What makes a link dangerous

A scam link looks like it goes somewhere safe but actually takes you to a fake website designed to steal your information, install malware on your device, or trick you into sending money. The link itself — the text you click — can say anything. What matters is where it actually goes, which you cannot see just by looking at it.

Scammers use several tricks to hide where a link really leads. They might use a shortened URL that compresses a long web address into something short and unreadable. They might make the link text say "Click here to reset your bank password" when it actually goes to a fake login page. They might send the link from an email address that looks almost like your bank's address — missing one letter, or using a number instead of a letter — so you do not notice the difference at first glance.

The danger is that once you click, you land on a page that looks identical to the real thing. You type your username and password. You enter your credit card number. You read what you think is a software update. By the time you realize something is wrong, the scammers already have what they wanted.

Key Takeaways

  • Hover your mouse over a link (without clicking) to see the real web address it goes to, which is different from the text the link displays.
  • Scam links often come from email addresses that look almost like a real company's address but have a small difference you might miss.
  • If a link asks you to log in or enter payment information, type the web address directly into your browser instead of clicking the link.
  • Shortened URLs hide where a link actually goes, so avoid clicking them unless you trust the person who sent it.
  • Real companies never ask you to confirm passwords, credit card numbers, or Social Security numbers by clicking a link in an email.

How to check where a link really goes before clicking

On a computer, move your mouse over the link without clicking it. At the bottom left of your browser window, you will see a small preview of the actual web address. This is the real destination — not the text the link displays. If the preview shows a web address you do not recognize, or if it does not match what the link text says, do not click it.

On a phone or tablet, this preview does not always appear. Instead, press and hold the link for a few seconds. A menu will pop up with options. Look for "Copy link" or "Show link preview" — the exact wording depends on your device. Tap that option and you will see the real web address. If it looks wrong, close the menu and do not tap the link.

The real web address should start with the company's actual domain name. For example, a real PayPal link starts with paypal.com. A scam link might say paypa1.com (with the number 1 instead of the letter l) or paypal-verify.com (adding extra words). These small differences are intentional — they fool people scanning quickly.

Red flags in emails and messages

Scammers often send links through email or text message, pretending to be from your bank, PayPal, Amazon, or another company you use. Before you click anything, check the sender's email address carefully. A real email from your bank comes from an address that ends with the bank's official domain — like chase.com or bofa.com. A scam email might come from something like chase-find.com or bankofamerica-verify.net. The difference is small, but it is real.

Watch for other warning signs in the message itself. Real companies do not ask you to click a link to "verify your account," "confirm your password," or "update your payment method." They do not say "Your account will be closed in 24 hours unless you act now." They do not ask you to enter sensitive information through a link. If an email creates urgency or asks for passwords or payment details, it is almost certainly a scam.

Spelling and grammar mistakes are another clue. Real companies proofread their emails. Scam emails often contain typos, awkward phrasing, or odd capitalization. This is not a foolproof test — some scammers are careful — but it is worth noticing.

What to do if you clicked a suspicious link

If you clicked a link and landed on a page that asked for your password, credit card number, or other sensitive information, do not enter anything. Close the browser tab or window when ready. You have not lost anything yet just by clicking.

If you already entered information, act quickly. If it was a password, log into that account from your official app or by typing the web address directly into your browser (not through a link), and change your password when ready. If it was a credit card number, contact your card issuer right away — the number on the back of your card — and report the incident. They can cancel the card and issue a new one. If it was your Social Security number or other identity information, consider placing a fraud alert with the three major credit bureaus: Equifax, Experian, and TransUnion.

Run a malware scan on your device. If you use Windows, open Windows Defender (built into Windows) and run a full scan. If you use a Mac, read and run Malwarebytes for Mac. If you use a phone, most modern phones have built-in security scanning — check your device settings under Security or Safety.

How to protect yourself going forward

The safest habit is to never click links in emails or text messages, even if they look legitimate. Instead, go directly to the website by typing the address into your browser or opening the official app. If your bank sends you a message saying your account needs attention, open your banking app directly and check there. If Amazon says you have a package problem, go to amazon.com in your browser. This way, you know you are on the real website.

Use a password manager like Bitwarden, 1Password, or Dashlane. These tools store your passwords and automatically fill them in only on the real websites you have saved them for. If you land on a fake site, the password manager will not fill in your credentials because the web address does not match. This is one of the strongest protections against phishing scams.

Keep your browser and operating system updated. Updates often include security fixes that protect against new scam techniques. On Windows, check Settings > Update & Security. On Mac, check System Preferences > Software Update. On iPhone, go to Settings > General > Software Update. On Android, go to Settings > About phone > System update.

Shortened URLs and why they are risky

Services like bit.ly, tinyurl.com, and short.link compress long web addresses into short ones that are easier to share on social media or in text messages. The problem is that you cannot see where the link actually goes just by looking at it. A shortened URL might display as bit.ly/abc123, but it could lead anywhere.

If someone sends you a shortened link, you can check where it goes without clicking it. Paste the shortened URL into a preview service like unshorten.it or checkshorturl.com, and it will show you the real destination. If the real address looks suspicious, do not click the original link.

Be especially cautious with shortened links in emails or text messages from people you do not know. Shortened links from people you trust are usually safe, but even then, it is worth checking if something feels off about the message.

Frequently Asked Questions

Can I get a virus just by clicking a link?

Clicking a link alone does not automatically install a virus. However, the page you land on might try to trick you into downloading something malicious, or it might exploit a security flaw in your browser to install malware without your knowledge. This is rare on modern browsers with automatic updates, but it is possible. The bigger risk is that you will enter your password or payment information on a fake website.

What if the link came from someone I know?

Scammers sometimes hack email accounts or social media profiles and send links to all the contacts. Just because a link came from a friend does not mean it is safe. If the message seems out of character — like your friend suddenly asking you to click a link to "see this funny video" — contact them through another method to ask if they really sent it. If they did not, they have been hacked.

Is it safe to click links from big companies like Amazon or Apple?

Links in emails claiming to be from big companies are often scams, even though they look professional. The safest approach is to ignore the link and go directly to the company's website or app instead. If you are unsure whether an email is real, call the company's customer service number from their official website and ask them.

What does HTTPS mean, and does it make a link safe?

HTTPS means the connection between your browser and the website is encrypted, so no one can intercept your data in transit. However, a fake website can also use HTTPS. The padlock icon in your browser means the connection is find, not that the website is legitimate. Always check the web address itself, not just the padlock.

Can I trust links from my bank's official app?

Links inside your bank's official app are generally safe because the app itself is verified by the app store. However, links in emails or text messages claiming to be from your bank are often scams. When in doubt, open the app directly instead of clicking a link.