How to check if a link is safe before you click it
Almost every link check comes down to one skill - finding the real domain in a URL. It is the part immediately before the first single slash, and everything to the left of it can say anything at all.
The short answer
- Find the real domain - it is the last two parts immediately before the first single slash. Everything before that can be set to anything by whoever owns the domain.
- Never judge a link by its visible text. Displayed text and destination are separate things, and in an email they often disagree.
- The padlock means the connection is encrypted, not that the site is honest. Most phishing sites have one.
- On a phone, press and hold to preview a link rather than tapping. On a desktop, hover and read the status bar.
- The strongest habit skips checking entirely - when a message is unexpected, go to the site yourself instead of using its link.
Most advice about suspicious links stops at "check the URL", which is useless if nobody has explained which part of a URL to look at. That is the whole skill, and it takes about a minute to learn.
Quick answer
Find the real domain: it is the last two parts immediately before the first single slash. Everything to the left of it is chosen freely by whoever owns that domain and means nothing.
https://accounts.google.com.secure-signin.co/verify
^^^^^^^^^^^^^^^^
the real domain
That link goes to secure-signin.co. The words accounts.google.com are just
subdomains — text the owner of secure-signin.co typed in front of their own
name. Anyone can put any brand there.
Compare:
https://accounts.google.com/signin real Google
https://accounts.google.com.secure.co/ not Google
https://google.accounts-verify.net/ not Google
https://myaccount.google.com/security real Google
Read right to left from the first single slash. Once you can do that, most phishing links identify themselves.
The eight checks
1. Read the domain, not the brand name
Covered above, and it is the one that matters most. The brand name appearing somewhere in a URL proves nothing about who owns it.
2. Do not trust the visible text
In an email or a web page, the text you see and the address it goes to are
completely separate. A link can display www.yourbank.com and lead anywhere.
This is ordinary HTML, not a hack — which is why the displayed text is worth
nothing as evidence.
3. Hover on a desktop
Put your pointer over the link without clicking. The real destination appears in the bottom-left corner of the browser, or as a tooltip in most email programs. Read the domain there.
4. Press and hold on a phone
Tapping is committing. Instead, press and hold the link — on both iPhone and Android a preview appears showing the full address. Read it, then release your finger somewhere else on the screen.
5. Look for lookalike characters and spelling
Attackers register domains that read correctly at a glance:
- Swapped letters —
paypaI.comwith a capital i instead of an l - Doubled or dropped letters —
arnazon.com,micosoft.com - Added words —
apple-support.com,netflix-billing.net - Different endings — the right name on
.co,.us,.info,.top,.shop - Non-Latin characters that render like ordinary letters
The last one is the hardest to catch by eye. Modern browsers usually display such domains in their raw form as a warning, but do not rely on it — rely on not following links from unexpected messages.
6. Treat shorteners as unreadable
A shortened link hides the destination. That is its function, and it is not sinister on its own — but you cannot check a domain you cannot see. Some services offer a preview by adding a character to the end of the URL. Otherwise, paste it into a scanner rather than opening it.
7. Check the padlock properly
The padlock means the connection is encrypted. It does not mean the site is honest, and certificates are free, automatic and instant — so most phishing sites have one.
8. Ask what the link wants
The strongest check is not technical. A link that leads to an article is a very different proposition from one that leads to a sign-in form or a payment page. The FTC's framing is useful: phishing messages nearly always want a credential, a payment, or an action taken urgently. If an unexpected link wants any of those, the destination hardly matters.
Using a scanner
For a link you genuinely need to evaluate rather than avoid, paste it — do not open it — into a checker:
- Google Safe Browsing site status, at
transparencyreport.google.com/safe-browsing/search, tells you whether Google currently lists the site as dangerous. Safe Browsing checks billions of URLs a day and powers the red warning pages in Chrome, Safari and Firefox. - Multi-engine scanners such as VirusTotal check a URL against many security vendors at once and expand shortened links.
The habit that beats every check
Nothing legitimate is lost by doing this. No real company requires you to use the specific link it sent, and none of them impose a deadline short enough to make going directly impractical.
Special cases
QR codes are links you cannot read at all. Most phone cameras now show the destination before opening it — read that preview like any other URL. QR code phishing covers why the format removes every habit you have built.
