Home/Lifehacks/How to Check If a Link Is Safe: Tips to Avoid Phishing and Malware
Lifehacks

How to Check If a Link Is Safe: Tips to Avoid Phishing and Malware

Checking a link's safety before clicking is crucial to avoid phishing, malware, and scams. Learn how to inspect suspicious URLs, unmask short links, and use online tools like VirusTotal for safer browsing. Discover step-by-step tips to protect your personal data from cyber threats.

Sep 16, 2026
12 min
How to Check If a Link Is Safe: Tips to Avoid Phishing and Malware

Checking a link for safety is essential before you click on it. A malicious URL can lead to a fake bank page, a login form for a popular service, a site with an infected file, or a resource designed to steal your personal data.

The danger lies in how convincing modern scam sites can appear. They often copy the design of well-known companies, use HTTPS, and register domains that differ by just a single letter from legitimate ones. That's why you can't rely on the appearance of a message or page alone to judge a link's safety.

You can check a suspicious link without opening it: first, examine the URL itself, then, if needed, run it through phishing and malware scanning services. This approach is especially useful for links received via email, messengers, SMS, comments, or unknown QR codes.

How to Tell if a Link Is Suspicious

The first thing to check isn't the button or message text, but the actual web address. For example, a "Go to bank website" label could hide a completely different URL.

On a computer, you can usually see the real address by hovering your cursor over the link-without clicking. The URL typically appears at the bottom of your browser window. On a smartphone, press and hold the link until a menu appears showing the address or a copy option.

Checking the Domain and Website Address

The most important part of a link is its domain name. This tells you what site you'll actually visit.

For instance, if the official address is:

example.com

then addresses like:

  • example-security.com
  • examp1e.com
  • example.login-check.net

may belong to entirely different owners.

Pay close attention to the domain immediately before the domain extension like .com, .net, or .ru. For example, in:

bank.example-login.com

the main domain is example-login.com-the word "bank" is just a subdomain. Just because a famous company's name appears at the start of a URL doesn't mean the site is owned by them.

Scammers also use similar-looking characters. The letter "o," the number "0," and the letters "l" and "I" can look almost identical in some fonts. As a result, a fake address may seem legitimate at a glance.

Be alert to unusually long URLs packed with random characters. While length alone isn't proof of malicious intent-many legitimate services use long addresses for tracking and technical details-it should make you cautious.

Beware of Shortened and Masked Links

URL shorteners turn long addresses into short links, which is convenient but hides the final domain.

Instead of a clear address, you might see:

short.example/Ab12Cd

With such links, you can't immediately tell where you'll be redirected. While the shortener itself may be legitimate, the final page may not be.

These types of links are especially risky if sent by someone you don't know, appear in unexpected messages, or are accompanied by urgent requests to log in, confirm a payment, or download a file.

Some links are even more subtly masked: the visible link text displays one address, but the actual hyperlink points elsewhere. Always check the actual URL your browser will open before clicking.

Common Signs of Phishing Links

Phishing messages typically try to create a sense of urgency, pushing you to act quickly without inspecting the address carefully.

Typical phrases include warnings about your account being blocked, urgent payment confirmations, undelivered packages, claims your password was stolen, or notifications about unexpected bonuses.

After clicking, you'll land on a page that looks legitimate. There, you'll be asked to enter your login, password, card number, verification code, or other confidential information-which is then sent to cybercriminals.

The message may even come from a familiar person or account that's been compromised and used to distribute malicious links.

For a deeper dive into how these schemes work and their warning signs, check out our article: How to Recognize and Avoid Phishing and Online Fraud.

How to Check a Link's Safety Without Opening It

If a link seems suspicious, don't visit the page just to check it. Most basic diagnostics can be done by inspecting the URL: look at the domain, unmask shortened links, and check the address using specialized services.

Manual Address Inspection

First, copy the link without opening it. On a computer, you can usually right-click and select "Copy link address." On a smartphone, press and hold the link until the context menu appears.

