What makes a link unsafe, and how to spot the difference

A link is unsafe when it leads to a website designed to steal your information, infect your device with malware, or trick you into sending money. The dangerous part is that unsafe links often look identical to real ones — the URL might say "amaz0n.com" instead of "amazon.com", or the link text might say "Click here to update your account" when it actually goes somewhere else entirely. Your browser cannot always tell the difference, so you have to learn the signs before you click.

The most common unsafe links come through email, text messages, and social media. Someone sends you a message that looks urgent — your bank account is locked, a package needs a signature, your password expires today — and includes a link. When you click it, you land on a fake website that looks real enough to fool you into typing your username and password. That information goes straight to the person who sent the link, not to your bank or delivery company.

Other unsafe links download malware directly to your device without asking permission. These are harder to spot because they can come from websites that look completely legitimate. The only defense is learning what to check before you click anything.

Key Takeaways

  • Hover over any link (without clicking) to see the real URL it points to — the text you see and the actual destination are often different.
  • Check the domain name carefully: "amaz0n.com" (with a zero) is not the same as "amazon.com" (with the letter O), and scammers count on you not noticing.
  • Urgent messages demanding immediate action — especially ones asking you to verify a password or payment method — are a red flag even if they appear to come from a trusted company.
  • If you are unsure about a link, go directly to the company's website by typing the address yourself rather than clicking the link in the message.
  • Your browser's address bar shows you the real website you are on; if it does not match what you expected, leave immediately and do not enter any information.

How to check a link before clicking it

On a computer, move your mouse over the link and pause — do not click. Look at the bottom left corner of your browser window. You will see the actual URL the link points to. Compare that URL to what you expected. If the text says "Update your Amazon account" but the URL starts with something like "secure-verify-amazon.ru", that is a fake link and you should not click it.

On a phone or tablet, press and hold the link for a few seconds. A menu will pop up with options. Look for "Copy link" or "Show link preview" — different phones use different words. Tap that option and you will see the real URL. Again, compare it to what you expected. If it does not match, do not tap it.

This one step — checking the actual URL before you click — stops most phishing attacks. Scammers rely on you clicking without looking. The moment you start checking, you are already safer than most people.

Red flags in the URL itself

Even if you cannot see the full URL, you can spot danger in the parts you can see. The domain name — the part right after "www." or "https://" — is what matters most. If an email claims to be from your bank but the URL says "bankname-security.tk" or "verify-bankname.xyz", that is not your bank's real website.

Legitimate companies own their own domain names. Bank of America's website is "bankofamerica.com", not "bankofamerica.co" or "bankofamerica.net". PayPal's website is "paypal.com". If you are not sure what the real domain is, open a new browser tab and search for the company name plus "official website". Go to that result instead of clicking any link in a message.

Watch for common tricks: replacing the letter "O" with the number "0", using "rn" instead of "m", or adding extra words before the real domain name. "Paypa1.com" (with a one instead of an L) looks close to "paypal.com" if you are reading fast. Scammers count on that.

Messages that are almost always unsafe

Certain types of messages are red flags no matter who appears to send them. Any message that creates urgency — "Your account will be closed in 24 hours", "Verify your password now", "Confirm your payment method immediately" — is usually a scam. Real companies do not lock you out of your account through a link in an email.

Messages asking you to click a link to "verify" or "confirm" anything are almost always phishing. Your bank, PayPal, Amazon, and Apple do not send links asking you to re-enter your password or credit card number. If you get a message like that, do not click the link. Instead, go directly to the company's website by typing the address yourself, log in, and check your account. If there is a real problem, you will see it there.

Be especially careful with messages that claim to come from someone you know — a friend, family member, or colleague. Scammers can hack email accounts and send messages that look like they come from people you trust. If a message from someone you know seems odd or asks you to click a link to something unusual, send them a separate message (by phone or a different app) and ask if they really sent it.

What to do if you already clicked an unsafe link

If you clicked a link and landed on a website that asked for your password, username, credit card number, or Social Security number, do not enter that information. Close the browser tab immediately. You have not done anything wrong by clicking — the danger is only if you type your information into the fake website.

If you already typed your password, change it as soon as possible. Go directly to the real website (by typing the address yourself), log in with your current password, and change it to something new. If the website is your email account, change that password first, because scammers often use a hacked email to reset passwords on other accounts.

If you entered a credit card number or banking information, contact your bank or credit card company by phone. Use the number on the back of your card or the number from your statement — do not use a number from a search result, because scammers sometimes fake those too. Tell them you may have entered your information on a fake website and ask them to watch your account for suspicious charges.

How your browser can help you spot unsafe websites

Modern browsers — Chrome, Firefox, Safari, and Edge — have built-in warnings for websites known to be dangerous. If you land on a site that is flagged as unsafe, your browser will show a warning page before you see the website itself. The page usually says something like "This site may be unsafe" or "Deceptive site ahead". When you see this warning, leave the website immediately. Do not click "proceed anyway" or any button that lets you continue.

These warnings are not perfect — some unsafe sites slip through, and some safe sites get flagged by mistake — but they catch a lot of phishing and malware sites. If your browser warns you, trust it.

You can also look at the address bar itself. In most browsers, a secure website shows a small lock icon next to the URL. A lock does not mean the website is trustworthy — it only means the connection between your device and the website is encrypted. A fake bank website can have a lock too. The lock is useful, but it is not a complete safety check on its own.

Checking links in emails and text messages

Email and text messages are where most phishing links come from. Before you click any link in an email, check who sent it. Look at the sender's email address, not just the name that appears. Scammers can make an email look like it comes from "Amazon Customer Service" but the actual email address might be something like "amazonhelp@fakesite.com". If the sender's email address does not match the company's real domain, it is not from that company.

Text messages are even trickier because you cannot hover over a link to see where it goes. If you get a text from your bank, delivery company, or any other service with a link, do not click it. Instead, open your phone's browser, go to that company's website directly, and log in to check your account. If there is a real issue, you will see it there. Real companies do not send links through text messages asking you to take urgent action.

The same rule applies to links in social media messages, comments, and posts. If someone sends you a link through Facebook, Instagram, or Twitter claiming you won something or asking you to check out a video, be skeptical. Scammers use social media constantly because people are more likely to trust messages from people they follow.

Frequently Asked Questions

Can a link be unsafe even if it comes from someone I know?

Yes. Scammers often hack email and social media accounts, so a message that looks like it comes from a friend might actually be from someone else. If a message from someone you know seems unusual or asks you to click a link to something strange, contact them through a different method and ask if they really sent it.

What does the lock icon in my browser mean?

The lock icon means your connection to the website is encrypted, so no one can see your data while it travels between your device and the website. It does not mean the website is trustworthy or that it is not a fake. A phishing website can have a lock too. Always check the domain name as well.

Is it safe to click a link if the text matches the URL?

Not always. Scammers can make the link text say "amazon.com" while the actual URL goes somewhere else. Always hover over the link to see the real URL, even if the text looks correct. The actual destination is what matters.

What should I do if I see a warning from my browser?

Leave the website immediately. Your browser's warning means the site is known to be dangerous or deceptive. Do not click any buttons that say "proceed anyway" or "continue to site". Close the tab and go somewhere else.

Can I get malware just by visiting a website, or do I have to download something?

You can get malware just by visiting certain websites, especially if your browser or operating system has security gaps. This is rare on modern devices with current updates, but it is possible. The safest approach is to avoid clicking suspicious links in the first place, keep your device updated, and use security software that scans for malware.