Links in text messages deserve the most suspicion, because SMS carries no sender verification and the format hides domains well. Toll notices, delivery fees and bank alerts are the common pretexts.
Search results and adverts. The advert above the real result can be attacker-bought. When looking for a login page or a software download, check the domain of the result before clicking, and prefer a bookmark.
Links from people you know. A compromised account sends real messages from a real contact. If a friend sends an unexpected link with little context, ask them through a different channel before opening it.
Consent screens. Some links lead to a genuine Google or Microsoft page that asks you to approve an app's access. The URL is correct there — the risk is what you approve. Consent phishing explains that one.
If you already clicked
Clicking alone is rarely the harmful step. What matters is what happened after:
- You only saw a page and typed nothing — close it. You are very probably fine.
- You entered a password — change it now, then sign out of all sessions on that account.
- You entered card details — call your bank on the number on the card and freeze it.
- You downloaded or ran something — disconnect from the internet and scan the device before doing anything else. If it told you to paste a command, read CAPTCHA scams.
I clicked a phishing link covers each of those in full.
Key takeaways
- The real domain is the last two parts before the first single slash. Everything left of it is decoration.
- Displayed link text and actual destination are unrelated — never judge by the text.
- Hover on desktop, press and hold on mobile, and read the address before committing.
- The padlock means encrypted, not trustworthy.
- Scanners are useful but lag behind new sites; a clean result is not a guarantee.
- For anything unexpected, skip the link and go to the site yourself.
Practise reading real URLs
SafeSurf IQ drills the domain check on genuine and fraudulent links until spotting the difference is automatic.
Try it freeFrequently asked questions
- How can I tell if a link is safe before clicking?
- Read the domain, which is the part immediately before the first single slash after the double slash. Take the last two segments of it - for example in secure-login.yourbank.com.verify-account.co the real domain is verify-account.co, not yourbank. If that domain is not one you recognise as belonging to the sender, do not follow the link. Preview it first by hovering on a desktop or pressing and holding on a phone.
- Does the padlock icon mean a website is safe?
- No. The padlock means traffic between you and the site is encrypted, which says nothing about who runs the site or what they intend. Certificates are free and instant, so the large majority of phishing sites have one. Treat the padlock as a minimum, not as reassurance - its absence is a bad sign, but its presence is not a good one.
- How do I check a link on my phone?
- Press and hold the link instead of tapping it. On both iPhone and Android a preview appears showing the full destination address, which you can read before deciding. Do not lift your finger onto the link itself. In a text message, the safer route is usually to ignore the link entirely and open the company's own app or type its address yourself.
- Are link shorteners safe?
- A shortener is neither safe nor unsafe - it hides the destination, which is the problem. You cannot read a domain that is not shown. Some shorteners let you preview by adding a character to the URL, and free scanners will expand and check one for you. In an unexpected message, a shortened link is a reason for more caution, not less.
- What is the safest way to reach a site mentioned in a message?
- Do not use the link at all. Type the address yourself, use a bookmark you saved earlier, or open the organisation's official app. This defeats every URL trick at once - lookalike domains, hidden text, shorteners, redirects and characters that imitate letters - because you are no longer relying on anything the sender supplied.
- I already clicked a link. What should I do?
- Clicking alone is rarely the harmful step. What matters is what happened next. If you only opened a page and typed nothing, close it and you are very likely fine. If you entered a password, change it and sign out of all sessions immediately. If you downloaded or ran a file, disconnect and scan the device before doing anything else.
Sources
- Google Safe Browsing site status — Google, 2026
- Safe Browsing — Google, 2026
- Phishing attacks - defending your organisation — UK National Cyber Security Centre, 2025
- How To Recognize and Avoid Phishing Scams — Federal Trade Commission, 2026
- Avoiding Social Engineering and Phishing Attacks — Cybersecurity and Infrastructure Security Agency, 2021
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Phishing
How to identify a phishing email in under ten seconds
Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.
- Phishing
I clicked a phishing link. What should I do?
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.
- Phishing
QR code phishing (quishing): why a square defeats your instincts
A QR code is a link you cannot read. That single property removes every habit built around checking where a link goes, which is why attackers are sending millions of them every day.