Practical safety guide

How to Check If a Link Is Safe Before Clicking

Do not rely on the padlock, the sender's display name, or one scanner result. Use this eight-step process to inspect the destination, context, and security signals together.

Quick answer: copy the link without opening it, identify the real domain, inspect it for lookalikes, scan it with more than one security signal, and verify unexpected requests through a trusted route you find independently. A clean scan lowers risk; it does not prove that a page is harmless.

Why suspicious links are difficult to judge

A link can display one name while sending you somewhere else. Attackers also use subdomains, misspellings, Unicode lookalikes, URL shorteners, compromised legitimate sites, and urgent messages to make a destination feel familiar. HTTPS only protects the connection to a site; it does not prove that the person operating that site is trustworthy.

The safest decision comes from combining technical evidence with context. Ask both “what does this URL show?” and “why did I receive it, from whom, and what is it asking me to do?”

Eight steps to check a link safely

1. Do not open the link while investigating it

On desktop, right-click and copy the link address. On a phone, press and hold the link to preview or copy it, but do not continue to the destination. If the message is already asking you to disable a warning, install software, or act immediately, treat that pressure as a risk signal.

2. Find the real domain—not the reassuring words

In https://accounts.google.com.security-check.example.net/login, the controlling domain is example.net, not google.com. Read the hostname from right to left and identify the registered domain immediately before the public suffix. Text elsewhere in the URL can be chosen by an attacker.

3. Look for impersonation and typosquatting

Compare the domain character by character with the organization's address you already know. Watch for missing letters, swapped letters, extra hyphens, number substitutions such as 0 for o, and xn-- prefixes that represent internationalized domain names. An unfamiliar top-level domain is context to investigate, not automatic proof of fraud.

4. Inspect the message around the link

Unexpected password resets, delivery fees, crypto opportunities, account suspensions, invoices, and requests for recovery codes are common social-engineering setups. Check the sender's actual address, whether the request is expected, and whether the tone is pushing secrecy or urgency.

5. Use a URL checker before visiting

Paste the copied address into the free Is This Link Safe checker. It checks known threat listings, lookalike-domain patterns, the public IP's abuse reputation, known domain verdicts, and whether the URL uses unencrypted HTTP. Read the reasons behind the result instead of treating the badge as a yes-or-no guarantee.

6. Treat shortened and QR-code links as hidden destinations

A short URL or QR code prevents you from reading the final domain before navigation. Use a preview feature supplied by the shortening service when available, or ask the sender for the full destination. Do not assume a scanner expanded every redirect unless it explicitly says so; this checker evaluates the URL you submit and does not promise redirect expansion.

7. Respect browser, password-manager, and device warnings

If Chrome or another security control displays a phishing or malware warning, do not bypass it. Google advises users not to visit pages shown as dangerous. A password manager that refuses to fill saved credentials can also reveal that the current domain differs from the one where the password was created.

8. Verify the request through an independent route

Open the organization's app yourself, type its known address, use a bookmark you created earlier, or call a verified number from a statement or official website. Do not use the phone number, reply address, or second link included in the suspicious message.

Fast link-safety checklist

Destination

Does the registered domain exactly match the organization you expect?

Context

Were you expecting this request, and can you confirm it outside the message?

Requested action

Is the page asking for a password, payment, download, seed phrase, or recovery code?

Security signals

Do the checker, browser, and your own inspection agree—or is any one of them warning you?

How the process changes by scenario

Email or text message

Check the complete sender address and message headers when available. Instead of clicking an account alert, open the service's official app or website directly. Report suspected phishing through your mail or messaging provider.

Social media or marketplace message

Be cautious when someone moves a conversation off-platform, sends a “verification” or “payment” link, or asks you to sign in again. Complete transactions and support conversations inside the platform whenever possible.

QR code

Use a camera app that previews the destination before opening it. Physical QR stickers can be placed over legitimate codes, so also inspect where the code appears and whether the requested action makes sense.

How to interpret scanner results

  • Safe: no available signal identified a known threat at scan time.
  • Suspicious: one or more warning signs require independent verification.
  • Dangerous: a strong threat-list or abuse-reputation signal was found.
  • Unknown: a required security provider did not complete, so no verdict was issued.

Do not turn Safe into permission. Fresh phishing sites may not yet appear on reputation lists, legitimate sites can be compromised, and a page can change after it was checked. Never enter a secret merely because one tool returned a clean result.

Further guidance

For independent safety advice, see the official Google Chrome guidance on unsafe-site warnings and CISA guidance on recognizing and reporting phishing. For details about this tool, read how our link checking works and the privacy policy.

Check the link before you click

Paste a suspicious URL into the free checker, review the evidence, and verify sensitive requests independently.

Use the free link checker