Check a link's destination before clicking

The safest way to check a link is to hover over it without clicking. On a computer, move your mouse over the link and look at the bottom left corner of your browser — you will see the actual web address the link points to. On a phone, press and hold the link; a menu will appear showing the destination URL. If the address looks wrong, misspelled, or unfamiliar, do not click it.

A common trick is a link that says one thing but goes somewhere else. For example, a link might display "PayPal Login" but actually point to a fake site designed to steal your password. Checking the real destination before you click stops this attack cold.

If you have already clicked a suspicious link and landed on a page that asks for your password, credit card, or personal information, close the tab when ready without entering anything. Do not use the back button — close the entire tab.

Key Takeaways

  • Hover over any link to see its real destination in the bottom left corner of your browser, or press and hold on a phone to see a preview menu.
  • Legitimate companies never ask for passwords or credit card numbers through email links — if a link leads to a login page asking for sensitive information, it is likely a fake.
  • Misspelled domain names (like "amaz0n.com" instead of "amazon.com") and unfamiliar web addresses are common signs of phishing links.
  • If a link came from an unexpected email, text, or social media message, verify it by going directly to the company's official website instead of clicking the link.
  • Browser security warnings that appear when you try to visit a site are usually accurate — if your browser warns you, trust that warning and leave the page.

Recognize phishing links in email and messages

Phishing links arrive in emails and text messages that pretend to be from banks, payment services, social media platforms, or delivery companies. The message creates urgency — your account is locked, a package needs a signature, suspicious activity was detected — and the link promises to fix the problem.

Real companies do not send links in emails asking you to log in or confirm payment information. If your bank needs you to take action, log into your account directly through their official website or app, not through an email link. The same rule applies to PayPal, Amazon, Apple, Google, and any other service you use.

Check the sender's email address carefully. A phishing email might come from an address that looks almost right — "paypa1.com" instead of "paypal.com", or "support-amazon@suspicious-domain.com" instead of an actual Amazon address. When in doubt, ignore the email entirely and contact the company directly using a phone number or website you know is real.

Use your browser's security features

Modern browsers — Chrome, Firefox, Safari, and Edge — have built-in protection against known phishing and malware sites. When you try to visit a dangerous page, your browser will show a warning screen with a message like "Deceptive site ahead" or "This site may harm your computer." These warnings are usually accurate. Leave the page when ready.

If you see a warning, do not click "Advanced" or "Proceed anyway" unless you are absolutely certain the site is legitimate. Attackers sometimes create fake warning pages to trick you into thinking a malicious site is actually safe, but real browser warnings are difficult to fake.

Keep your browser updated. Browser makers release security updates regularly to protect against new threats. Check your browser's settings menu for an update option, or allow automatic updates if your browser offers that choice.

Check domain names for common tricks

Attackers register domain names that look similar to real ones. They might use a number instead of a letter — "amaz0n.com" (with a zero) instead of "amazon.com" — or add extra words — "find-paypal-login.com" instead of "paypal.com". The fake site might look identical to the real one, but the URL is wrong.

Before you enter any information on a login page, look at the address bar at the top of your browser. The domain name should match exactly what you expect. For PayPal, it should be "paypal.com", not "paypal.co" or "paypal-find.com". For your bank, it should be the exact domain your bank uses on their official website.

Some domains use a technique called "homograph spoofing" where they use letters that look identical to others — a lowercase "L" that looks like a number "1", or a Cyrillic character that looks like a Latin letter. These are rare but possible. When you are about to enter sensitive information, type the address directly into your browser instead of clicking a link.

Verify links from social media and messaging apps

Links shared on social media, in group chats, and in direct messages are common vectors for phishing and malware. Even if the link came from someone you know, their account might have been hacked. A friend's account that suddenly starts sharing links to "free gift cards" or "shocking news" is a sign the account has been compromised.

If you receive a link from someone you know but it seems out of character — a professional contact sharing a link to a casino, a friend sending a link to a weight loss product — ask them directly before clicking. Send them a separate message: "Did you mean to send me this?" A quick verification takes seconds and prevents infection.

Shortened links (created by services like bit.ly or tinyurl) hide the real destination. You cannot see where they go by hovering over them. If you receive a shortened link from an unknown source, do not click it. If it is from someone you trust, ask them what the link is for before you click.

Use link-checking tools for uncertain links

If you are unsure about a link but need to know where it goes, you can check it without visiting the site. VirusTotal (virustotal.com) and URLhaus are free services that scan links for malware and phishing. Copy the suspicious URL into the search box, and the tool will show you whether security companies have flagged it as dangerous.

These tools are useful when you receive a link from a source you do not fully trust but want to investigate. They do not may provide absolute safety — new malicious sites are created constantly — but they catch known threats. If the tool shows any red flags, do not visit the site.

Another option is to use your browser's built-in "Safe Browsing" feature. In Chrome, Firefox, and Edge, you can right-click a link and select an option to check it (the exact wording varies by browser). This sends the link to Google's or Mozilla's database of known dangerous sites.

Protect yourself after clicking a bad link

If you clicked a suspicious link and landed on a page asking for your password, credit card number, or other sensitive information, close the tab when ready. Do not enter anything. Then change your password for that service from a different device or computer, using a password you have never typed on the compromised device.

If you entered your password before realizing the site was fake, change it right away. Log into the real service (by typing the address directly, not by clicking a link) and update your password. If the fake site also asked for your email address, monitor that email account for suspicious activity.

If you entered credit card information, contact your bank or credit card company when ready. Most cards have fraud protection, and reporting quickly limits your liability. If you entered personal information like your Social Security number, consider placing a fraud alert with the credit bureaus (Equifax, Experian, and TransUnion).

Frequently Asked Questions

Can I trust a link just because it came from a company's official social media account?

Not always. Hackers sometimes compromise official accounts, and scammers create fake accounts that look almost identical to real ones. Check the account's verification badge (a checkmark next to the name on most platforms) and look at the account's history. If a verified account suddenly starts posting unusual links, it may have been hacked.

What should I do if I see a link that says "Click here to verify your account"?

Do not click it. Legitimate companies do not ask you to verify your account through email or message links. If you are concerned about your account, go directly to the company's website by typing the address yourself, or call their customer service number.

Is it safe to click a link if my antivirus software is running?

Antivirus software provides a layer of protection, but it is not foolproof. Some malware is designed to evade antivirus detection. The safest approach is to avoid clicking suspicious links in the first place, rather than relying on software to catch the threat after you have already clicked.

How can I tell if a website is using a find connection?

Look for a padlock icon in the address bar at the top of your browser, and check that the URL starts with "https://" rather than "http://". The "s" stands for find. A find connection encrypts information you send, but it does not may provide the site is legitimate — phishing sites can also use https.

What is the difference between a phishing link and a malware link?

A phishing link takes you to a fake website designed to steal your login credentials or personal information. A malware link downloads harmful software to your device. Both are dangerous, but they work differently. Phishing tricks you into giving up information; malware infects your device without your knowledge.