Next, carefully examine the URL-locate the site's main domain and compare it to the service's official address. If the link supposedly leads to Google, a bank, a marketplace, or a social network, it's safer to open the official site via a bookmark or by typing the address manually in your browser.

Watch out for extra words and symbols in the domain. For example:

account.example.com
example.account-check.com

are different sites. In the first, the domain is example.com; in the second, it's account-check.com.

Words like "login," "secure," "verification," "payment," or a company name in the URL don't guarantee legitimacy-anyone can register a domain with those terms.

Also check the address extension. Sections after "?" and "#" usually contain page parameters and don't necessarily indicate a threat. For a primary check, correctly identifying the main domain is much more important.

How to Reveal Where a Shortened Link Leads

A shortened URL hides the real address, making it harder to assess a site's safety. This applies to shorteners and redirect systems that initially send you to an intermediate address before the final destination.

It's best to copy such a link and check it using a service that can show the redirect chain or the final URL. After revealing the address, review the domain using the same rules as for any other link.

Keep in mind: the final address may also contain multiple redirects. Just because the initial link uses a reputable shortener doesn't mean the end site is safe.

Why HTTPS Alone Doesn't Make a Site Safe

The padlock icon and an address starting with https:// are often seen as signs of trust. In reality, HTTPS only means the connection between your browser and the server is encrypted.

A phishing site can also use HTTPS and have a valid TLS certificate. In this case, your data is protected-up to the attacker's server.

So, while HTTPS is necessary for modern websites, it's not proof of legitimacy. When checking a link's safety, always review the domain, the message source, and the content of the page you're being directed to.

How to Scan a Link for Viruses and Phishing with Online Services

Even if a URL looks fine, you can further check it using reputation analysis services. These compare the address with databases of known phishing, malicious, and compromised sites, helping you assess the risk without visiting the page.

This method is especially useful if the link comes from an unknown sender, leads to a login page, or offers a file download.

VirusTotal

One of the best-known ways to check a link for viruses is VirusTotal. Paste the URL into the service to get results from multiple security systems.

The report will indicate whether different security engines flag the address as malicious, phishing, or safe. If several engines mark the link as phishing or malware, avoid opening it.

However, a clean report isn't a 100% guarantee. A new scam domain may not yet be listed in security databases.

Treat VirusTotal's results as an extra signal. If nothing is detected but the domain still looks suspicious or the message urges you to enter a password, card data, or verification code, clicking is still risky.

Google Safe Browsing

Site reputation systems like Google Safe Browsing can also help detect pages associated with phishing, malware, or other threats.

These databases are used by browsers to show red warnings if you're about to visit a dangerous or deceptive site.

If an address is already known to be malicious, such checks can reveal the problem before you visit the page.

But remember: databases are updated constantly, yet there may be a delay between the creation of a scam site and its detection.

Why You Shouldn't Rely on a Single Service

Neither VirusTotal, Safe Browsing, nor any antivirus can know about every malicious site online. Cybercriminals regularly create new domains, change page addresses, and exploit previously clean sites that have been hacked.

Some phishing pages exist for only a few hours. Once a domain is blocked, scammers simply move the site elsewhere.

That's why thorough link checking involves several steps: first, examine the URL, then check it with security services, and finally, consider whether the link makes sense in context.

For example, if you get an unexpected message from your bank asking you to urgently follow a link and confirm your card, it's safer not to use the link at all. Instead, open your bank's official app or type its address manually and check for notifications there.

This approach protects you even if a malicious link hasn't yet been added to any database.

What to Do If You've Already Clicked a Suspicious Link

Simply opening a suspicious link doesn't necessarily mean your device is infected or your data is stolen. Your next steps depend on what happened after the page opened: did the site just load, did you enter information, or did you download a file?

If You Just Opened the Page

If the site looks suspicious, don't click any buttons, allow notifications, download files, or enter any data. Close the tab, and clear your browser's downloads if needed.

