A link is safe to click when it comes from a source you trust and points to where it says it points
The link itself — the blue underlined text or button — does not tell you much. What matters is where it came from and where it actually goes. A link can look like it goes to your bank's website but actually take you to a fake site designed to steal your password. Or it can come from someone you know whose email account has been hacked. The safest habit is to check before you click, not after.
You have three ways to do this: look at the sender, check where the link actually points, and notice what the link asks you to do. None of them require special software or technical knowledge.
Key Takeaways
- Hover your mouse over a link to see the real web address it points to — if the address does not match what the link text says, do not click it.
- Links from people you know are safer than links from strangers, but a hacked email account can send a dangerous link from a trusted name.
- Links that ask you to log in, read something, or act fast are higher risk and deserve extra checking before you click.
- If a link looks suspicious, you can always type the web address directly into your browser instead of clicking the link itself.
Check where the link actually points before clicking
On a computer, move your mouse over the link without clicking. A small box will appear at the bottom left of your screen showing the real web address. On a phone, press and hold the link — a menu will pop up showing the address or an option to "preview link" or "see preview". Look at that address carefully.
The real address should match what the link text promises. If the link says "Click here to log into your bank" but the address shown is something like bankofamerica-find-login.com or bankofamerica.suspicious-site.net, that is a fake. Real bank websites use addresses like bankofamerica.com — the bank's actual name comes first, before any dots. If you see the bank's name anywhere else in the address, or if there are extra words before it, the link is not from the real bank.
Decide how much to trust the sender
A link from someone you know is lower risk than a link from a stranger. But that trust is not absolute. Email accounts get hacked. A message that looks like it came from your friend might actually come from someone who broke into their account. The message might even say something that sounds like your friend — scammers read old emails to learn how people write — but ask you to click a link or read a file.
If you get a link from someone you know but the message seems odd, contact them another way to check. Call them, text them, or send them a message through a different platform. Ask if they really sent that email. Most of the time they will say no, and you will have avoided a problem.
Links from people you have never heard of are riskier still. A stranger's email is more likely to be spam or a scam. You do not owe anyone you do not know a click.
Watch for links that ask you to act fast or give up information
Scammers use urgency to stop you from thinking. A link that says "Your account will be closed in 24 hours — click here now" or "Confirm your password when ready" is trying to scare you into clicking without checking. Real companies do not work that way. Your bank will not threaten to close your account over email and demand you click a link to fix it.
Links that ask you to log in, read something, or enter personal information are higher risk. Before you click, use the hover-and-check method above. If the address does not match the company's real website, do not click. If you are not sure what the real website is, open a new browser tab and type the company name into a search engine. Go to the official website that way instead of clicking the link.
Links in text messages and social media posts follow the same rules. Hover or press and hold to see where they really point. Be especially cautious with links in messages from accounts you do not follow or from people claiming to be customer service — those are common scam tactics.
Recognize when a link is trying to trick you with its appearance
Some links use tricks to look trustworthy. A link might say "Click here to verify your PayPal account" but actually point to a fake PayPal login page. The text looks official, but the address is wrong. This is why checking the real address matters more than the link text.
Another trick is a link that looks short and harmless — like bit.ly/abc123 — but actually points somewhere dangerous. Short links hide where they really go. If you see a short link and you are not sure where it came from, do not click it. You can paste it into a link-checker tool like urlscan.io to see where it points before you click, but the safest choice is usually to skip it.
What to do if you clicked a suspicious link
If you clicked a link and a login page appeared, do not enter your password. Close the browser tab or window when ready. If the page looked like your bank or email, log into the real website separately (by typing the address yourself, not by clicking a link) and check if anything has changed. Change your password if you are worried.
If a file started downloading, do not open it. Delete it from your downloads folder. If you are not sure whether the file is safe, ask someone you trust or contact the company the link claimed to be from — call their main phone number, do not reply to the email.
If you entered a password or personal information before realizing the link was fake, change your password right away. If the fake site asked for credit card information, contact your bank or credit card company to report it.
Frequently Asked Questions
Can a link from my email provider be dangerous?
Yes. Scammers can fake the "from" line in an email to make it look like it came from Gmail, Outlook, or your bank. Always check the real address the link points to, not just who the email says it is from. When in doubt, go to the official website by typing the address yourself.
Is it safer to click a link or type the web address myself?
Typing the address yourself is safer because you control where you go. Clicking a link means trusting that the link points where it says. If you are not sure about a link, open a new tab and type the address instead.
What does HTTPS mean in a web address?
HTTPS means the connection between your computer and the website is encrypted — your information is scrambled so others cannot read it. It is a good sign, but it does not mean the website is trustworthy. A fake bank site can use HTTPS too. Always check that the address matches the real company name.
Should I be suspicious of all links?
Not all links are dangerous, but it costs nothing to check. A quick hover or press-and-hold takes two seconds and can stop you from entering your password on a fake site. Links from trusted sources that point to expected addresses are generally safe to click.
What if I do not recognize the web address a link points to?
Do not click it. If you think it might be legitimate, search for the company name online and go to their official website instead. Real companies want you to reach them through their main website, not through mysterious links in emails.