Check the link before you click — here's what to look for
A safe link takes you where it says it will go. An unsafe one might download malware, steal your login information, or trick you into giving money to scammers. You can spot most dangerous links by checking three things: where the link actually points, whether the website looks legitimate, and whether you expected to receive it.
The most common mistake is clicking a link that looks normal in an email or text message without checking where it actually leads. Your browser can show you the real destination before you click — and that takes two seconds.
Key Takeaways
- Hover your mouse over any link to see the real web address it points to, which may be completely different from the text shown.
- Legitimate websites use HTTPS (with a padlock icon in your browser), while many phishing sites use plain HTTP or no security at all.
- Scammers often misspell domain names slightly — amazon.com is real, but amaz0n.com (with a zero) is not.
- If you did not expect the link or it came from someone asking you to act fast, do not click it — contact the sender directly using a phone number or email you know is theirs.
- Your browser's address bar shows the actual website you are on; if it does not match what you expected, leave immediately.
Hover over the link to see where it really goes
Every link has two parts: the text you see and the actual web address underneath. Scammers count on you reading only the text. On a computer, move your mouse over any link without clicking and wait one second — your browser will show you the real address in a small box or in the bottom left corner of the screen.
On a phone or tablet, press and hold the link for two seconds. A menu will pop up showing the real address. If the address does not match what the link text says, do not click it. For example, a link that says "Click here to reset your Amazon password" might actually point to amaz0n-secure.ru — a completely different website designed to steal your login.
This single habit stops most phishing attacks. Scammers rely on you not checking. Take the two seconds.
Look for HTTPS and the padlock icon in your browser
Every website address starts with either HTTP or HTTPS. The S stands for secure. Legitimate websites that handle passwords, payment information, or personal data use HTTPS. Your browser shows a padlock icon next to the address when you are on a secure site.
If you land on a login page or a page asking for payment and the address bar shows HTTP (no S) or no padlock, stop. Do not enter any information. Leave the page immediately. Scam sites often skip the security certificate because it costs money and requires verification.
This is not a perfect test — some legitimate sites use HTTP for pages that do not collect sensitive data — but if a site is asking for your password or credit card and does not have HTTPS, it is unsafe.
Check the domain name for common misspellings
Scammers register domain names that look almost identical to real ones. They use a zero instead of the letter O, swap similar letters, or add extra words. apple.com is real. appie.com, aple.com, and apple-support.com are not.
When you land on a website, look at the domain name in the address bar carefully. Read it letter by letter if you are not sure. The domain is the main part of the address — in www.amazon.com, the domain is amazon.com. Everything after the first slash (like /account/login) is just a page on that site and does not matter for this check.
If you are logging into your bank or email, type the address directly into your browser instead of clicking a link. This is the safest method because you control exactly where you go.
Do not click links in unexpected messages
Phishing emails and texts often create fake urgency: "Your account will be locked," "Confirm your identity now," "Unusual activity detected." Real companies rarely ask you to click a link to fix something urgent. If you get a message like this, do not click the link.
Instead, contact the company directly using a phone number or website you know is real. Call your bank's customer service number on the back of your card. Go to your email provider's website by typing the address yourself. If there really is a problem, the company's official channel will show it to you.
This applies to messages from people you know, too. If a friend sends you a link with no context, or a link that seems out of character for them, ask them about it before clicking. Their account may have been hacked.
Watch for poor spelling and design on the website itself
Once you land on a website, look at the overall quality. Legitimate companies invest in their websites. Scam sites often have spelling mistakes, blurry logos, broken images, or awkward layouts. This is not always a perfect indicator — some real sites are poorly designed — but it is a warning sign.
Pay special attention to forms asking for information. Real companies do not ask for your full password, Social Security number, or credit card number via email or on a page you reached through a link. If a form is asking for sensitive information you did not expect to provide, leave the site.
Look for contact information too. Real companies list a phone number, email, and physical address. If a website has none of these, it is suspicious.
Use your browser's security warnings
Modern browsers (Chrome, Firefox, Safari, Edge) have built-in protection against known phishing and malware sites. If you try to visit a dangerous website, your browser will show a warning page before the site loads. The warning will say something like "This site may be unsafe" or "Deceptive site ahead."
Take these warnings seriously. Do not click "proceed anyway" unless you have a very good reason and you are certain the site is safe. These warnings catch thousands of attacks every day.
If you see a warning, go back and contact the company through a different method — call them, visit their official app, or go to their website by typing the address yourself.
Frequently Asked Questions
What if I already clicked a suspicious link?
Do not panic. Clicking a link does not automatically infect your device. If the page loaded and you did not enter any information, you are likely fine. Close the page and move on. If you entered a password or payment information, change that password immediately from a different device and contact your bank or email provider to report it.
Can I trust a link just because it came from someone I know?
Not always. Scammers hack email and social media accounts regularly. If a link seems out of place or you were not expecting it, contact the person through a different method — call them or send them a separate message — and ask if they really sent it. Real friends will understand.
Is it safe to click links in emails from my bank or email provider?
It is safer to type the address yourself or use the official app. Even if the email looks real, scammers can make fake emails that look identical to the real thing. When in doubt, go directly to the company's website by typing the address yourself or calling their customer service number.
What does the padlock icon mean exactly?
The padlock means the connection between your device and the website is encrypted — nobody can see your data while it travels. It does not mean the website is trustworthy, only that the connection is secure. A phishing site can have a padlock too. Always check the domain name and the content of the page as well.
Should I be worried about links in text messages?
Yes, more than email. Text messages are easier to fake, and people often click them faster without thinking. Use the same rules: hover over or press and hold the link to see where it really goes, check the domain name, and never enter sensitive information on a page you reached through an unexpected text.