A URL is the web address you type into your browser to reach a website

A URL (Uniform Resource Locator) is the full address of a webpage or file on the internet. When you type something like https://www.example.com/pages/about into your browser's address bar, you are typing a URL. It tells your browser exactly where to find the page you want to see.

Every URL has the same basic structure, broken into distinct parts. Understanding what each part does helps you recognize legitimate websites, spot suspicious links, and navigate the web more confidently.

Key Takeaways

  • A URL has four main parts: the protocol (https://), the domain name (example.com), the path (/pages/about), and sometimes a query or fragment at the end.
  • The protocol https:// means the connection is encrypted; http:// without the "s" is unencrypted and less secure for sensitive information.
  • The domain name is the core address — everything before the first single slash — and is what you should check carefully to avoid fake websites.
  • The path after the domain name shows which specific page or file you are viewing on that website.
  • URLs can include query strings (the ? part) that pass information to the website, like search terms or filter settings.

The four parts of a URL explained

Every URL breaks down into up to four pieces. Here is a real example: https://www.wikipedia.org/wiki/Computer_science?language=en#History

Protocol: The https:// at the very start tells your browser how to connect to the website. HTTPS means the connection is encrypted — your data is scrambled so others cannot read it. HTTP (without the "s") is unencrypted. You should see HTTPS on any page where you enter passwords, credit card numbers, or personal information. A small lock icon next to the address bar confirms the connection is secure.

Domain name: The www.wikipedia.org part is the actual address of the website. The domain name is what you should look at carefully to check whether you are on the real site or a fake one. Scammers sometimes create URLs that look similar to legitimate ones — for example, wikipidia.org (missing an "e") instead of wikipedia.org. The domain name is everything from the first character after :// up to the first single forward slash (/).

Path: The /wiki/Computer_science part shows which specific page or folder you are viewing on that website. Think of it like a file path on your computer — it narrows down from the main site to the exact page. If there is no path, you are on the website's home page.

Query and fragment: The ?language=en#History part passes extra information to the website. The question mark starts the query string, which tells the site what to do (in this case, show the page in English). The hash symbol (#) marks a fragment, which jumps you to a specific section of the page (in this case, the History section). Not every URL has these parts.

How to spot a real domain name versus a fake one

Scammers rely on the fact that most people do not read URLs carefully. A fake URL might look almost identical to the real one at a glance, but one letter or symbol will be different. Always check the domain name — the part between :// and the first /.

Real domain names follow a pattern: a name, a dot, and a top-level domain (TLD). Common TLDs are .com, .org, .gov, .edu, and .net. A URL like https://secure-paypal-login.com looks official but is not PayPal's real domain. PayPal's real domain is paypal.com. Everything before paypal.com (like secure-) is just a subdomain or part of a fake domain name.

If you are unsure whether a link is real, do not click it. Instead, go directly to the website by typing the domain name yourself into the address bar, or search for the company's official website in a search engine.

Subdomains and how they fit into a URL

Sometimes you will see a URL like https://mail.google.com or https://support.microsoft.com. The mail and support parts are subdomains. They belong to the main domain (google.com and microsoft.com) but point to different services or sections.

Subdomains are created by the website owner and sit to the left of the main domain name. They are legitimate when they come from the real company, but scammers can also create fake subdomains. For example, https://paypal.fake-security-check.com looks like it might be PayPal, but the real domain is fake-security-check.com, not PayPal. Always read from right to left: the rightmost part before the first slash is the real domain.

What HTTPS means and why it matters

HTTPS stands for HyperText Transfer Protocol Secure. The "S" at the end means the connection between your browser and the website is encrypted. When you type information into an HTTPS page, that data is scrambled so that hackers on the same network cannot read it.

HTTP (without the "s") has no encryption. If you enter a password or credit card number on an HTTP page, someone could potentially intercept it. Most modern websites use HTTPS, and your browser will show a lock icon in the address bar when the connection is secure. If you see a warning that says the connection is not secure, do not enter sensitive information on that page.

HTTPS does not mean the website is trustworthy — it only means the connection is encrypted. A scam website can still use HTTPS. Always check the domain name itself, not just the lock icon.

Query strings and how websites use them

A query string is the part of a URL that starts with a question mark. For example, in https://www.google.com/search?q=how+to+reset+password, the query string is ?q=how+to+reset+password. It tells Google what to search for.

Query strings are common on search engines, shopping sites, and pages with filters. When you search for something or apply a filter, the website adds a query string to the URL to remember what you asked for. You can often edit the query string directly in the address bar to change the search or filter without clicking through the page.

Be cautious with query strings in links from strangers or suspicious emails. A scammer might create a link that looks like it goes to a real website but includes a query string that passes your information somewhere else. Always check the domain name first — if the domain is real, the query string is usually safe.

Frequently Asked Questions

What is the difference between a domain name and a URL?

A domain name is just the address part — like example.com. A URL is the complete address including the protocol, domain, path, and any query strings — like https://www.example.com/pages/about?id=5. A domain name is part of a URL, but a URL contains more information.

Why do some URLs have www and others do not?

The www stands for "World Wide Web" and is a subdomain. Websites can be set up to work with or without it. Both https://www.example.com and https://example.com usually point to the same website. The www is not required, but many websites include it by habit.

Can I trust a website just because it has HTTPS?

No. HTTPS only means the connection is encrypted, not that the website is legitimate. Scam sites can use HTTPS too. Always check the actual domain name to confirm you are on the real website, regardless of whether you see a lock icon.

What does the # symbol in a URL do?

The # symbol marks a fragment, which jumps you to a specific section of a webpage. For example, https://example.com/page#section2 takes you to the page and then scrolls down to the section labeled "section2". The fragment does not send information to the website — it only works on your browser.

Is it safe to click links in emails?

It is safer to type the website address yourself or search for it in a search engine. If you must click a link, hover over it first (without clicking) to see the actual URL it points to. Scammers often hide fake URLs behind text that looks legitimate. When in doubt, do not click.