How to spot a dangerous link before it harms your device
A safe link takes you where it says it will, doesn't install anything without your permission, and doesn't trick you into giving up passwords or money. A dangerous one does the opposite — it might look like a bank login but steal your credentials, or it might download malware that runs silently in the background.
You can check a link's safety in about 30 seconds by looking at three things: where it actually goes (not where it claims to go), whether the destination site uses encryption, and whether security tools have flagged it. This matters because the link itself is often how malware and phishing attacks reach you — more than email attachments or pop-ups.
Key Takeaways
- Hover over a link to see its real destination before clicking; if the URL doesn't match the link text, do not click it.
- Check whether a website uses encryption by looking for "https://" and a padlock icon in your browser's address bar.
- Use Google Safe Browsing, Microsoft Defender SmartScreen, or a dedicated tool like URLhaus to check whether security researchers have flagged a link as malicious.
- Shortened links (bit.ly, tinyurl) hide the real destination, so expand them before clicking if you are unsure about the source.
- Links in unsolicited messages — texts, emails, social media DMs — are higher risk even if they look legitimate, because attackers often impersonate trusted senders.
Hover over the link to see where it actually goes
The text of a link can say anything. A link might display "Click here to reset your bank password" but actually point to a fake website designed to steal your login. The only way to know the real destination is to hover your mouse over the link without clicking.
On Windows, move your mouse over the link and wait a moment — the real URL appears in a small box at the bottom left of your browser window. On Mac, the same information appears at the bottom left of the screen. On a phone, press and hold the link (do not tap it) and a menu will show the destination URL. If the URL doesn't match what the link text promises, or if it looks suspicious (misspelled domain names, unusual characters, or a domain you don't recognize), do not click it.
Common red flags in URLs include domains that misspell well-known company names (like "amaz0n.com" instead of "amazon.com"), URLs that use IP addresses instead of domain names, or links that contain suspicious parameters like "?redirect=" or "?login=" followed by another URL.
Check for encryption and a valid certificate
Legitimate websites that handle sensitive information use HTTPS encryption, which scrambles data between your device and the website so attackers cannot intercept it. Before you enter a password, credit card number, or personal information, confirm the site is encrypted.
Look at your browser's address bar. If the URL starts with "https://" (not "http://"), the connection is encrypted. You should also see a padlock icon next to the URL — click it to view the certificate details. The certificate should show the name of the organization that owns the site. If the certificate name doesn't match the domain (for example, a certificate for "paypal.com" appearing on a site claiming to be PayPal but using a different domain), the site is not legitimate.
HTTPS alone does not mean a site is safe — attackers can obtain valid certificates for fake sites. But the absence of HTTPS is a strong warning sign, especially for any site asking for passwords or payment information. If a site lacks HTTPS and is asking for sensitive data, do not proceed.
Use a link checker tool to scan for known malware
Security researchers and antivirus companies maintain databases of URLs that have been flagged as malicious. You can check whether a suspicious link appears in these databases before you click it.
Google Safe Browsing is built into Chrome, Edge, and Firefox — if you land on a flagged site, your browser will show a warning page. You can also check a link manually by visiting google.com/safebrowsing/report and pasting the URL. Microsoft Defender SmartScreen works similarly in Edge and Windows. URLhaus (urlhaus.abuse.ch) is a free tool run by security researchers that lets you paste a URL and see whether it has been reported as hosting malware or phishing pages.
These tools are not perfect — new malicious sites appear constantly, and some dangerous links may not yet be flagged. But they catch a large portion of known threats. If a tool flags a link as malicious, do not click it under any circumstances.
Expand shortened links to see the real destination
Shortened links (created by services like bit.ly, tinyurl, or short.link) hide the real URL behind a short code. This is useful for sharing long links, but it also makes it easy for attackers to disguise malicious destinations. A shortened link might display as "bit.ly/abc123" but actually point to a phishing site.
Before clicking a shortened link from an untrusted source, expand it to see the real destination. Paste the shortened URL into a tool like unshorten.me or expandurl.com, and the tool will show you the full URL without taking you there. If the expanded URL looks suspicious, do not click the original shortened link.
Shortened links from trusted sources (like your employer's official social media account or a news outlet you recognize) are lower risk, but expanding them is still a good habit if you are unsure.
Be especially cautious with links in messages
Links in unsolicited emails, text messages, social media DMs, and chat apps are higher risk because attackers often impersonate trusted senders. A message might appear to come from your bank, PayPal, or a colleague, but the sender's address or account may be spoofed or compromised.
If you receive a message asking you to click a link and take urgent action — reset your password, confirm your account, update payment information — stop and verify the sender independently. Do not use the link in the message. Instead, go directly to the official website by typing the address into your browser, or call the organization's phone number from their official website. Legitimate companies do not ask you to click links in unsolicited messages to verify sensitive information.
This applies even if the message looks professional and the sender's name appears correct. Attackers can spoof email addresses and create convincing fake messages. When in doubt, contact the organization through a channel you know is legitimate.
What to do if you clicked a suspicious link
If you clicked a link and a page loaded that looked suspicious, or if your browser showed a malware warning, close the page immediately. Do not enter any information or download anything. Close the browser tab or window.
If the page asked you to enter a password or credit card number before you realized it was fake, change that password immediately from a different device or a trusted computer. If you entered a credit card number, contact your bank or card issuer right away. If you downloaded a file, run a full antivirus scan on your device — use Windows Defender (built into Windows) or a third-party tool like Malwarebytes.
If you are unsure whether your device was infected, you can also take your computer to a local repair shop for a professional scan, or contact your device manufacturer's support line for guidance.
Frequently Asked Questions
Can a link be safe even if it doesn't have HTTPS?
Yes, but only for pages that do not ask for sensitive information. A news article or blog post without HTTPS is generally safe to read. But if a site asks for a password, credit card, or personal information and lacks HTTPS, do not enter anything. Legitimate financial and healthcare sites always use HTTPS.
What if the link looks legitimate but my browser still warns me?
Trust your browser's warning. If Chrome, Edge, or Firefox shows a "Deceptive site" or "Malware detected" message, the link has been flagged by security researchers. Do not proceed, even if the page looks professional or you recognize the domain name. Attackers can create very convincing fake sites.
Is it safe to click a link from someone I know on social media?
Not always. Accounts can be hacked or compromised, and attackers can send messages that appear to come from your contacts. If a friend sends you a link that seems out of character or asks you to click urgently, message them separately (through a different platform or by phone) to confirm they sent it before clicking.
Do I need to install anything to check if a link is safe?
No. Your browser's built-in security tools (Google Safe Browsing, SmartScreen) work automatically. Free online tools like URLhaus and unshorten.me require no installation. You do not need to buy special software to check links safely.
What is the difference between a phishing link and a malware link?
A phishing link takes you to a fake website designed to steal your login credentials or personal information. A malware link downloads software that can harm your device or steal data. Both are dangerous, but phishing tricks you into giving information willingly, while malware works without your knowledge.