What checking a URL means and why it matters

Checking a URL means looking at the web address itself — the text in your browser's address bar — before you click a link or visit a site. A URL can tell you whether you're about to visit the real website you think you are, or a fake one designed to steal your information. Scammers often create URLs that look almost identical to legitimate ones, relying on the fact that most people don't look closely at the address.

The reason this matters is that your browser doesn't always protect you from fake sites. You can land on a convincing copy of your bank's website, enter your login details, and hand them directly to a criminal. Checking the URL takes seconds and catches most of these traps before you enter any information.

Key Takeaways

  • The domain name — the part after "www." and before the first single slash — is what you need to verify, because that's what the site actually owns.
  • Legitimate sites use HTTPS (not HTTP), shown by a lock icon in your address bar, which means the connection is encrypted.
  • Scammers hide the real domain by putting a fake one in the subdomain (the part before the dot), so always read from right to left: the rightmost part is the real owner.
  • If a link in an email or text message looks suspicious, hover over it without clicking to see where it actually goes — the preview will show the real URL.
  • When you're about to enter a password or payment information, stop and manually type the URL into your address bar instead of clicking a link.

Understanding the parts of a URL

A URL has a predictable structure, and knowing the parts helps you spot fakes. Here's a real example: https://www.paypal.com/signin

HTTPS is the protocol — the method your browser uses to talk to the website. HTTPS means the connection is encrypted. HTTP (without the S) means it's not. Legitimate banks, email providers, and payment sites always use HTTPS. If you see HTTP on a site asking for a password, that's a red flag.

www.paypal.com is the domain name. The domain is what matters most. In this case, "paypal.com" is the actual domain — PayPal owns it. The "www" is a subdomain, a prefix that PayPal added. Subdomains can be anything, which is why scammers use them to hide the real domain.

/signin is the path — the specific page on the site. Paths don't matter for security checks; the domain is what you verify.

How to spot a fake domain hiding in a subdomain

This is the most common trick. A scammer creates a URL like https://www.paypal-secure-login.com/signin. It looks like PayPal because "paypal" appears in the address. But the real domain — the part you own and control — is "paypal-secure-login.com", not "paypal.com". PayPal doesn't own that domain; the scammer does.

To find the real domain, read the URL from right to left. Start at the rightmost part and work backward until you hit a slash or the beginning of the address. In https://www.paypal-secure-login.com/signin, reading right to left gives you: com (the top-level domain), then paypal-secure-login (the domain name), then www (the subdomain). The real owner is whoever registered "paypal-secure-login.com" — not PayPal.

Compare that to the real PayPal URL: https://www.paypal.com/signin. Reading right to left: com, then paypal, then www. The real domain is "paypal.com", which PayPal owns. This is the difference between a legitimate site and a fake one.

Checking for the lock icon and HTTPS

Before you enter any sensitive information — a password, credit card number, or social security number — look at your address bar. You should see a lock icon, usually to the left of the URL. That lock means the connection between your browser and the website is encrypted, so no one listening on the network can see what you type.

The lock icon only appears on HTTPS sites. If you're on a page asking for a password and there's no lock, or if the address bar shows HTTP instead of HTTPS, close the page and don't enter anything. Legitimate banks, email providers, and payment processors always use HTTPS for login pages.

In some browsers, you can click the lock icon to see more details about the site's security certificate. This shows you who registered the certificate and confirms the domain name. You don't need to understand all the details, but if the domain name in the certificate doesn't match the domain you're visiting, that's a warning sign.

How to check a link before clicking it

When you receive a link in an email, text message, or social media, you can see where it actually goes without clicking. On a computer, hover your mouse over the link for a second or two. A small preview will appear showing the real URL. On a phone, press and hold the link (don't tap it) and a menu will appear with the URL displayed.

This is especially useful for emails that claim to be from your bank or a service you use. The email might say "Click here to verify your account," but the preview shows the link goes to a completely different domain. That's a phishing attempt — a fake email designed to trick you into visiting a fake site.

If the preview URL looks suspicious or doesn't match the company that supposedly sent the email, don't click it. Instead, go directly to the company's website by typing the URL into your address bar yourself, or by calling their customer service number from your statement or their official website.

Manually typing URLs for sensitive actions

Whenever you're about to enter a password, payment information, or personal details, type the URL yourself instead of clicking a link. This takes an extra 10 seconds but eliminates the risk that a link is sending you to a fake site.

Open a new tab, click on the address bar, and type the domain name you want to visit. For example, if you need to log into your bank, type the bank's domain directly. If you're not sure of the exact URL, search for the company's name in a search engine and look for their official website in the results. The official site usually appears at the top and often has a small label saying "Official website" or similar.

This habit is especially important for banking, email, and payment sites. Criminals invest time in creating convincing fake versions of these sites because they know people will enter valuable information there. Typing the URL yourself is the simplest way to may provide you're on the real site.

What to do if you're unsure about a URL

If you land on a site and something feels off — the design looks slightly wrong, the URL looks odd, or you're not sure if it's real — close the page and start over. Type the URL yourself or search for the company's name. There's no penalty for being cautious, and it takes less time than dealing with a compromised account.

If you've already entered information on a site you now suspect is fake, take action immediately. If it was a banking or payment site, contact your bank or payment provider directly using the phone number on your statement or their official website. If it was an email account, change your password right away from a different device. The sooner you act, the better your chances of preventing fraud.

Frequently Asked Questions

Can a URL with a lock icon still be fake?

Yes. The lock icon means the connection is encrypted, not that the site is legitimate. A scammer can buy an SSL certificate for a fake domain like "paypal-secure-login.com" and get a lock icon. Always check the domain name itself, not just the lock icon.

What's the difference between .com, .org, and other endings?

The ending (.com, .org, .net, .gov) is called the top-level domain. Anyone can register a .com or .org domain, so the ending alone doesn't prove a site is real. .gov is reserved for U.S. government agencies, so a .gov site is more trustworthy for government services. Always verify the full domain name, not just the ending.

If I hover over a link and the URL looks right, is it safe to click?

It's safer than clicking blind, but for sensitive actions like logging in, typing the URL yourself is still better. Hovering shows you the URL, but it doesn't protect you if the link has been altered or if you misread it quickly. When money or passwords are involved, take the extra step of typing it yourself.

Why do some URLs have numbers and symbols instead of words?

Shortened URLs and tracking links are common in emails and social media. A link might show as "bit.ly/abc123" instead of the full address. These are legitimate when used by real companies, but they hide where you're actually going. Hover over them to see the real destination before clicking.

Is it safe to click links from emails sent by companies I know?

Not always. Scammers can fake the sender's email address or compromise a company's email system. Always hover over links in emails to check the real URL, even if the email looks official. When in doubt, go to the company's website directly instead of clicking the link.