How to check if a link is safe before you click

Most scam links give themselves away if you know where to look. These five checks take about thirty seconds, and work on any device.

Updated 28 September 2026 · 3 min read

The 30-second check

Five things to look at

  1. 01

    See the real address

    The words of a link can say anything. On a computer, rest the pointer on the link and look at the address your browser shows. On a phone, press and hold the link to see its full address.

  2. 02

    Read the domain, from the right

    Find the first single “/” after https://. The name just before it is the site you’ll really visit: read it from the right. Anything further left is decoration anyone can add.

    https://paypal.com.secure-login.top/verify?account=update

    This link goes to secure-login.top, not paypal.com.
  3. 03

    Unwrap short links

    Short links such as bit.ly or t.co hide where they go, and so do some redirects. Use a link checker to see the final destination before you open it.

  4. 04

    Watch for lookalikes

    Scam addresses copy real ones: a 1 for an l (paypa1), rn for m, extra words (paypal-account-verify), or an ending you wouldn’t expect for that company. Unusual endings in a message about money or logins deserve extra care.

  5. 05

    Question urgency and small payments

    “Pay a £1.45 redelivery fee”, “your account will be closed today”, a tax refund you weren’t expecting: pressure and small payments are classic lures. When in doubt, go to the company’s website or app yourself instead of using the link.

Let LinkGuard do it

See where any link goes before you click.

Already clicked?

What to do next

  1. 1

    If a page opened but you didn’t type anything, close it. Opening a page alone is rarely enough to cause harm.

  2. 2

    If you typed a password, change it on the real site straight away, and anywhere else you use it. Turn on two-step verification.

  3. 3

    If you gave card or bank details, call your bank on the number on the back of your card.

  4. 4

    In the UK, forward scam texts to 7726 and scam emails to report@phishing.gov.uk.

FAQ

Common questions

How can I tell if a link is fake?

Look at the real address, not the words of the link. Read the domain from the right: it’s the part just before the first single “/”. If it isn’t the company you expect, or it uses lookalike letters, extra words or an unusual ending, treat it as fake.

Is it safe to click a shortened link?

Only once you know where it goes. Short links hide the destination, so unwrap them first with a link checker such as LinkGuard, which follows the redirects and shows the landing page.

What should I do if I clicked a scam link?

Don’t type anything on the page. If you already entered a password, change it on the real site and turn on two-step verification. If you shared card or bank details, call your bank on the number on your card. In the UK, forward scam texts to 7726 and emails to report@phishing.gov.uk.

Can a link checker be wrong?

Yes. No checker catches everything, and brand-new scam sites may not be on any list yet. LinkGuard adds an AI judgement for those, but it can still be wrong in both directions, so use it together with your browser’s own protection and your judgement.