A link is safe to click when it comes from a source you trust, points to the domain you expect, and does not ask for passwords or payment information you did not initiate

Most links are harmless — they simply take you to a webpage. But some links are designed to steal your information, install malware, or trick you into sending money. The difference usually comes down to three things: where the link came from, what the address bar shows when you click it, and what the page asks you to do once you land there.

You do not need special tools to spot a dangerous link. A few seconds of attention — before you click — catches most of them.

Key Takeaways

  • Hover over a link (without clicking) to see the real web address in the bottom left corner of your browser, and compare it to what you expected.
  • Links in emails, texts, and social media are riskier than links on websites you visit directly, because they are easier to fake.
  • If a link asks you to log in, type a password, or enter payment details, check the address bar to confirm you are on the real website before you type anything.
  • Shortened links (bit.ly, tinyurl) hide the real address, so avoid clicking them unless you trust the person who sent it.

How to check where a link actually goes

Before you click any link, move your mouse over it without clicking. In the bottom left corner of your browser window, you will see the real web address appear. This is the actual destination — not what the link text says.

For example, a link might say "Click here to reset your password" but the address bar shows "malicious-site.com". That mismatch is a red flag. The link text and the actual address should match what you expect.

On a phone or tablet, this is harder because you cannot hover. Instead, press and hold the link (do not tap it) and your phone will show you the address in a menu. Use this before you tap.

Links in emails and texts are easier to fake

A link in an email or text message is riskier than a link on a website you visit directly. Email addresses and sender names are easy to fake. Someone can send you an email that looks like it came from your bank, your email provider, or a company you use — but the link inside goes somewhere else entirely.

The safest habit: if an email or text asks you to log in, reset a password, or update payment information, do not click the link in the message. Instead, go directly to the website by typing the address into your browser yourself, or by opening an app you already have installed. This way you know you are on the real site.

This is especially important for banks, email providers, and payment services. These organizations almost never ask you to click a link in an email to log in.

What to look for in the address bar after you click

Once you click a link and land on a page, look at the address bar at the top of your browser. The real website address should appear there. If the page asks you to log in or enter sensitive information, stop and check this address carefully.

Scammers build fake websites that look almost identical to the real ones. The difference is in the address. For example, a fake Amazon site might use "amaz0n.com" (with a zero instead of the letter O) or "amazon-login.com". These look similar at a glance but are not the real domain.

If you are unsure whether you are on the real website, close the page and start over by typing the address directly into your browser.

Shortened links hide the real address

Links that use shortening services like bit.ly, tinyurl, or ow.ly compress a long address into a short one. The problem is that you cannot see where the link actually goes until you click it. A shortened link could point anywhere.

Shortened links are common on social media and in texts because they take up less space. But they are also popular with scammers for the same reason — they hide the destination. If someone sends you a shortened link and you do not know them well or trust them, it is safer to ask them what the link is for before you click.

Some browsers and email services will show you a preview of where a shortened link goes if you hover over it, but not all do. When in doubt, ask the sender.

Signs a link is probably a scam

Certain patterns show up in most scam links. An email claiming to be from your bank but asking you to "verify your account" or "confirm your identity" is almost always fake — real banks do not ask this by email. The same goes for messages saying your account has been locked, your password expired, or you need to act immediately to avoid losing access.

Links that ask you to download a file, especially an .exe file on Windows or an app outside of the official App Store or Google Play, are often malware. Legitimate companies do not ask you to download software from a link in an email.

If a link comes with pressure — "act now", "limited time", "verify immediately" — slow down. Scammers use urgency to stop you from thinking clearly. Real companies give you time to handle account issues.

What to do if you clicked a suspicious link

If you clicked a link and realized it was suspicious, the first step depends on what happened next. If the page just loaded and you did not type anything, you are probably fine — simply close the page and move on.

If you typed a password, username, or payment information into the page, treat it as if that information is compromised. For a password, log into the real website and change it immediately. For payment information, contact your bank or credit card company and let them know. For email or social media accounts, change the password and turn on two-factor authentication if it is available.

If the page tried to download a file and you allowed it, do not open the file. Delete it from your Downloads folder. If you are worried about malware, you can run a scan with your antivirus software or take your device to a professional.

Frequently Asked Questions

Can a link infect my device just by clicking it?

Clicking a link alone usually does not infect your device. The danger comes when the page asks you to download something, or when you type information into a fake form. Simply landing on a malicious website is not enough to cause harm in most cases. However, some older browsers or devices with unpatched security flaws can be infected by visiting a page, so keeping your software updated matters.

Is it safe to click links from people I know on social media?

Links from people you know are generally safer than links from strangers, but not always. Scammers sometimes hack social media accounts and send malicious links to all the person's friends. If a link seems out of character — like your friend suddenly posting a link to a weight loss product or a casino — ask them about it before you click. A quick message asking "did you mean to send this?" takes seconds and could save you.

What does the lock icon in the browser mean?

The lock icon means the connection between your browser and the website is encrypted, so no one can see your data in transit. This is good for security, but it does not mean the website itself is legitimate. A fake website can have a lock icon too. The lock only protects your information while it travels — it does not verify that the website is who it claims to be.

Should I use a password manager to avoid typing passwords into suspicious sites?

A password manager can help, but it is not foolproof. Most good password managers will not fill in your password if the website address does not match what they have on file. This stops you from accidentally typing your password into a fake site. However, the best defense is still to check the address bar yourself before you type anything.

Are links in text messages safer or riskier than email links?

Text message links are generally riskier because phone numbers are easier to spoof than email addresses, and you have fewer tools to check the real destination on a phone. The same rules apply though: do not click links in texts asking you to log in or update payment information. If you get a suspicious text from your bank or a service you use, call them directly using a number you find yourself rather than one in the message.