Also check for any new browser extensions, apps, or installation prompts. Be especially wary of pages asking you to enable notifications, install a "browser update," or download unknown files.

If You Entered Your Login or Password

If you entered account information on a suspicious site, change your password immediately using the official website or app. If the same password is used elsewhere, update it there as well. Reusing passwords makes phishing consequences much worse.

Additionally, log out of all active sessions in your account settings and enable two-factor authentication if it's not already on.

If you entered bank card details or a transaction code, contact your bank as soon as possible via the official number or app.

If You Downloaded a File

Don't open a downloaded file, even if its name looks harmless. Attackers can disguise malware as documents, archives, installers, or updates.

Scan the file with built-in antivirus or other security software. If the source is unknown or you're suspicious, it's safer to delete the file without opening it.

If you've already launched the file and notice strange pop-ups, new programs, high system load, or browser changes, run a full antivirus scan.

For broader tips on protecting your accounts, devices, and data, see our article: Cybersecurity for Beginners: Essential Tips for 2025.

How to Safely Handle Unknown Links in the Future

The best defense against malicious links is to avoid clicking them automatically. Even a familiar logo, sender's name, or convincing message doesn't guarantee a link is safe.

If a message unexpectedly asks you to log in, confirm a payment, reset a password, or download a document, it's better to open the relevant service yourself-use the official app, a saved bookmark, or type the site's address manually.

Always check the domain before entering your password, especially after following a link from email, SMS, or messengers. A fake login form can closely mimic the real thing, so don't judge a page by its appearance alone.

A password manager can also help: it usually fills in credentials only on the domain where they were saved. If your usual password doesn't autofill, double-check the site's address.

Don't disable browser warnings or built-in protection against dangerous sites. While they don't replace manual link checks, they can stop you from visiting known phishing or malicious resources.

Be especially careful with links from compromised accounts. Messages can come from friends, colleagues, or relatives but still contain a harmful URL. If someone suddenly sends a link with no explanation or asks you to do something unusual, confirm with them via another channel.

Follow this simple rule: the more a message pressures, scares, or promises you benefits, the more closely you should inspect the link. Taking a few seconds to check a domain and URL is usually safer than dealing with the aftermath of a stolen password or infected device.

FAQ

  1. Can I check a link without opening it?

    Yes. You can copy the link and inspect it manually: verify the domain, look for suspicious symbols, and check the final address. Additionally, submit the URL to services like VirusTotal or check its reputation with systems such as Google Safe Browsing.

  2. How can I tell if a link leads to a phishing site?

    Most often, phishing links have a domain that looks similar to the original but is altered, an unexpected request for your password or bank details, and urgent messages. Be extra cautious if a site asks you to immediately confirm your account, payment, or password reset.

  3. Can VirusTotal guarantee that a link is safe?

    No. If VirusTotal detects no threats, it only means the scanning engines didn't identify the URL as dangerous at the time of analysis. New phishing sites may not be in the databases yet, so always combine the service's results with your own domain check.

  4. What should I do if I accidentally clicked a suspicious link?

    If you only opened the page without entering data or downloading anything, just close it and avoid interacting with its content. If you entered a password, change it via the official service website. If you downloaded or launched an unknown file, run an antivirus scan.

Conclusion

It's best to check a suspicious link before clicking, not after. The basic steps are simple: look at the real URL, check the core domain, consider the message's context, and, if in doubt, run the address through VirusTotal or another reputation service.

Neither HTTPS nor a lack of antivirus alerts guarantees complete safety. New phishing sites may not yet appear in security databases, so it's more important to combine automated checks with careful analysis of the address.

If a link claims to lead to your bank, social network, online store, or another important service, the safest option is to avoid using it entirely. Open the official app or type the known site address yourself. This approach helps you avoid most scams based on fake pages and credential theft.

Tags:

cybersecurity
phishing
malware
link-safety
virus-scanning
online-security
internet-safety
scam-prevention

Similar Articles