Skip to content

How to Check If a Link Is Safe Before You Click

How to check if a link is safe: preview the real address, read the domain the right way, spot lookalikes and text-message tricks, and what to do if you clicked.

Published
Journey
4 min
Covered here
6 sections
Route
Tech
Telephone, mobile and call

Covered here

  1. Read the address, not the label
  2. How to read a web address correctly
  3. Warning signs inside the link
  4. Warning signs around the link
  5. Tools that do some of the checking
  6. What to do if you already clicked

To check if a link is safe, look at where it really leads before you open it. Hover over it on a computer, or press and hold it on a phone, to preview the full address; read the domain name carefully; and treat shortened links, odd spellings and messages that rush you with extra suspicion. When doubt remains, skip the link entirely and reach the service by typing its address yourself or opening its official app.

Read the address, not the label

The visible text of a link is decoration. A button that says "Track your parcel" can point to any address at all. On a computer, rest the pointer on the link without clicking, and the true destination usually appears in the bottom corner of the browser or email window. On a phone, press and hold until a preview or menu pops up, then read the address without tapping through.

How to read a web address correctly

The part that matters most is the registered domain: the name directly before the ending, such as .com, .co.uk or .org, and before the first single forward slash. Anything to the left of it is a subdomain, which the owner can set to any word they like, including the name of your bank. Anything after the slash is a path, and anything after a question mark is a parameter; our explainer on how URL parameters work shows what those trailing strings do.

Shape of the addressWho actually controls it
login.bankname.com/accountThe owner of bankname.com
bankname.com.account-check.example/loginThe owner of account-check.example, not the bank
bankname-secure-login.comWhoever registered that whole name
bankname.com/redirect?to=…The bank, but the link may hand you on elsewhere

Reading from the ending backwards to the first full stop before it is a reliable way to find the real owner.

Warning signs inside the link

  • Lookalike spelling. A zero in place of the letter o, "rn" standing in for "m", an extra hyphen or an added word such as "secure" or "verify".
  • A brand name in the wrong place. The familiar name sits in the subdomain or the path while the registered domain is something unrelated.
  • Shortened links. These hide the destination. Some shorteners offer a preview page; otherwise, a link-checking service can expand it without you visiting.
  • Raw numbers or gibberish. An IP address in place of a name, or a long string of random characters, is unusual for a genuine sign-in page.
  • Unexpected downloads. Files ending in .exe, .scr or .zip, or documents that ask you to "enable content", deserve a hard stop.
  • The padlock myth. "https" and a padlock mean the connection is encrypted, not that the site is honest. Fraudulent pages use them too.

Warning signs around the link

The message carrying a link gives as much away as the address. Notices that a parcel is held, an account is locked, a fine is overdue or a refund is waiting all lean on urgency. When the bait arrives by text message it is called smishing, and the same tricks appear in chat apps, social media messages and on QR code stickers placed over genuine ones on posters or parking machines. Slow down when:

  • you were not expecting the message;
  • it asks you to sign in, pay or "confirm" details through the link;
  • the sender's address or number does not match the organisation it claims to be;
  • the tone is threatening or the deadline is a matter of hours.

Tools that do some of the checking

  • Browser protection. Modern browsers warn about known dangerous pages. Keep the feature switched on and the browser up to date.
  • Link-scanning services. Reputable scanners test an address against several security databases without you opening it. Paste the link only, never your personal details.
  • Security software. Web protection on computers and phones blocks many known bad addresses.
  • Password managers and passkeys. Neither will fill in your details on a lookalike domain. If your manager stays silent on a page that claims to be your bank, treat that as a warning. Passkeys go further because they only work on the genuine address.

What to do if you already clicked

  1. Close the page. On an updated device, simply opening a link rarely does the damage; the risk climbs if you typed details or downloaded a file.
  2. If you entered a password, change it at once on the real site and anywhere else you used the same one.
  3. If you entered card or bank details, call your bank on the number printed on your card.
  4. If something downloaded, delete it and run a full scan with your security software.
  5. Check the account's active sessions and recovery details; our guide to recovery emails explains what to look for.
  6. Report the message with the "report phishing" or "report junk" option in your mail or messaging app so others are warned too.

Change here for

Also on this line