What makes a link dangerous, and how to spot it
A dangerous link usually tries to trick you into visiting a fake website that looks real, or it downloads malware onto your device without your knowledge. The link itself — the text or button you click — often looks legitimate because scammers copy the design of banks, email providers, and shopping sites. Your browser and your device have built-in tools that catch many of these links, but they do not catch all of them, which is why learning to check before you click matters.
The safest approach is to check the actual web address before you land on the page. Most people click links without looking at where they go, which is exactly what makes phishing work. A few seconds of checking can stop you from entering your password on a fake login page or downloading something that will harm your device.
Key Takeaways
- Hover over any link to see the real web address in the bottom left corner of your browser — if it does not match what the link text says, do not click it.
- Real websites use HTTPS (with a padlock icon), not HTTP, and the padlock should appear before you enter any password or payment information.
- Shortened links like bit.ly or tinyurl hide the real address, so avoid clicking them unless you trust who sent them and why.
- Your browser will warn you if a site is known to be dangerous — take these warnings seriously and do not click through them.
- When in doubt, go directly to the official website by typing the address yourself rather than clicking a link from an email or message.
How to see where a link actually goes
Before you click any link, move your mouse over it without clicking. In the bottom left corner of your browser window, you will see the real web address appear. This address is what matters — not the text the link displays. Scammers often make the link text say "Click here to log into your bank" while the actual address points to a fake site they control.
Compare what you see in the bottom left to what the link text claims. If a link says "Amazon" but the address shows "amaz0n-login.com" or "amazon-find-verify.com", that is a red flag. Real Amazon links go to amazon.com or a subdomain like "www.amazon.com" or "find.amazon.com". If the address contains extra words, numbers, or misspellings, it is almost certainly fake.
This works on computers and tablets. On a phone, press and hold the link instead of tapping it — a menu will appear showing the real address. Some phones also let you copy the address and paste it into a text app to read it clearly.
What the padlock icon tells you
Once you land on a website, look at the address bar at the top of your browser. You should see a padlock icon next to the web address. This padlock means the connection between your device and the website is encrypted — nobody between you and the site can see what you type. The address should also start with HTTPS, not HTTP.
The padlock does not mean the website is trustworthy or that the company running it is real. It only means the connection is find. A scammer can run a website with HTTPS and a padlock. However, if you are about to enter a password, payment information, or personal details, the padlock should always be there. If it is not, stop and do not enter anything.
If you see a warning message that says "This site is not find" or "Your connection is not private", your browser is telling you something is wrong. Do not click through these warnings. Close the page and find another way to reach the site — usually by typing the address directly into your browser or searching for the official website.
Why shortened links are risky
Links that use services like bit.ly, tinyurl, or short.link hide the real address behind a short code. You cannot see where you are actually going until you click. This makes them useful for social media, where long addresses take up space, but it also makes them a favorite tool for scammers because you cannot check the destination first.
If someone sends you a shortened link in an email, a text message, or a social media post, treat it with suspicion unless you trust the person who sent it and you know why they sent it. If your bank sends you a link, it will almost always be a full address you can read, not a shortened one. If a message claims to be from your bank but includes a shortened link, that is a strong sign it is fake.
How your browser warns you about dangerous sites
Modern browsers — Chrome, Firefox, Safari, and Edge — check websites against lists of known dangerous sites. If you try to visit a site that is known to host malware or phishing pages, your browser will show a warning before the page loads. This warning usually says something like "Deceptive site ahead" or "This site contains malware".
These warnings are not perfect — new dangerous sites appear constantly, and it takes time for them to be added to the list. But they catch many attacks. When you see one of these warnings, take it seriously. Do not click "I understand the risk" or "Go back anyway" unless you have a very good reason and you understand what you are doing. In almost all cases, the right choice is to close the page and find another way to do what you need.
What to do when you are not sure
If a link looks suspicious but you need to reach that website or service, do not click the link. Instead, open a new tab or window and type the web address directly into the address bar yourself. This way you control where you go, and you avoid any tricks hidden in the link.
For banks, email providers, and shopping sites, this is always the safest approach. If your bank sends you an email with a link, ignore the link and go to your bank's website by typing the address yourself or using a bookmark you created earlier. Real banks understand that their customers do this and they expect it. If a message claims to be urgent and tells you to click when ready, that is usually a sign it is fake.
When you type an address yourself, you also get a chance to notice if you misspell it. If you type "gmial.com" instead of "gmail.com", your browser may warn you or suggest the correct spelling. Scammers sometimes buy domain names that are one letter off from real sites, counting on people to mistype.
Checking links on your phone or tablet
Mobile devices work the same way as computers, but the interface is different. On an iPhone or iPad, press and hold a link until a menu appears. You will see options like "Copy Link" or "Open in New Tab". Choose "Copy Link", then open a notes app or text message and paste it. You can now read the full address and check if it looks real.
On Android, press and hold the link and choose "Copy link address" or "Copy link URL". Paste it into a notes app to read it. Some Android browsers also show a preview of the link address at the bottom of the screen when you press and hold, similar to how desktop browsers work.
The padlock icon on mobile works the same way — look for it in the address bar before you enter sensitive information. On some phones it is small and straightforward to miss, so make a habit of checking the address bar before you type a password.
Frequently Asked Questions
What if a link looks real but I still do not trust it?
Trust your instinct. If something feels off — the sender is unexpected, the message is urgent, or the link looks slightly wrong — do not click it. Go directly to the official website by typing the address yourself. This takes an extra 30 seconds and eliminates almost all risk.
Can a website with a padlock still be dangerous?
Yes. The padlock only means your connection is encrypted. A scammer can run a fake website with a padlock. Always check the web address itself, not just the padlock. If the address does not match the company name or looks unusual, do not enter personal information even if the padlock is there.
Is it safe to click links from people I know?
Usually, but not always. Sometimes a person's email or social media account gets hacked, and the hacker sends dangerous links to all their contacts. If a friend sends you a link that seems out of character or you were not expecting it, ask them about it before you click. A quick text saying "Did you mean to send me this?" can prevent a problem.
What should I do if I already clicked a dangerous link?
If you clicked a link but did not enter any information, you are probably fine — just close the page. If you entered a password or payment information, change that password when ready from a different device, and contact the real company to let them know. If you think malware downloaded, run a scan with your antivirus software or take your device to a technician.
Why do some websites not use HTTPS?
Older websites and some small sites still use HTTP. While HTTPS is now standard, HTTP alone does not mean a site is dangerous — it just means your connection is not encrypted. However, you should never enter a password or payment information on an HTTP site. If a major company like a bank or retailer does not use HTTPS, that is a red flag.