Queasy about a cryptic link in an email, a text, or in search results perhaps? Wish there was a way to know whether danger lurks before you click? Find out here how to view and check a link to see if it is safe without opening it ⤓, what to do when you suspect phishing and how to open links safely.
On This Page
How to Test a Link for Phishing without Opening It
Time needed: 10 minutes
To check a suspicious link and URL — from an email, for instance, or received via a social network or a messaging platform — are safe to open:
- Important: Do not click, tap or open the link.
CAVE NEXUM: Treat every unexpected link as suspicious unless you have a good reason not to do so; see below for more characteristics of a dangerous link.
- Copy the link URL.
Here’s how: Typically, you should be able to click with the right mouse button, tap with two fingers or tap and hold to bring up a context menu that lets you copy the link’s address, location, or URL.
- Expand any shortened URLs to their full size and target.
Here’s how: Use a short URL expander; some will check a link’s safety in addition to expanding it.
- Use an online check for safe browsing to test the expanded URL.
View the link: You can paste the link you copied into a plain text editor, of course, to see it in full.
- If the link, after all these checks takes you to a page that has you log in to a banking, shopping or other site that holds or has you submit sensitive data:
- Open the institution’s official site or app.
- Log in manually using the app or page. - If the link results in a file downloaded to your computer:
- Make sure to check the file with a virus scanner, either on your machine or online; here are the best free online virus scanners for suspicious files.
Caught a phishing link?
Tips help fuel these email and tech how-tos.
How to View and Check a Link without Opening It: FAQ
What should make me suspicious about a link and check its safety?
Everything. Consider every link suspicious until and unless you have a good reason to believe it is safe.
Typical things that should raise flags and make you test a link before opening it:
- The link is in an unsolicited message whose sender you cannot verify — via email, a social network, messaging, etc.
- The link pretends to go to a safe, official site when it will in effect take you to a phishing page; see below.
Examples: Look for things like
https://paypai.com/…,
https://ladedu.com.verifyaccount.page/…,
https://myaccountverification-paypal.ga/… or
http://www.amaz0n.com/…. - The link uses a URL shortener; instead of a long address, you will see a shorter one that redirects to the eventual target page.
Note: This, by itself, is nothing sinister, of course. URL shortening services offer easy to share, compact links that add tracking for the owner on top.
Watch out: The shortened URL does not, however, allow you to see where you will end up right away, which should make you treat the link as suspicious initially.
Examples: URL shortening services include TinyURL, Bit.ly, t.co, ow.ly, x.co and many, many more.
How to Read a Suspicious URL
You can also find out a lot about any link just by looking at it.
This is no substitute for verifying with an online safety checker.
- Identify the (real) domain.
Here’s how: Read the domain from right to left, starting with the top-level domain (e.g.,com) immediately before the first single slash/; the real domain is the rightmost part of that section, with exactly one period (.) separating the domain from the top-level domain; everything before that is a sub-domain, which anybody can set up to match another domain name.
Example: Inhttps://ladedu.com.verify-account.page/account, the domain is not ladedu.com but verify-account.page. - Check for lookalike characters.
Here’s how:0(zero) instead ofoandIinstead oflare just two characters that, at a glance, look similar in domain names; these can be used to make a counterfeit domain look real.
Example:https://Iadedu.comis not the same ashttps://ladedu.com. - Be on the lookout for misleading redirects.
Here’s how: Some links use a legitimate domain to redirect to a malicious domain and page; the destination of the redirect might be obfuscated and redirecting further.
Example: Inhttps://ladedu.com/redirect?to=https://Iadedu.com, the redirecting domain looks safe, but the destination does not.
Can my browser test links automatically?
Yes, it probably can:
- Chrome: How to Have Google Chrome Check Page Safety Automatically
- Edge: How to Have Edge Check Page and Download Safety Automatically
- Firefox: How to Have Firefox Check for Phishing and Dangerous Downloads Automatically
- Opera: How to Have Opera Check Page Safety Automatically (and Guard Your Privacy)
- Safari: How to Have Safari Check Page Safety Automatically (on macOS and iOS)
Are QR codes safe to scan and follow?
No, not automatically.
Treat QR codes like any other link and do not follow them until you have checked for safety. Use your phone’s camera to turn the QR code into a URL, then inspect the URL using the steps above before you open it.
What if I already clicked a suspicious link?
Following a link is typically not by itself a disaster. Often, the goal is for you to take action on the phishing page. Instead:
- Close the browser tab or window.
Important: Do not enter any information, download necessary tools or follow any further links on the page. - If you entered log-in data such as a password, log in to the service’s website or app using the official URL and change your password.
- If you typed other personal data (such as credit card details, social security numbers or banking information), contact the institution by phone or a secure connection using the official website or app.
- If a file was downloaded, do not open it; you can scan it using a file scanner; see above.
(Tested with desktop browsers; first published March 2019, last updated August 2026)
