How to tell if a link is safe

Before you click a link, you can check three things without opening it: where it actually goes, whether the website it points to is real, and whether your browser or email program has flagged it as dangerous. The fastest check is to hover your mouse over the link — your browser will show you the real destination in the bottom left corner. If the text says "Click here to reset your password" but the address bar preview shows something like "malicious-site.ru/steal-data", that link is trying to deceive you. If the preview looks legitimate, you can then check whether the website itself is trustworthy before clicking through.

The second layer is checking the website's reputation. You can paste a suspicious link into Google Safe Browsing (safebrowsing.google.com) or VirusTotal (virustotal.com) and see whether security companies have flagged it. These services scan websites for malware and phishing attempts. If either tool shows warnings, do not click. If both show the site is clean, the link is almost certainly safe to open.

Key Takeaways

  • Hover over any link to see where it actually goes before clicking — the real destination appears in your browser's bottom left corner.
  • Check suspicious links using Google Safe Browsing or VirusTotal, which tell you whether security companies have flagged the website.
  • Look for HTTPS in the address bar and a padlock icon, which mean the connection to the website is encrypted, though this does not may provide the site itself is trustworthy.
  • Email links are higher risk than links you find elsewhere — verify the sender's actual email address by clicking their name, not by trusting the display name alone.
  • If a link asks you to log in, type the website address directly into your browser instead of clicking the link, so you know you are on the real site.

Hover to see the real destination

Your browser shows you where a link actually goes without you having to click it. Move your mouse over the link and wait a moment — the real web address appears in a small preview, usually in the bottom left corner of your screen. On a phone, press and hold the link instead; most phones will show you the destination in a popup.

This is the fastest way to catch a fake link. A link might say "Update your Apple ID" but point to "applesecurity-verify.com" instead of apple.com. The text is trying to trick you; the destination address tells you the truth. If the destination looks wrong, suspicious, or misspelled, do not click.

Use Google Safe Browsing or VirusTotal to scan a link

If you are unsure whether a website is safe, you can check it without visiting it. Go to safebrowsing.google.com and paste the link into the search box. Google will tell you whether the site has been flagged for malware, phishing, or unwanted software. The results appear in seconds.

VirusTotal (virustotal.com) works the same way but checks the link against 90 different security companies at once. Paste the link, wait for the scan to finish, and you will see whether any of those companies have flagged it. If even one company marks it as dangerous, treat it as unsafe. If all show green, the link is almost certainly legitimate.

Check for HTTPS and a padlock icon

When you do click a link and land on a website, look at the address bar. A real, secure website shows "HTTPS://" at the start of the address and a padlock icon to the left. HTTPS means the connection between your browser and the website is encrypted — nobody between you and the website can see what you type or what the site sends back.

A missing padlock or "HTTP://" instead of "HTTPS://" does not automatically mean the site is malicious, but it does mean your connection is not encrypted. If you are about to enter a password or payment information, do not do it on a non-HTTPS site. Be aware that a padlock only means the connection is encrypted; it does not may provide the website itself is trustworthy. A phishing site can have HTTPS too.

Verify the sender of email links

Email is where most dangerous links arrive. A link in an email claiming to be from your bank might actually be from a criminal. To check, click on the sender's name or email address — not the link itself. Your email program will show you the actual email address the message came from. If it says it is from "Bank of America" but the actual address is "bankofamerica-security@gmail.com" or anything other than a real Bank of America domain, it is fake.

Real companies use their own domain names in their email addresses. Bank of America uses addresses ending in @bankofamerica.com. Amazon uses @amazon.com. If the sender's real address does not match the company they claim to represent, the email is phishing, and the link is dangerous.

Log in by typing the address yourself, not by clicking a link

If a link asks you to log into your email, bank, social media account, or any other service, do not click it. Instead, open a new browser tab and type the website address directly. This protects you from phishing links that look real but actually point to a fake login page designed to steal your password.

Legitimate companies almost never send you links to log in. They send you a message saying "We noticed unusual activity" or "Please verify your account," but they expect you to go to the real website yourself. If you click their link and land on a login page, you have no way to know whether you are on the real site or a fake one. Typing the address yourself guarantees you are in the right place.

What to do if you clicked a dangerous link

If you clicked a link and realized it was suspicious, or if your browser showed a warning, close the tab immediately. Do not download anything the page offers, and do not enter any information. In most cases, simply visiting a malicious website does not infect your computer — you have to download and run something for that to happen.

If you entered a password on a suspicious site, change that password as soon as you reach the real website. If you entered payment information, contact your bank or credit card company and let them know. They can watch for fraudulent charges and issue you a new card if needed. If you are on a work computer, tell your IT department what happened so they can check whether malware was installed.

Frequently Asked Questions

Can a link be safe even if my browser shows a warning?

No. If your browser shows a warning — "This site may be unsafe" or "Deceptive site ahead" — do not click through. These warnings come from Google Safe Browsing or similar services and mean security companies have flagged the site. The warning exists to protect you, and ignoring it puts you at real risk.

Is a link safe if it comes from someone I know?

Not necessarily. Criminals hack email and social media accounts and send malicious links to all the contacts. If a friend sends you a link that seems out of character — especially one asking you to click urgently or verify something — check with them through another method (a phone call, a text message) before clicking. Ask "Did you send me a link about [topic]?" If they did not, the account has been compromised.

What if the link looks like it goes to a real website but I am still not sure?

Use VirusTotal or Google Safe Browsing to scan it. These tools are free and take 30 seconds. If you are still uncertain after scanning, do not click. There is no penalty for being cautious with links — the worst that happens is you skip something harmless. The worst that happens if you click a dangerous link is much worse.

Do I need special software to check if a link is safe?

No. Your browser's built-in warnings catch most dangerous links automatically. Google Safe Browsing and VirusTotal are free websites you can use in any browser. You do not need to download or install anything. The tools you already have — your browser and the ability to hover over links — handle most situations.

What is the difference between a phishing link and a malware link?

A phishing link takes you to a fake website designed to steal your login information or payment details. A malware link tries to download and install harmful software on your computer. Both are dangerous, but they work differently. Phishing relies on you entering information; malware relies on you downloading something. Both can be caught by the same checking methods.