How to Check if a Link Is Safe Before You Click
Phishing links arrive by email, SMS, WhatsApp and Discord, and they're designed to look legitimate. You can check almost any link in under a minute without opening it. Here's how, plus the tell-tale signs that give fake links away.
Don't tap it. Copy the link (long-press on a phone, right-click → Copy link on a computer) and paste it into a URL safety checker, which follows the redirects safely to show where it really goes, how old the domain is, and whether it shows phishing signs. Then check the real domain yourself: in https://paypal.com.secure-login.xyz/ the site is secure-login.xyz, not PayPal. If in doubt, go to the company's website by typing its address.
Check the link without opening it
On a computer, hover over the link to see the real address in the bottom corner of the browser or email app, or right-click → Copy link. On iPhone and Android, long-press the link and choose Copy (don't tap Open).
Paste it into the URL Safety Checker. It never renders the page: our server follows redirects to reveal the final destination, looks up when the domain was registered, and scores it against phishing signals. The Phishing Link Checker explains each trick it finds.
How to read the real domain
The part that matters is the domain just before the first single slash: in https://login.microsoft.com.account-verify.top/signin, the real site is account-verify.top. Everything to the left of it is decoration an attacker can set to anything.
Watch for look-alikes (paypa1.com, rnicrosoft.com), extra words (paypal-security-support.com), unusual endings (.top, .xyz, .zip) for well-known brands, and addresses containing @ — everything before @ is ignored.
Red flags in the message itself
Urgency (“your account will be closed today”), a request to log in, pay, or share a code, a prize you didn't enter, a delivery fee for a parcel you weren't expecting, or a message from a “friend” on a new number. Legitimate companies rarely send login links by SMS.
If you already clicked
If you only opened the page, close it — modern browsers make drive-by infections rare. If you entered a password, change it immediately on the real site (and anywhere you reused it) and turn on two-factor authentication. If you entered card details, call your bank. If you downloaded a file, don't open it; delete it and run a malware scan.
Try Free Web Tools Mentioned in This Guide
URL Safety Checker
Check if a link is safe: see where it really goes, domain age, and phishing and malware warning signs.
Phishing Link Checker
Analyse a suspicious link for phishing tricks: look-alike domains, hidden destinations and new domains.
SSL Checker
Check a site's SSL/TLS certificate, chain, expiry, TLS versions, HTTPS redirect and HSTS.
What Is My IP Address
See your public IP address, IPv4/IPv6, country and privacy signals — plus a WebRTC leak test.
Frequently Asked Questions
Can checking a link infect my phone?↓
Copying and pasting a link into a checker is safe — it's just text. Checkers that follow redirects do it from their own servers, not your device.
Are shortened links (bit.ly) dangerous?↓
Not necessarily, but they hide the destination. A URL checker follows the shortener's redirect to reveal where it really goes.
Is a link safe if it has a padlock (HTTPS)?↓
No. HTTPS only means the connection is encrypted — most phishing sites use HTTPS too. Check the domain, not the padlock.