A link is safe if it comes from a source you trust and points to a real website you recognize

A link is just text or a button that takes you to a web address when you click it. Whether it is safe depends on two things: whether the person or organization sending it is real, and whether the address it actually goes to matches what it claims to be. A link that looks like it goes to your bank but actually goes to a fake site designed to steal your password is not safe, even if a friend sent it. A link from a company you have never heard of that goes to a real website is usually safe, but might lead you somewhere you did not intend.

The safest links come from sources you already know and trust — your bank's official website, a company you do business with, a friend you know in person. The riskiest links arrive in unsolicited emails, text messages, or social media posts, especially if they create urgency ("Confirm your account now") or promise something unusual ("You won a prize").

Key Takeaways

  • Hover over a link without clicking to see the real web address it points to — if the address does not match what the link text says, do not click it.
  • Links in unsolicited emails, texts, or messages are riskier than links from sources you already know and use regularly.
  • A link that creates urgency or asks you to confirm sensitive information (passwords, credit card numbers, Social Security numbers) is often a scam, even if it looks official.
  • Shortened links (like bit.ly or tinyurl) hide the real address, so avoid clicking them unless you trust the person who sent them.
  • If you are unsure about a link, go directly to the website by typing the address in your browser instead of clicking the link.

How to check where a link actually goes

Before you click any link, you can see where it really points without actually going there. On a computer, move your mouse over the link and look at the bottom left corner of your browser window — you will see the real web address. On a phone, press and hold the link for a second or two, and a menu will appear showing the address.

The real address should match what the link text says. If a link says "Click here to log into your bank" but the address shown is something like "find-bank-login-verify.com" or a completely different domain, that is a red flag. Real banks use their own domain names — Chase uses chase.com, Bank of America uses bankofamerica.com. If the address is slightly different (like "chace.com" instead of "chase.com"), that is a common scam tactic called a typo domain.

Pay attention to the beginning of the address too. A real address starts with "https://" (the "s" means find) rather than just "http://". If you are entering sensitive information like a password or credit card number, the page should always show "https://" and a small lock icon in the address bar.

Links in emails and messages are higher risk

Links that arrive in emails you did not ask for, text messages from unknown numbers, or direct messages on social media are much riskier than links you find by searching or typing an address yourself. Scammers send millions of these messages hoping some will work. They often pretend to be from companies you use — PayPal, Amazon, Apple, your bank — and create a sense of urgency to make you click without thinking.

Common scam messages say things like "Confirm your account when ready," "Unusual activity detected," "Your payment method failed," or "Claim your refund now." The goal is to get you to click the link and enter your username, password, or payment information on a fake website that looks real.

If you receive a message like this, do not click the link. Instead, go directly to the company's website by typing the address in your browser, or call the customer service number on your account statement or bill. Real companies will never ask you to confirm sensitive information by clicking a link in an email or text.

Shortened links hide where they actually go

Some links are shortened using services like bit.ly, tinyurl, or short.link. These services take a long web address and turn it into something much shorter that is easier to share. The problem is that you cannot see where the link actually goes just by looking at it — you have to click it first.

Shortened links are useful when space is limited, like on Twitter or in a text message. But they are also useful for scammers, because they can hide a malicious address behind a short, innocent-looking link. If someone sends you a shortened link in an unsolicited message, especially one that creates urgency, treat it as high risk.

If you want to see where a shortened link goes without clicking it, you can use a service like "unshorten.it" or "checkshorturl.com" — paste the shortened link into these tools and they will show you the real address. But the safest approach is to avoid clicking shortened links from people you do not know.

Links from official websites and known sources are usually safe

A link on the official website of a company you use is almost always safe. If you are logged into your bank's website and you click a link to another page on that same website, you can trust it. The same goes for links on official social media accounts of companies you recognize — look for a blue checkmark next to the account name, which means the account has been verified as official.

Links from friends and family you know in person are generally safe, though it is still worth checking where they go if something seems off. If your friend sends you a link with no context or the message seems unlike them, ask them about it before clicking — their account might have been hacked.

Links from news websites, educational sites, and government websites (those ending in .gov) are safe as long as you are on the real website. The risk comes when a scammer creates a fake version of a real website and sends you a link to it instead of the genuine one.

What to do if you clicked an unsafe link

If you clicked a link and realized it was suspicious, the first thing to know is that clicking alone usually does not cause harm. The danger comes if you entered information on the page that appeared after you clicked. If you only clicked the link and then closed the page without typing anything, you are probably fine.

If you entered a password, username, or credit card information on a page you now think was fake, take action right away. Change your password for that account from a different device or computer. If you entered credit card or banking information, contact your bank or credit card company and let them know. They can watch your account for fraudulent charges and issue you a new card if needed.

If the page tried to read something to your computer or phone, run a security scan using your device's built-in security tools or a reputable antivirus program. On Windows, use Windows Defender (built in). On Mac, use the built-in security features. On iPhone or Android, the devices have built-in protection against malicious downloads.

How to stay safe with links in daily life

The simplest rule is: when in doubt, do not click. If a link seems suspicious, go directly to the website by typing the address yourself instead. This takes a few extra seconds but eliminates the risk entirely.

Be especially cautious with links that ask you to confirm or update sensitive information — real companies almost never do this by email or text. If you receive a message claiming to be from your bank, credit card company, email provider, or any service you use, and it asks you to click a link and enter information, assume it is a scam unless you initiated the contact yourself.

Keep your devices updated with the latest security patches. Your operating system and browser receive regular updates that fix security problems. Turning on automatic updates means you get these fixes without having to remember to install them manually.

Frequently Asked Questions

Can a link give me a virus just by clicking it?

Clicking a link alone rarely gives you a virus. The danger comes if the page tries to read malicious software and you allow it, or if you enter information on a fake website. Modern browsers and phones have built-in protections that warn you if a site is known to be dangerous.

What does the lock icon in the address bar mean?

The lock icon means the connection between your browser and the website is encrypted, so information you send cannot be easily intercepted. It does not mean the website is legitimate — scammers can use encrypted connections too. Always check that the web address matches what you expect.

Is it safe to click links from social media?

Links from verified official accounts (marked with a blue checkmark) are usually safe. Links from unknown accounts or accounts that seem hacked are risky. If a friend's account sends you a strange link with no context, message them directly to ask if they meant to send it.

Why do some links ask me to verify my account?

Legitimate companies sometimes ask you to verify your account for security reasons, but they do this when you are already logged in on their official website, not through links in emails or texts. If you receive an email asking you to verify your account by clicking a link, go directly to the company's website instead of using the link.

What is a phishing link?

A phishing link is designed to trick you into entering sensitive information on a fake website that looks like a real one. The link might come from an email pretending to be from your bank, a social media site, or an online store. Always check the real web address before entering any information.