How to Check a Suspicious Link Before You Click
Almost every scam message ends in a link, and almost every link is built to be misread at a glance. There's a reliable way to read one. It takes a few seconds and works on any address you'll ever be sent.
A web address is not read left to right the way a sentence is. The brand name you recognise can be anywhere in it, and only one part decides where you actually end up. Once you know which part that is, most lookalike links stop working on you.
Where the real domain hides
Find the first single slash after the https:// part. Everything before it is the host. Everything after it is just a path, and whoever owns the host controls all of it. Within the host, only the last two labels decide the destination.
https://usps.com.tracking-update.net/redelivery
https://paypal.secure-billing.co/invoice
https://apple-id-verify.info/signin
https://accounts.google.com/signin
The first goes to tracking-update.net. The second goes to secure-billing.co. The third goes to apple-id-verify.info, which is a name anyone can register. Only the fourth is what it appears to be, because the last two labels before the first slash are google.com.
Dots join, hyphens don't
A dot separates one label from another, so login.yourbank.com really is part of yourbank.com. A hyphen joins words inside a single label, so yourbank-login.com is an entirely separate domain that merely contains the bank's name. That one character is the difference, and it is the difference most lookalike links are built on.
One exception is worth knowing: addresses ending in .co.uk, .com.au and similar country endings use the last three labels rather than two.
The link text is not the link
In an email, a chat message, or a web page, the words you see and the address you go to are two separate things. Anyone writing the message chooses both, independently. A link that reads https://yourbank.com/verify can point anywhere at all. The visible text is a label, not evidence, so it is worth checking the real destination even when the text already looks correct.
Signs a link is not what it claims
- A brand name appears in the address, but joined to other words with hyphens rather than separated by a dot — secure-paypal.com rather than paypal.com.
- The brand name is a subdomain of something else. Read to the first single slash: in netflix.billing-update.net, the destination is billing-update.net.
- An ending you wouldn't expect from a large company or a government service: .shop, .top, .icu, .cc, .xyz, .zip or a country ending unrelated to where the company operates.
- Letters that look nearly identical at small sizes — a capital I standing in for a lowercase l, rn instead of m, or a zero for the letter O. Compare character by character rather than glancing.
- A shortened link in a message you didn't ask for. A shortener hides the destination completely, which is a reason to use one for sharing and a reason to distrust one in an unexpected message.
- The visible text of a link and the address shown on hover or long-press are different, or the visible text isn't a link at all but a picture of one.
- A very long address where the brand name sits far to the left and the real domain is pushed off the end of a narrow phone screen.
How to check a link before you open it
- 1On a phone, press and hold the link without lifting your finger. A preview appears showing the real address, and you can dismiss it without opening anything. On a computer, hover over the link and read the address that appears at the bottom of the window.
- 2Find the first single slash and read only what comes before it. Ignore the path, the query string, and anything after a question mark — none of it changes where you're going.
- 3Inside that host, take the last two labels. Ask whether that exact pair is the company's real domain, not whether the company's name appears somewhere in the address.
- 4If the address is shortened or you can't see the whole thing, treat the destination as unknown and stop there.
- 5Reach the same place another way instead: open the company's official app, or type their address into your browser yourself. Typing beats searching, since search results can include ads for lookalike sites.
- 6If you've already opened the page, don't type anything into it — especially a password or a one-time code. Close the tab and go to the real site yourself.
Not sure about a link you were sent?
Paste it into the free checker and see the specific red flags in it. No signup, no email.
Check a messageUsing this on a real message
The address is usually the fastest thing to check, but it rarely sits alone. Scam messages pair a lookalike link with a reason to hurry, and the two work together. Our guide to delivery texts saying a package is on hold shows the pattern in its most common form, and bank fraud alert texts covers the harder case, where a real alert and a fake one look almost the same.
If you already entered details on a page you now doubt, treat that as urgent rather than embarrassing. Our reporting guide covers what to change first and where to report it.
Common questions
- Where exactly is the real domain in a web address?
- Start after https:// and read up to the first single slash. That whole piece is the host. Within it, the registered domain is the last two parts — so in account.secure-login.net the registered domain is secure-login.net. Country endings are the exception: addresses ending in .co.uk, .com.au and similar use the last three parts instead.
- Does a padlock icon or https mean a site is safe?
- No. The padlock only means traffic between your device and that site is encrypted. It says nothing about who owns the site or what they intend to do with what you type. Certificates are free and automatic, so a fake page can have a padlock as easily as a real one.
- How do I see where a shortened link goes without opening it?
- You usually can't from the link itself, which is why shorteners are worth treating as unknown. Rather than trying to expand one, ignore it and reach the same destination another way: open the company's own app, or type their website address into your browser yourself.
- I tapped a link but didn't type anything in. Is that a problem?
- Usually not. Simply loading a page is much less serious than entering information on it. Close the tab, don't return to it, and don't enter anything if you land back on it by accident. Keep your phone and browser updated, since most drive-by risks depend on out-of-date software.
This page is informational and we aren't affiliated with any company or agency named on it. We can't tell you whether your specific message is genuine. Verify independently: open the company's official app or type their website address yourself, and call the number printed on your card, statement, or the back of your ID — never a number supplied by the message.
Related guides
- Romance Scam Warning SignsThe patterns that show up long before money is ever mentioned.
- Bank Fraud Alert Texts: Real or Fake?Real and fake fraud alerts look identical. The safe habit that works either way.
- Crypto Investment Scam Warning SignsFake platforms, fake profits, and the withdrawal fee that never ends.
Want simple scam alerts for your family?
Join the early-access list. This is an idea we're testing, not an active protection service — nothing is monitored today, and joining changes nothing about your accounts.