← All posts

How to Check if a Link Is Safe Before You Click It

5 min read

A text says your package is stuck. An email says your account will be closed tonight. A friend's account sends you “is this you in this video?”. Before you tap, a minute of checking tells you most of what you need to know. Here are seven checks, from ten-second ones to thorough ones, and how to look at the page itself without putting your own device at risk.

What a bad link can actually do

  • Phishing is the most common: a fake sign-in or payment page dressed up as your bank, Microsoft, a streaming service or a delivery company. Nothing bad happens until you type something into it.
  • Malware: the page pushes a file, such as an “invoice”, a “video player update” or an app to install. The danger starts when you open it.
  • Browser attacks that work just by visiting are rare and target bugs that updates fix. An up-to-date browser and phone close almost all of them.
  • Confirming you're real: a link made just for you can tell the sender you clicked, which brings more scams.

So the goal is to find out where a link goes and what's there without typing anything, downloading anything or telling the sender you're interested.

1. Read the real address, not the link text

The words you see (“Track your parcel”) can point anywhere. On a computer, rest the mouse on the link and read the address in the bottom corner of the browser. On a phone, press and hold the link to see the address without opening it.

Then find the real site. Take the part between https:// and the next /. The site is its last two parts, or the last three for country endings like .co.uk. Everything before that is decoration the owner of the site can set to anything:

  • https://paypal.com.account-check.co/login is on account-check.co, not PayPal.
  • https://www.amazon.co.uk/orders is on amazon.co.uk.

Watch for lookalikes: arnazon.com (an r and an n posing as an m), paypa1.com (a one instead of an L), extra words such as microsoft-support-desk.com, or a different ending such as .co instead of .com.

2. Expand short links without opening them

Short links (bit.ly, TinyURL and the like) hide the destination on purpose. You can see it first:

  • Bitly: add a + to the end of the link (bit.ly/abc123+) to see where it goes.
  • TinyURL: put preview/ before the code (tinyurl.com/preview/abc123).
  • Any short link: paste it into a link expander such as WhereGoes or Unshorten.me. They follow every redirect on their own servers and show you each stop, which matters because scam links often bounce through several.

3. Ask a free scanner

  • Google Safe Browsing (site status check): tells you whether Google currently flags the site as dangerous. It's the same list behind the red warning pages in Chrome.
  • VirusTotal: checks the address against more than 70 security companies' scanners and blocklists at once. It shares what you submit with those companies.
  • urlscan.io: opens the page in its own browser and shows you a screenshot, every redirect and every server the page contacts. Public scans can be seen by anyone, so choose Private, and never scan a link that contains personal details, like a password-reset link or a shared document.

4. Check how old the site is

Scam sites are often registered days before the message reaches you. Look up the site's name (just the name, like account-check.co) at ICANN Lookup and read the creation date. A bank or shop that has “served you for years” from a site registered last week is a red flag. ICANN Lookup doesn't cover some country endings, such as .de or .uk; for those, use the country's own registry (DENIC for .de, Nominet for .uk).

5. Go the long way round

Don't use the link to check the link. If a message claims to be from your bank, a delivery company or a streaming service, open their app or type their address yourself and look there. If there really is a problem, you'll see it.

Signs the message itself is a scam: a deadline (“within 24 hours”), a threat (account closed, a fine), a small fee to release a parcel, a prize you didn't enter for, a generic greeting, or a sender address that doesn't match the company.

6. Still need to see the page? Open it in a throwaway browser

Sometimes you do need to look: you're the person your family asks, the link came from a client, or you want to report exactly what it does. A cloud browser opens the page on someone else's computer and streams the picture to you.

  • What it protects: anything the page runs or downloads stays on the remote computer. The site sees that computer's internet address, not yours, and a fresh browser with none of your cookies or logins. With MyBrowser, each session runs in its own container that is deleted when the session ends.
  • What it doesn't: if you type a password or card number into a fake page, the scammer gets it, wherever the browser runs. And a file you choose to copy to your own device is on your device.

Open a suspicious link in a throwaway browser

Free, no sign-up: a 3-minute session that’s deleted when it ends. Don’t type passwords or card numbers into a page you’re checking.

7. Already clicked? What to do next

  • You only opened the page: close it and make sure your browser and device are up to date. That's usually all.
  • You typed a password: change it now on the real site (type its address yourself), plus anywhere else you use the same password, and turn on two-step verification.
  • You entered card or bank details: call your bank on the number printed on your card.
  • You downloaded and opened a file: disconnect from the internet and run a full scan (Windows Security or your antivirus). On a work device, tell your IT team right away.
  • Report it: forward phishing emails to reportphishing@apwg.org (as an attachment, if your email app can). In the US, forward scam texts to 7726 and report fraud at reportfraud.ftc.gov. In the UK, forward scam emails to report@phishing.gov.uk and texts to 7726.

The short version

Read where the link really goes (1–2), ask a scanner (3) and check the site's age (4), then go to the real site yourself (5). If you still need to see the page, look from a browser that isn't yours (6), and never type anything into it.