Check the link before you click
You can see whether a link is safe by checking three things before you click: the web address itself, the sender's identity, and what happens when you hover over the link. Most unsafe links either hide their real destination, come from someone pretending to be someone else, or lead to a site that tries to steal your information or install malware on your device.
The fastest check is to hover your mouse over the link without clicking. Your browser will show you the actual web address the link goes to — usually in the bottom left corner of your screen. If that address does not match what the link text says, or if it looks wrong or misspelled, do not click it.
The second check is to look at who sent you the link. Scammers often impersonate banks, payment services, or companies you use. If an email claims to be from your bank but the sender's email address is not from the bank's official domain, it is fake. If a text message asks you to click a link to "verify your account," but you did not request that, it is likely a scam.
Key Takeaways
- Hover over any link to see its real destination in the bottom left corner of your browser — if it does not match the link text, do not click it.
- Check the sender's email address or phone number against official contact information from the company — scammers often use addresses that look similar but are slightly different.
- Legitimate companies rarely ask you to click a link to verify your password, update payment information, or confirm your identity in an email or text.
- If a link takes you to a website that looks like a login page but the web address is wrong, close the tab immediately and do not enter any information.
- You can paste a suspicious link into a URL scanner tool to check whether the destination site is known to be unsafe.
How to read a web address to spot fakes
The web address — called a URL — tells you exactly where a link goes. Scammers often create addresses that look almost like the real thing but have a small difference you might miss. For example, a fake might use "amaz0n.com" (with a zero instead of the letter O) or "paypa1.com" (with the number 1 instead of the letter L).
The part of the address that matters most is the domain — the main name between the "://" and the first forward slash. For PayPal, the real domain is "paypal.com". For Amazon, it is "amazon.com". If you see anything else before that domain name, or if the domain itself is spelled differently, the link is not going to the real site.
Some fake addresses try to hide the real destination by putting a legitimate-looking name in front. For example, "paypal.com.scamsite.net" looks like it might be PayPal, but the actual domain is "scamsite.net" — everything before the last two parts (the .net) is just a subdomain that the scammers control. Read the address from right to left: the last part (.com, .net, .org) and the word directly before it make up the real domain.
Verify the sender is actually who they claim to be
Before you click any link in an email or text, check whether the sender is really who they say they are. Scammers often use email addresses or phone numbers that are close to the real thing but not quite right.
For emails, look at the sender's full email address, not just the display name. A display name can say "Bank of America" but the actual address might be "bankofamerica@fakebank.net" or something similar. Hover over the sender's name to see the real email address. Then check the company's official website to see what email address they actually use for customer service. If they do not match, the email is fake.
For text messages, remember that legitimate companies rarely text you asking you to click a link to verify your account or update your information. If your bank texts you, it is usually to tell you about a transaction that already happened, not to ask you to do something. If you are unsure, hang up and call the company directly using the phone number on their official website or your account statement — not a number from the text message.
Use a URL scanner to check suspicious links
If you are not sure about a link, you can paste it into a free URL scanner tool to check whether the destination site is known to be unsafe. These tools check the web address against databases of sites that have been reported for phishing, malware, or other threats.
Common URL scanners include Google Safe Browsing (safebrowsing.google.com), VirusTotal (virustotal.com), and URLhaus (urlhaus.abuse.ch). You do not need to click the link — just copy the web address and paste it into the scanner's search box. The tool will tell you whether the site has been flagged as dangerous.
Keep in mind that a scanner can only flag sites that have already been reported. A brand-new scam site might not show up as unsafe yet. That is why the other checks — looking at the sender and reading the web address — are still important even if a scanner says the link is clean.
What to do if you already clicked an unsafe link
If you clicked a link and realized it was unsafe, the first thing to do depends on what happened next. If the link took you to a fake login page, close the tab immediately without entering any information. If you already typed in your password or account details, change your password right away from a different device or browser.
If the link tried to download a file to your computer, do not open that file. Delete it from your Downloads folder. If you are worried the file might have already run or installed something, run a scan with your antivirus software. Most computers come with built-in antivirus protection — on Windows, this is Windows Defender; on Mac, it is built into the operating system.
If you clicked a link in a text message or email and are not sure what happened, check your device for any new apps you did not install, or unusual activity on your accounts. If you see something wrong, change your passwords and contact your bank or the company whose account was affected.
Red flags that a link is probably unsafe
Certain patterns show up in almost every scam. If you see any of these, do not click the link: the sender is asking you to verify your password or update payment information; the message creates a sense of urgency ("Your account will be closed in 24 hours"); the link came in an unexpected email or text from someone you do not know; the sender is asking you to click a link to claim a prize or refund you did not request; or the web address has obvious misspellings or looks unusual.
Another common red flag is when a link in an email or text does not match what the message says. For example, an email might say "Click here to log into your account" but when you hover over the link, the actual destination is a completely different website. Trust the web address you see when you hover, not the text of the link.
If an email or text is asking you to do something urgent or important, go directly to the company's official website or call their customer service number instead of clicking the link. Type the web address yourself into your browser or look up the phone number on your account statement. This takes an extra minute but protects you from most scams.
Frequently Asked Questions
What does it mean when my browser shows a warning about a website?
Your browser is telling you that the site has been reported as unsafe — usually because it tries to steal information, install malware, or impersonate another company. Do not enter any information on that page. Close the tab and go to the official website by typing the address yourself into your browser or searching for the company name.
Is it safe to click a link if the sender is in my contacts?
Not always. Scammers sometimes hack email or text accounts and send messages from real people you know. If a contact sends you a link that seems out of character or unexpected, ask them about it through a different method before you click. A quick phone call or separate text message can confirm whether they actually sent it.
Can I get hacked just by clicking a link?
Clicking a link itself usually does not hack your device, but it can take you to a fake login page where you enter your password, or to a site that tries to download malware. The danger is what happens after you click, not the click itself. If you click and then close the tab without entering information or downloading anything, you are usually safe.
What is the difference between a phishing link and a malware link?
A phishing link takes you to a fake website designed to steal your login information or payment details. A malware link tries to download and install harmful software on your device. Both are unsafe, but phishing relies on you entering information, while malware can cause damage without your action. Either way, do not click if you are unsure.
Should I report unsafe links I receive?
Yes. Most email providers let you report phishing emails — in Gmail, look for the "Report phishing" option in the three-dot menu. For text messages, you can forward suspicious texts to your carrier's abuse number (usually 7726, which spells SPAM). Reporting helps protect other people and gives companies information about new scams.