How to Check if a Link Is Safe Before Clicking
Updated 2026-09-03 · HasTrust
One careless click on a bad link can land you on a fake shop, a phishing page, or a download you never wanted. The good news: almost every dangerous link gives itself away before you click — if you know where to look. Here is a practical routine you can run in under a minute.
Step 1: See the real URL first
Never judge a link by its clickable text. The words on screen can say anything; what matters is the address underneath.
- On a computer: hover your mouse over the link without clicking. The true destination appears in the bottom-left corner of your browser or in a small tooltip.
- On a phone: press and hold the link. A preview of the full URL pops up, usually with options to copy it. Copy it instead of opening it.
- In email: hover as above, and also check the sender's actual address, not just the display name. A message signed "Your Bank" sent from a random webmail address is answer enough.
Step 2: Read the domain the right way
Scammers count on people reading URLs left to right and stopping early. Read the domain — the part just before the first single slash — from right to left instead.
In paypal.com.secure-login.info, the real site is secure-login.info. "Paypal.com" is just a subdomain label anyone can create. The genuine domain is always the last two pieces before the first "/": paypal.com, amazon.co.uk, temu.com.
Lookalike tricks to watch for
- Swapped or extra letters: arnazon, tem-u, paypa1 (with a number one). Zoom in if the font makes letters hard to tell apart.
- Added words: amazon-support.com or temu-outlet.shop are not Amazon or Temu. Big brands sell from their main domain, not hyphenated spin-offs. If a link claims to be a well-known store, compare it against the official domain listed on that store's review page — for example HasTrust's Temu review shows the real address.
- Odd endings: a familiar brand on an unfamiliar ending like .top, .icu or .buzz deserves extra suspicion, especially combined with a huge discount.
Step 3: Expand shortened links
Short links (bit.ly, tinyurl, t.co and similar) hide the destination completely, which is why scammers love them in texts and social posts. Before clicking, paste the short link into a URL expander such as CheckShortURL or add a "+" to the end of most bit.ly links to see a preview page. Once you can see the real destination, run it through steps 1 and 2.
Step 4: Don't trust the padlock alone
The padlock icon (HTTPS) only means the connection is encrypted — it says nothing about who is on the other end. Most fake shops and phishing pages have padlocks too. Treat a missing padlock as a red flag, but never treat its presence as proof of safety.
Step 5: Test the link with free tools
When a link passes the eye test but you're still unsure, let a scanner look at it for you:
- Google Safe Browsing: search for "Google transparency report site status", then paste the URL to see if Google has flagged it.
- VirusTotal: paste the URL and dozens of security engines check it at once.
- HasTrust: if the link came in a suspicious message, paste the whole message into the scam checker and it will assess the link and the wording together. If the link leads to an online store, you can look the shop up on HasTrust to see its trust signals and what other shoppers report.
Step 6: When in doubt, go direct
The single most reliable habit: don't click links in unexpected emails or texts at all. If "your bank", "the post office" or "your favourite shop" says there's a problem with your account or a package, close the message and type the official website address into your browser yourself, or open the company's app. If the alert is real, it will be waiting for you there. If you can't find it, call the number printed on your card or on previous official correspondence — never the number in the message.
Already clicked? Do this now
- Don't enter anything. Opening a page is usually not enough to harm you; typing a password or card number is. Close the tab.
- If you entered a password, change it immediately on the real site, and everywhere else you reused it. Turn on two-factor authentication.
- If you entered card details, contact your bank or card issuer straight away and ask them to block the card and watch for charges.
- If you downloaded a file, delete it without opening it and run a full antivirus scan.
- Report it: forward phishing emails to your email provider's report function and to the impersonated company; report scam texts to your carrier's spam-reporting number if one exists in your country.
Make it a habit
Hover, read the domain right to left, expand anything shortened, and scan anything doubtful. Those four moves catch the vast majority of malicious links. And before you buy from a store you reached through any link — even one that checks out — take a moment to verify the shop itself, because a clean URL can still belong to a store that never ships.
Frequently asked questions
How can I check where a link goes without clicking it?
On a computer, hover your mouse over the link and read the full URL in the browser's bottom corner. On a phone, press and hold the link to preview the address, then copy it instead of opening it. You can then paste it into a scanner like Google Safe Browsing, VirusTotal, or HasTrust's scam checker.
Is a link safe if it has HTTPS and a padlock?
Not necessarily. The padlock only means the connection is encrypted, not that the site is honest. Many phishing and fake-shop sites use HTTPS. Treat a missing padlock as a warning sign, but always check the domain name and reputation too.
How do I see where a shortened link (like bit.ly) leads?
Paste it into a URL expander such as CheckShortURL, or for many bit.ly links add a plus sign to the end of the URL to open a preview page. Once you can see the real destination domain, check it the same way you would any other link.
What should I do if I already clicked a suspicious link?
Close the page without entering anything. If you typed a password, change it right away on the real site and enable two-factor authentication. If you entered card details, contact your bank immediately. If you downloaded a file, delete it and run an antivirus scan.
How do I know if a link is really from a company like my bank or a big store?
Read the domain from right to left: the real site is the part just before the first slash, such as paypal.com — not a lookalike like paypal.com.secure-login.info or amazon-support.com. When unsure, skip the link entirely and type the company's official address into your browser or open its app.
Not sure about a specific shop?
Paste its name or web address and get a trust score in seconds — or paste a suspicious message into the scam checker.
Related checks
0is echappee.shop legitUnknownSkip