Before you click, you can see where a link leads

A link is just text or an image that points to a web address. Before you click it, you can find out where it actually goes — without visiting the page. This matters because links can look like they go one place and actually go somewhere else entirely. A link that says "Check your bank account" might lead to a fake login page designed to steal your password. Learning to read a link before you click it is one of the fastest ways to avoid phishing scams and malware.

The method changes slightly depending on what device you use, but the basic idea is the same: you hover over the link or right-click it, and your browser shows you the real web address underneath.

Key Takeaways

  • Hover your mouse over a link to see the real web address in the bottom left corner of your browser (on desktop).
  • A link that says "Update your password" but points to a different website is almost certainly a phishing attempt.
  • On a phone, long-press the link to see options including the actual web address.
  • The part of the address before the first single slash (the domain) tells you who actually owns the website.

How to check a link on a computer

On Windows or Mac, move your mouse pointer over the link without clicking. Look at the very bottom left corner of your browser window. You will see a small preview of the web address — this is the real destination. In Chrome, Firefox, Safari, and Edge, this preview appears in the same spot every time.

If the link text says one thing but the address says another, do not click it. For example, if you see a link that says "Verify your Apple ID" but the address preview shows "secure-verify-apple.xyz.com", that is a red flag. The real Apple website would have "apple.com" in the address, not "apple" buried in the middle of a longer name.

You can also right-click the link (or Ctrl+click on Mac) and select "Copy link address" or "Copy link" from the menu. Then paste it into a text document or your browser's address bar to read the full address without visiting the page.

How to check a link on a phone or tablet

On iPhone or Android, long-press the link — hold your finger on it for a second or two without lifting. A menu will pop up with several options. Look for "Copy link" or "Copy URL" and tap it. Then open Notes or any text app and paste the address to read it.

Some phones also show a preview of the link address at the bottom of the screen when you long-press, though this is less reliable than copying and pasting. If you are not sure what you are seeing, copying and pasting is always the safer choice.

What the web address actually tells you

A web address has several parts, and the most important one for spotting fakes is the domain — the main part that comes before the first single forward slash. For example, in the address "www.amazon.com/account/login", the domain is "amazon.com". Everything after that slash is just a page or folder within that website.

Scammers often try to hide the real domain by putting a trusted name earlier in the address. For instance, "amazon.secure-login.net" looks like it might be Amazon, but the actual domain is "secure-login.net" — Amazon has nothing to do with it. The domain is always the part right before the first slash, and it is the only part that matters for knowing whose website you are actually visiting.

If you are not sure whether a domain is real, type it into your browser's address bar yourself rather than clicking the link. Go to the official website directly — look up the phone number on your bank statement or the back of your credit card, and call them to ask if a link you received is legitimate.

Common link tricks to watch for

Phishing links often use urgency in the text to make you click without thinking: "Your account will be closed in 24 hours" or "Confirm your identity now." The link text might also mimic a button, using words like "Verify," "Update," or "Confirm." These are all normal-sounding words, but combined with pressure and a suspicious address, they are a warning sign.

Another trick is using a shortened link service like bit.ly or tinyurl. These services shorten long web addresses into short ones, which is sometimes useful — but it also hides where the link actually goes. You cannot see the real address just by looking at "bit.ly/abc123". Before clicking a shortened link, you can paste it into a link expander tool (search "expand shortened URL") to see the real destination first.

Email links are particularly risky because the link text can say anything. An email might show a link that says "Click here to update your password" but actually point to a fake website. This is why checking the address before clicking is so important — the text is easy to fake, but the address is not.

When you have already clicked and are not sure

If you clicked a link and landed on a page that asks for your password, credit card, or personal information, close the tab or window immediately. Do not enter anything. Then go directly to the official website by typing the address into your browser yourself, or by calling the organization's phone number from a bill or official document.

If you already entered sensitive information, contact the organization right away. If it was a bank or financial account, call the number on the back of your card. If it was an email account, go to the real website and change your password immediately. The sooner you act, the better your chances of preventing fraud.

Frequently Asked Questions

Can a link be safe even if the address looks weird?

Not really. If the domain (the part before the first slash) is not what you expect, the link is not safe. Legitimate companies use their own domains. If you are unsure, do not click — instead, go to the official website directly or call them.

What if I see a link that says it goes to one place but the preview shows somewhere else?

That is a phishing attempt. Do not click it. The preview address is what matters — that is where you will actually go. Report the link to whoever sent it if you trust them, in case their account was hacked.

Are shortened links always dangerous?

Not always, but they hide the real address, which makes them riskier. Use a link expander tool to see where a shortened link actually goes before you click. Legitimate companies usually do not hide their links this way.

What should I do if I think I clicked a phishing link?

Close the page immediately and do not enter any information. Then change your password on the real website and contact the organization if you entered sensitive data. If it was financial, call your bank right away.