A link is safe to click when it comes from a source you trust, points to where it says it points, and doesn't ask you to do something unusual right away.

The hard part is that scammers have gotten good at making links look trustworthy. A link that appears to be from your bank, your email provider, or a package delivery service might actually lead to a fake website designed to steal your password. The URL in the address bar — the thing that starts with http or https — is the most reliable way to check, but even that requires you to look carefully at what's actually written there, not just what the link text says.

Before you click, you can hover your mouse over the link (without clicking) and look at the bottom left corner of your browser window. Most browsers will show you the actual URL the link points to. If the link text says "Click here to update your Apple ID" but the URL shown at the bottom says something like "find-apple-verify.com" or any domain you don't recognize, that's a red flag. Real links from Apple go to apple.com or a subdomain of apple.com, like support.apple.com.

Key Takeaways

  • Hover over any link before clicking to see the real URL in the bottom left corner of your browser — the link text and the actual destination often don't match in scams.
  • Check the domain name carefully: legitimate links from a company go to that company's actual website, like amazon.com or paypal.com, not to a lookalike domain.
  • Be suspicious of links in unsolicited emails, texts, or pop-ups that ask you to log in, verify your account, or update payment information right away.
  • If you're unsure, close the link and go directly to the company's website by typing the address yourself or using a bookmark you saved before.
  • Shortened links (like bit.ly or tinyurl) hide the real destination, so avoid clicking them unless you know and trust who sent them.

How to read a URL and spot a fake domain

A URL has a specific structure, and scammers exploit the fact that most people don't read it carefully. The part that matters most is the domain name — the main part between "://" and the first single slash. For Amazon, that's amazon.com. For PayPal, that's paypal.com. Anything before the domain (like https:// or www.) or after it (like /account/login) doesn't change which company actually owns the website.

Scammers create domains that look similar to the real thing. They might use "amaz0n.com" (with a zero instead of the letter O), or "paypa1.com" (with the number 1 instead of the letter L). They might also use a real company's name as part of a longer domain, like "paypal-verify.com" or "amazon-security-check.com". None of these are the actual PayPal or Amazon domain. If you're not sure whether a domain is real, type the company name and "official website" into a search engine, or find the company's phone number and call them directly to ask.

What to do when a link asks you to log in or enter sensitive information

Legitimate companies rarely ask you to log in or update sensitive information through a link in an email or text message. If you receive an email claiming to be from your bank, your email provider, or an online retailer, and it includes a link asking you to "verify your account" or "confirm your password," that is almost always a scam. Real companies know that sending login links in email is a security risk, so they avoid it.

If you're concerned that something might actually be wrong with your account — like a suspicious login or an expired payment method — close the email or text and go directly to the company's website by typing the address yourself. Log in normally and check your account settings. If there's a real problem, you'll see a notification when you log in directly. This approach protects you because you're going to the real website, not to wherever the link was trying to take you.

Why shortened links are harder to trust

Services like bit.ly, tinyurl, and short.link create shortened versions of long URLs. They're useful when you need to fit a link into a text message or a social media post, but they hide the real destination from you. When you click a shortened link, you don't see where it's actually taking you until after you've already clicked.

This makes shortened links a favorite tool for scammers. Someone might text you a shortened link and say it's a funny video or an important update, but the real destination could be a malware site or a phishing page. If someone sends you a shortened link and you're not sure who they are or why they're sending it, don't click. If it's someone you know, you can ask them directly what the link is for, or you can use a URL expander tool (search for "expand shortened URL") to see the real destination before you click.

Red flags that suggest a link is a scam

Certain patterns appear again and again in scam links and the messages that contain them. If an email or text claims to be from a company you use, but it uses poor grammar, misspells the company name, or has an unusual tone, that's a warning sign. Scammers often work in other countries and may not write in natural English. If the message creates a sense of urgency — "Your account will be closed in 24 hours" or "Click now to claim your prize" — that's another red flag. Real companies give you time to respond to account issues.

Be especially cautious of links that arrive unexpectedly. If you didn't request a password reset, didn't sign up for a service, and didn't enter a contest, then a link claiming to help you with any of those things is probably not legitimate. Legitimate password reset links usually arrive only after you've requested them, and they typically expire within a few hours. If you receive a password reset link you didn't ask for, that's a sign someone may have tried to access your account, and you should change your password when ready.

How to check a link on your phone

On a smartphone, hovering over a link to see the URL is harder because there's no mouse. Instead, press and hold the link for a second or two. On iPhone, a menu will appear with options including "Copy" and sometimes a preview of the URL. On Android, you'll see similar options. Look at the URL that appears — it should match what the link text claims.

Another approach on a phone is to open your browser's address bar and type the company name directly, rather than clicking a link from an email or text. This takes a few extra seconds but is much safer. If you're not sure whether a link is real, it's always better to navigate to the website yourself than to click and hope for the best.

What to do if you've already clicked a suspicious link

If you clicked a link and realized it looked suspicious, or if you entered your password on a page that might not have been real, don't panic. Close the browser tab or window when ready. If you entered a password, change it as soon as possible — go directly to the real website and update your password from there. Make it something different from what you used before.

If the link took you to a page that asked for credit card information, bank account details, or social security number, and you entered any of that information, contact your bank or credit card company right away. They can monitor your account for fraudulent charges and help you protect yourself. If you're not sure whether the page was real, it's better to call and ask than to assume it was fine. Most companies have fraud departments that handle these situations regularly.

Frequently Asked Questions

Can a link with "https://" at the beginning be a scam?

Yes. The "https://" means the connection is encrypted, which is good for security, but it doesn't mean the website is legitimate. Scammers use https on their fake websites too. The important part is the domain name that comes after "https://". Check that carefully, not just whether the link is encrypted.

What does it mean when a link says "www" in front of the domain?

The "www" is just a subdomain — a section of a larger website. It doesn't change which company owns the site. Amazon.com and www.amazon.com are the same website. What matters is the main domain name, not whether "www" appears in front of it.

Is it safe to click a link from someone I know on social media?

Not always. Scammers sometimes hack into real accounts and send links to all of that person's friends. If a friend sends you a link with no context or with a message that doesn't sound like them, ask them directly before you click. A quick text or call asking "Did you mean to send this?" takes a few seconds and could save you from malware or a phishing scam.

What should I do if I see a suspicious link on a website I'm visiting?

Don't click it. If the website itself looks suspicious — poor design, lots of ads, misspelled words — leave the site entirely. If it's a site you normally trust but something looks off, you can report it to the company. Most websites have a "Report a problem" or "Contact us" link at the bottom of the page.

Can I trust a link if it has a green lock icon next to it?

The green lock means the connection is encrypted, but it doesn't mean the website is safe or legitimate. Scammers can get encryption certificates too. Always check the domain name in the address bar, not just the lock icon. The lock only tells you that your data is encrypted in transit — it doesn't tell you whether you're on the right website.