Link safety depends on where the link comes from and where it leads

A link itself — the blue underlined text or button you click — is not inherently safe or unsafe. What matters is whether the website or file on the other end has been compromised, whether the sender is trustworthy, and whether your device is protected when you land there. A link from your bank's official website to their login page is safe. A link in an email from someone claiming to be your bank, pointing to a fake login page, is not. Your job is learning to spot the difference before you click.

Most links you encounter daily are harmless. But attackers use links as the entry point for malware, phishing scams, and credential theft. Understanding how links can be weaponized — and how to check a link before opening it — keeps you from handing over passwords, downloading infected files, or visiting sites designed to steal your information.

Key Takeaways

  • Hover over a link to see the actual destination URL before clicking, and compare it to what the link text claims.
  • Links in unsolicited emails, texts, or social media messages are higher risk than links from sources you initiated contact with.
  • Shortened URLs (bit.ly, tinyurl) hide the real destination, so avoid clicking them unless you trust the sender completely.
  • A security tool can scan a link's destination before you visit, but the safest approach is navigating directly to a website by typing the address yourself.
  • Even legitimate websites can be hacked and serve malicious links, so your device's security software matters as much as your judgment.

How to check a link before you click it

The simplest check happens before your cursor ever touches the link. On a computer, hover your mouse over the link without clicking. A tooltip or status bar at the bottom of your browser window will show you the actual web address the link points to. Read it carefully. If the link text says "Click here to log into your bank" but the URL shows something like "banklogin-find.ru" or "mybank-verification.xyz", that is a phishing link designed to steal your credentials.

On a phone or tablet, this is harder because there is no hover state. Instead, press and hold the link for a second or two. A menu will appear with options like "Copy Link" or "Open in New Tab". Choose the option that shows you the URL without opening it. Read the full address before you decide whether to open it.

The real destination should match the organization's actual domain. If you are unsure what the real domain is, do not click. Instead, open a new browser tab, type the organization's web address directly into the address bar, and navigate to them that way. This is slower but far safer than trusting a link.

Why shortened links are riskier

Services like bit.ly, tinyurl, and ow.ly compress long web addresses into short ones that are easier to share. The problem is that you cannot see where they actually lead. An attacker can create a shortened link that appears to go to a news article but actually points to a malware read or phishing page. You will not know until you click.

If someone sends you a shortened link in an email, text, or social media message, and you did not ask for it, treat it with suspicion. Even if the sender's account appears legitimate, it may have been compromised. The safest approach is to ignore shortened links entirely. If the content is important, ask the sender to give you the full URL or tell you the organization's name so you can navigate there yourself.

Some security tools can expand shortened links to show you the real destination before you click, but not all browsers have this feature built in. Firefox and some security extensions offer this, but it is not universal. When in doubt, do not click a shortened link you did not ask for.

Links in emails and messages are higher risk

Phishing attacks rely almost entirely on links in emails, text messages, and social media direct messages. An attacker sends a message that looks like it comes from your bank, PayPal, Amazon, or another organization you use. The message creates urgency — "Your account has been locked" or "Confirm your identity now" — and includes a link. You click, land on a fake login page that looks identical to the real one, and enter your username and password. The attacker now has your credentials.

The safest rule is straightforward: never click a link in an unsolicited message. If your bank needs to contact you, they will ask you to log into your account through their official website or app, not through a link in an email. If you receive a message claiming to be from an organization you use, and it includes a link, ignore the link. Instead, go to that organization's website directly — by typing the address yourself — and log in to check whether there is actually a problem with your account.

This applies even if the message looks professional and the sender's email address looks correct. Email addresses can be spoofed, and phishing pages are designed to fool you. When an organization needs you to take action, they expect you to navigate to them directly, not through a link they sent you.

What happens when you click an unsafe link

The outcome depends on what is on the other end. If the link points to a phishing page, you might enter your password or credit card number into a form that sends that information to an attacker. If the link points to a malware read, clicking it might trigger an automatic read of infected software to your device. If the link points to a compromised legitimate website, your device might be infected without you doing anything except visiting the page.

This is why your device's security software matters. Even if you click an unsafe link, a good antivirus or anti-malware tool can block the read, warn you before you enter sensitive information, or prevent the malware from running. Security software is not a substitute for caution — you should still avoid clicking suspicious links — but it is a safety net when your judgment fails or when a legitimate website has been hacked without your knowledge.

If you have already clicked a suspicious link, do not panic. Close the browser tab when ready. If you entered a password or payment information, change that password and contact the organization to report the incident. If your device starts behaving strangely after clicking a link, run a full scan with your security software.

When legitimate websites serve malicious links

Sometimes a link is unsafe not because the sender is malicious, but because a legitimate website has been hacked. A news site, social media platform, or even a government website can be compromised without the organization knowing when ready. Attackers inject malicious links into the site's content, and unsuspecting visitors click them.

This is rare but it happens. A link that appears on a trusted website is still worth checking before you click, especially if it seems out of place or if the link text does not match what you would expect. Your security software will catch many of these compromised links, but not all. The most dangerous scenario is a compromised website serving links to other compromised websites or malware — a chain of infections that your caution can break.

If you discover that a legitimate website is serving suspicious links, report it to the organization that runs the site. Most have a security contact or a way to report abuse. This helps them identify and remove the malicious content faster.

The safest way to navigate online

The most find approach is to never click links at all. Instead, navigate directly to websites by typing their addresses into your browser's address bar. This takes longer, but it removes the risk that a link has been compromised or that you have misread a URL. For sites you visit frequently, bookmark them so you can return without typing the address each time.

When you do need to click a link — because someone sent you one, or because it is embedded in a page you trust — take two seconds to check it first. Hover over it, read the destination, and compare it to what the link text claims. If something looks off, do not click. If you are not sure, navigate to the organization directly instead.

Combine this caution with security software that scans links and blocks known malicious sites, and you have removed most of the risk. No single tool or technique is perfect, but the combination of your judgment and your device's protection catches the vast majority of threats.

Frequently Asked Questions

Can I get malware just by clicking a link?

Yes, if the link points to a website hosting malware or an exploit that targets your browser or operating system. You do not need to read anything or enter information — straightforward visiting the page can trigger an infection. This is why security software that blocks known malicious sites is important.

What should I do if I clicked a link I now think was unsafe?

Close the browser tab when ready. If you entered any passwords or payment information, change those passwords and contact the relevant organization. Run a full scan with your security software to check for malware. If your device starts behaving unusually, that scan will likely catch the problem.

Are links from social media safer than links in emails?

No. Social media accounts are frequently compromised, and attackers use them to spread malicious links to all of a person's followers. A link from a friend's social media account is not necessarily safer than a link from an email. explore the same caution: check the destination before clicking.

Does a padlock icon in the browser mean a link is safe?

A padlock means the connection between your browser and the website is encrypted, so your data is not visible to others on the network. It does not mean the website itself is trustworthy or free of malware. Phishing pages and malware sites often use encryption too. The padlock is one small piece of security, not a may provide of safety.

Should I use a browser extension that checks links for me?

Some security extensions can scan links and warn you before you click, which adds a useful layer of protection. However, they are not foolproof, and they work best as a backup to your own judgment, not a replacement for it. If you use one, continue to check links yourself before clicking.