padlock only means the connection is encrypted, not that the site is trustworthy. Scam pages can have padlocks too, so still check the domain carefully.
Are QR codes safe to scan?
A QR code is just a hidden link. Your phone usually shows the destination before opening it, so pause and check that URL like any other, and be wary of QR codes in unexpected places or stuck over existing ones.
What should I do if I already clicked a suspicious link?
If you only clicked, watch your accounts and follow the clicked-link steps. If you entered a password or card details, change your password and contact your bank or card issuer right away.