A link is safe to click when it comes from a source you trust, points to the website you expect, and doesn't ask you to do something unusual like enter a password on a page that looks wrong

Most links are harmless. But some are designed to steal your password, install malware, or trick you into sending money. The good news is that you can check a link before clicking it — and you don't need special software to do it. You just need to know what to look for.

The biggest risk is a phishing link: a URL that looks like it goes to your bank, email, or social media, but actually goes somewhere else. Criminals send these in emails, texts, and social media messages. A second risk is malware links that download harmful software when you click them. A third is a legitimate website that has been hacked and now serves malware without the owner knowing.

Key Takeaways

  • Hover over a link (don't click) to see the real URL in the bottom left corner of your browser — if it doesn't match what you expect, don't click it.
  • Phishing links often misspell the real domain name slightly (like "amaz0n.com" instead of "amazon.com") or hide the real domain after a slash or @.
  • If a link asks you to log in and the page looks off — wrong colors, missing logos, awkward text — close it and go to the website directly by typing the address yourself.
  • Links in unexpected emails, texts, or messages from people you know are higher risk, especially if they ask you to click urgently or confirm account details.
  • Your browser and antivirus software can warn you about known malware sites, but they don't catch everything, so your own judgment matters.

How to check a link before clicking it

The simplest check is to hover your mouse over the link without clicking. In most browsers — Chrome, Firefox, Safari, Edge — a small box appears in the bottom left corner showing the real URL. Compare that URL to what you expect. If you're reading an email from your bank and it says "Click here to log in," hover over the link. The URL should start with your bank's real domain name, like "chase.com" or "bofa.com", not something else.

If you're on a phone and can't hover, press and hold the link for a second or two. A menu should appear with an option to "Copy link" or "Show link preview." Use that to see the real URL before you tap it.

Pay attention to the domain name — the part between "https://" and the first slash. That's what matters most. A URL like "https://amazon.com/some-page" is real. A URL like "https://amaz0n.com/some-page" (with a zero instead of the letter O) is fake. So is "https://amazon-login.com" or "https://login.amazon.com.phishing-site.com" — the last one hides the real domain after a dot or slash to trick you.

Red flags in phishing emails and messages

Phishing links usually arrive with a story designed to make you click fast. Common ones: "Your account has been locked," "Confirm your payment method," "Unusual activity detected," or "Click to claim your refund." The message creates urgency so you don't stop to think.

Real companies rarely ask you to click a link in an email to log in or enter sensitive information. If your bank sends a message saying "Confirm your password," the safest move is to close that message, open your browser, type the bank's website address yourself, and log in normally. If there really is a problem, you'll see it when you log in that way.

Another red flag: the message comes from someone you know but asks you to click a link that seems out of character. If your friend texts you a link with no context, or your colleague sends you a link to "check out this funny video" but the URL looks like random characters, be skeptical. Accounts get hacked, and criminals send messages from them.

What to do if a page looks wrong after you click

Sometimes you click a link and land on a page that looks almost like the real thing, but something feels off. The colors might be slightly wrong, the logo might be missing, or the text might have spelling errors. This is a fake login page designed to steal your password.

If you notice this, close the page immediately. Don't enter your password or any personal information. Go back to your browser, type the real website address yourself, and log in from there. If you already entered your password on the fake page, go to the real website and change your password right away.

Your browser may also show a warning before you reach the page — a red screen saying "This site may be unsafe" or "Deceptive site ahead." These warnings come from Google, Mozilla, or Microsoft's lists of known phishing and malware sites. If you see one, trust it and go back.

Links from shortened URL services

Services like bit.ly, tinyurl.com, and short.link let people compress long URLs into short ones. The problem is you can't see where the link really goes until you click it. Criminals use these services to hide phishing and malware links.

If you get a shortened link from someone you don't know, or even from someone you do know but it seems suspicious, you can expand it without clicking. Paste the shortened URL into a site like "unshorten.it" or "expandurl.com" and it will show you the real destination. Then you can decide whether to click.

If the real URL looks suspicious, don't click it. If it looks legitimate, you can click it — though you're still taking a small risk, because the destination site itself could be hacked.

When your antivirus or browser warns you

Chrome, Firefox, Safari, and Edge all have built-in protection against known phishing and malware sites. When you try to visit one, you'll see a warning page. Windows Defender, macOS, and most antivirus programs add another layer by scanning downloads.

These warnings are reliable for sites that have already been reported and added to a blocklist. But new phishing and malware sites appear constantly, and it takes time for them to be discovered and added to the list. So a warning means "don't go there," but no warning doesn't mean "it's definitely safe." Your own judgment still matters.

If you see a warning and you're sure the site is legitimate — maybe you mistyped the address — you can usually click "Advanced" or "Details" and then "Proceed anyway." But do this only if you're certain. Most of the time, a warning means stop.

Links in public places like social media and forums

Links posted in comments, group chats, or public forums are riskier than links from people you know well. Scammers create fake accounts and post links to phishing pages or malware. They might pretend to be a company offering a deal, or a person sharing a video.

Before clicking a link from social media, check who posted it. Is it an account you recognize? Does the account have a verification badge (a checkmark next to the name)? Does the post match what that account usually shares? If something seems off, don't click.

Also look at the replies. If other people are saying "This is a scam" or "Don't click this," listen to them. Scammers often get reported quickly by the community.

Frequently Asked Questions

Can I get hacked just by clicking a link?

Clicking a link alone usually doesn't hack you. But it can take you to a page that steals your password, tricks you into installing malware, or exploits a security flaw in your browser. The risk depends on what the link does and what you do after you click it.

What if I already clicked a suspicious link?

Don't panic. If you didn't enter any passwords or download anything, you're probably fine. If you did enter a password, change it right away on the real website. If your browser downloaded a file, don't open it — delete it. If you're worried, run a scan with your antivirus software or take your device to a tech support person.

Is it safe to click links from my email provider or bank?

Links from your actual email account or bank account are usually safe — they come from the real company. But scammers can fake the "from" address in an email to make it look like it came from your bank when it didn't. Always hover over the link to check the real URL, even if the email looks official.

Do I need special software to check if a link is safe?

No. Hovering over a link and checking the URL is free and works in any browser. Your browser's built-in warnings are also free. Paid antivirus software adds extra scanning, but it's not required for basic safety.

What's the difference between a phishing link and a malware link?

A phishing link takes you to a fake website designed to steal your login information or personal data. A malware link downloads harmful software to your device. Both are dangerous, but they work differently. Phishing tricks you into giving up information; malware infects your device.