Skip to content
FlexibleToolsAI
Security Guide6 min read Updated September 28, 2026

How to Check if a Link Is Safe Before You Click

Phishing links arrive by email, SMS, WhatsApp and Discord, and they're designed to look legitimate. You can check almost any link in under a minute without opening it. Here's how, plus the tell-tale signs that give fake links away.

Quick Takeaway

Don't tap it. Copy the link (long-press on a phone, right-click → Copy link on a computer) and paste it into a URL safety checker, which follows the redirects safely to show where it really goes, how old the domain is, and whether it shows phishing signs. Then check the real domain yourself: in https://paypal.com.secure-login.xyz/ the site is secure-login.xyz, not PayPal. If in doubt, go to the company's website by typing its address.

Check the link without opening it

On a computer, hover over the link to see the real address in the bottom corner of the browser or email app, or right-click → Copy link. On iPhone and Android, long-press the link and choose Copy (don't tap Open).

Paste it into the URL Safety Checker. It never renders the page: our server follows redirects to reveal the final destination, looks up when the domain was registered, and scores it against phishing signals. The Phishing Link Checker explains each trick it finds.

How to read the real domain

The part that matters is the domain just before the first single slash: in https://login.microsoft.com.account-verify.top/signin, the real site is account-verify.top. Everything to the left of it is decoration an attacker can set to anything.

Watch for look-alikes (paypa1.com, rnicrosoft.com), extra words (paypal-security-support.com), unusual endings (.top, .xyz, .zip) for well-known brands, and addresses containing @ — everything before @ is ignored.

Red flags in the message itself

Urgency (“your account will be closed today”), a request to log in, pay, or share a code, a prize you didn't enter, a delivery fee for a parcel you weren't expecting, or a message from a “friend” on a new number. Legitimate companies rarely send login links by SMS.

If you already clicked

If you only opened the page, close it — modern browsers make drive-by infections rare. If you entered a password, change it immediately on the real site (and anywhere you reused it) and turn on two-factor authentication. If you entered card details, call your bank. If you downloaded a file, don't open it; delete it and run a malware scan.

Try Free Web Tools Mentioned in This Guide

Frequently Asked Questions

Can checking a link infect my phone?↓

Copying and pasting a link into a checker is safe — it's just text. Checkers that follow redirects do it from their own servers, not your device.

Are shortened links (bit.ly) dangerous?↓

Not necessarily, but they hide the destination. A URL checker follows the shortener's redirect to reveal where it really goes.

Is a link safe if it has a padlock (HTTPS)?↓

No. HTTPS only means the connection is encrypted — most phishing sites use HTTPS too. Check the domain, not the padlock.

Related Guides