Check a link before clicking by using a URL scanner, looking at the sender's email address, and reading what comes before the domain name
A suspicious link is one of the fastest ways malware, ransomware, or spyware gets onto your computer. You do not have to click blindly. Three practical checks take less than a minute and catch most dangerous links: scan the URL with a free tool, verify the sender is actually who they claim to be, and read the full web address carefully instead of just the text the sender wrote.
The goal is not to be paranoid about every link. It is to slow down enough to notice when something looks off — a link from your bank that goes to a weird address, a file read from someone you do not know, or a message that creates pressure to click fast.
Key Takeaways
- Paste any suspicious link into Google Safe Browsing or VirusTotal to see if security researchers have flagged it as malicious.
- Hover over a link (do not click) to see the actual web address in the bottom left corner of your browser, which often differs from the text shown.
- Check the sender's full email address, not just their name — attackers often use addresses that look similar to legitimate ones but have a slight difference.
- Be skeptical of links in unexpected messages, especially ones that create urgency or ask you to confirm a password or payment information.
- If you accidentally click a dangerous link, close the browser tab when ready and run a scan with your antivirus software.
Use a free URL scanner to check before you click
Google Safe Browsing and VirusTotal are both free tools that check whether a link has been reported as malicious. You do not need to click the link yourself — you paste the web address into the scanner and it tells you what it found.
To use Google Safe Browsing, go to safebrowsing.google.com, paste the link into the search box, and click "Check". It will tell you if the site is flagged as unsafe. VirusTotal (virustotal.com) does the same thing but scans the link against 90 different security vendors at once, so it catches more threats. Paste the link, press Enter, and wait a few seconds for the results.
These tools are most useful for links you are unsure about — a read link from an email you did not expect, a shortened URL from a stranger, or a link in a message that seems off. They are not perfect (a new malicious site might not be flagged yet), but they catch the majority of known threats.
Hover over the link to see where it actually goes
Attackers often hide the real web address by writing friendly text over a dangerous link. The link might say "Click here to reset your password" but actually point to a fake login page designed to steal your credentials. You can see the real address without clicking by hovering your mouse over the link.
In most browsers, when you hover over a link, the actual web address appears in the bottom left corner of the screen. Read it carefully. Does it match the organization it claims to be from? Does it have any misspellings or odd characters? If the link says it is from your bank but the address is something like "bankofamerica-find-verify.ru", that is a red flag.
This works in email, on websites, and in messages. Get in the habit of hovering before clicking, especially on links that ask you to log in, confirm payment information, or read something.
Check the sender's full email address, not just their name
Attackers create email addresses that look almost identical to legitimate ones. An email might appear to come from "Amazon" but the actual address is "amaz0n@fakesite.com" (with a zero instead of the letter O). You only see the real address if you look at the full sender information, not just the display name.
In Gmail, click the down arrow next to the sender's name to see their full email address. In Outlook, right-click the sender and select "View Message Details". In Apple Mail, go to the View menu and select "Show All Headers". Look at the "From" field — that is the actual email address. If it does not match the organization it claims to be from, it is almost certainly a phishing attempt.
Legitimate companies like Amazon, PayPal, and your bank always email you from their own domain (the part after the @). If you get an email claiming to be from your bank but it comes from a Gmail address or a domain you do not recognize, do not click any links in it.
Watch for pressure tactics and unusual requests
Dangerous links often arrive in messages designed to make you act without thinking. The email says your account has been compromised and you must click now, or your package is about to be returned and you need to confirm your address when ready, or you have won a prize but the offer expires today. These are pressure tactics.
Legitimate organizations rarely create artificial urgency around links. Your bank will not threaten to close your account if you do not click a link in an email. Amazon will not ask you to confirm your password by clicking a link. If a message creates panic or pressure, slow down and check the sender's address and the link itself before you click.
The same applies to requests for sensitive information. No legitimate company asks you to confirm your password, Social Security number, or credit card details by clicking a link in an email or text message. If a link asks for that information, it is a phishing attempt.
What to do if you clicked a dangerous link
If you realize after clicking that a link was malicious, close the browser tab when ready. Do not fill in any forms or read anything. Then run a full scan with your antivirus software — Windows Defender (built into Windows), Malwarebytes, or Avast all have free versions that scan for threats.
If the link took you to a fake login page and you entered your password, change that password as soon as possible from a different device. If you entered credit card or banking information, contact your bank or credit card company directly (use the number on the back of your card, not a number from the suspicious site) and let them know.
Most of the time, clicking a link does not when ready infect your computer. The danger comes when you read a file from the link, fill in a form, or enter credentials. If you closed the tab without doing any of those things, you are likely fine — but running a scan gives you confirmation.
Shortened URLs and QR codes hide the real address
Shortened URLs (created with bit.ly, tinyurl.com, or similar services) and QR codes hide the actual web address. You cannot hover over them to see where they go. This makes them useful for legitimate purposes — sharing long links on social media — but also useful for attackers.
If you receive a shortened URL or QR code from someone you do not know, or in a message that seems suspicious, do not scan or click it. If you receive one from someone you trust but it seems out of character (your friend suddenly sending you a random link), ask them directly whether they meant to send it.
Some URL expanders (like expandurl.com) let you see where a shortened link goes without clicking it. Paste the shortened URL and it shows you the real address. This is useful if you are curious about a link but do not want to click it directly.
Frequently Asked Questions
Can I get malware just by hovering over a link?
No. Hovering over a link does not execute anything — it only shows you the address. You have to click the link or read a file from it for malware to reach your computer. Hovering is safe.
What if a link looks safe but my antivirus blocks it anyway?
Trust your antivirus. It may have detected something that is not yet widely known, or the site may have been compromised recently. If you need to visit the site, contact the organization directly using a phone number or address you find independently, rather than using contact information from the suspicious link.
Is it safe to click links in text messages from unknown numbers?
No. Text message links are a common way attackers deliver malware and phishing pages. If you get a text from an unknown number with a link, delete it. If it claims to be from a company you use, go to that company's website directly instead of clicking the link.
Do I need to scan every single link I click?
No. Scanning is most useful for links you are unsure about — unexpected downloads, links from strangers, shortened URLs, or messages that seem off. Links from people you know and trust, and links on established websites you visit regularly, are generally safe without scanning.
What is the difference between Google Safe Browsing and VirusTotal?
Google Safe Browsing checks against Google's own database of malicious sites. VirusTotal scans against 90 different security vendors, so it catches more threats but can also produce false alarms. For most purposes, either one works — VirusTotal is more thorough if you want to be extra careful.