Start here

How to check if a link is safe without clicking it

Learn to read any web address in ten seconds: find the real domain, spot the five common tricks, and know what a padlock does and does not prove.

By the Scammer Checker editors · Updated September 21, 2026 · 4 minute read

Key takeaways

  • Find the first single slash, then read backwards. The last two parts before it (like example.com) are the real site. Everything to the left of that is just a label anyone can make up.
  • A padlock and https mean the connection is private. They say nothing about who owns the site.
  • An @ sign in a link means everything before it is ignored by your browser.
  • Short links hide the destination. Treat them as unknown.
  • The safest way to visit a site from a message is not to use the link at all. Type the address or open the app.

The one skill that beats most phishing

Almost every phishing message depends on you not reading the web address. The logo, the wording, and the layout can all be copied perfectly. The address cannot, because only the real company controls its real domain.

You do not need software for this. You need to know which part of the address counts.

How to read a web address

Take this link: https://usps.parcel-help.example.com/track?id=9400

  1. Find the first single slash after the https://. Here it comes right after .com.
  2. Read backwards from that slash. The last two parts are example.com. That is the registrable domain: the thing somebody actually paid for and controls.
  3. Ignore everything to the left of it. usps.parcel-help. are subdomains. The owner of example.com can put any words there, including the name of a real company.
  4. Ignore everything to the right of the slash. /track?id=9400 is a path on their site. It can also say anything, including /usps.com/login.

So this link goes to a site owned by whoever owns example.com. It has nothing to do with the postal service.

Some countries use three parts, such as example.co.uk. The rule is the same: find the part someone had to register.

The five tricks

1. The familiar name at the front

paypal.com.account-verify.support/login looks like PayPal because your eye stops at the first .com. Read from the right: the domain is account-verify.support.

2. The look-alike

paypa1.com, arnazon.com, micros0ft-support.com. Swapped or doubled characters are easy to miss on a phone. Some use letters from other alphabets that look identical. If a link matters, do not rely on how it looks. Type the address yourself.

3. The @ trick

In https://yourbank.com@login.example.net/secure, everything before the @ is treated as a username and ignored. The real destination is example.net.

4. The short link

bit.ly, tinyurl.com, t.co and similar services hide the destination completely. Real companies sometimes use them in marketing, but a short link in an unexpected message about your account or a payment is a reason to stop.

5. The brand in the path

secure-portal.example.org/chase.com/verify has the bank's name after the slash, where anyone can type anything.

What the padlock means

The padlock and https tell you the connection is encrypted, so someone on the same wifi cannot read what you type. That is all. They do not check who owns the site, and certificates are free and automatic. Scam pages routinely have one.

The reverse is still useful: if a page asks for a password or card number and has no https, leave.

How to look before you tap

  • On a computer: hover over the link. The true address shows at the bottom of the window. The visible text of a link can say one thing and go somewhere else.
  • On a phone: press and hold the link. A preview shows the address. Choose copy, not open, if you want to examine it.
  • In an email: check the sender's address the same way. The display name is free text. Read the part after the @.
  • QR codes: your camera shows the address before opening it. Read it the same way. See QR code scams.

You can paste a copied link into our checker. It reads the structure of the address in your browser, shows you the real domain separately from the labels and the path, and never opens the link.

A correct domain is necessary, not sufficient. Accounts get hacked and real sites get compromised. So the strongest habit is this:

If a message asks you to sign in, pay, or confirm details, do not use its link at all. Open the app you already have, use a bookmark, or type the address. If the request is real, it will be waiting for you there.

This one habit makes almost every trick above irrelevant, because you never depend on the link being honest.

If you entered something on a fake page

  • A password: change it on the real site straight away and everywhere else it was used. Turn on two-factor sign-in.
  • Card details: call the number on the back of your card and ask for a replacement.
  • A Social Security number: go to IdentityTheft.gov for a plan, and consider a credit freeze.
  • A one-time code: contact the real company now through their app or the number on your card. A code can approve a payment or a new device within seconds.

Common questions

Is a website safe if it has a padlock?

No. The padlock means the connection between you and the site is encrypted. It does not mean the site belongs to who it claims to be. Scam sites get padlocks for free in minutes.

How can I see where a link goes without opening it?

On a computer, hover the mouse over the link and read the address shown at the bottom of the window. On a phone, press and hold the link until a preview of the address appears, then choose copy, not open. Then read the address using the method in this guide.

Are link checker websites reliable?

They can catch links that have already been reported, but a brand new scam page will usually pass. A clean result never proves a link is safe. Reading the domain yourself is quicker and works on links nobody has reported yet.

What should I do if I clicked a bad link?

If you typed nothing and installed nothing, close the page. If you entered a password, change it on the real site. If you entered card details, call your card issuer. If you installed an app or let someone connect to your device, disconnect from the internet and get help from someone you trust.

Official sources and further reading

Published September 21, 2026, last updated September 21, 2026. This guide is general education for people in the United States. It is not legal or financial advice, and it cannot tell you whether a particular message or person is genuine. Spot an error? Tell us.

Keep reading