Email Scams

How to Check If a Link Is Safe Before You Click

The link is where scams happen. Six ways to check one — from a two-second hover to asking a human.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

Six ways to check a link: (1) hover or long-press to preview the real destination before clicking; (2) read the actual domain — the part just before the first single slash — and check it's the company's real one; (3) watch for lookalikes (amaz0n, paypal-secure.info, extra words before the real name); (4) never use an email link to reach a login page — open the app instead; (5) paste the link into a reputation checker like Google's Safe Browsing tool (transparencyreport.google.com) or VirusTotal; (6) when it's an email and you're still unsure, forward the whole message to check@spamcheck.com and get a plain-English verdict in under a minute. When in doubt, don't click — real notices survive independent checking.

1. Preview before you click

On a computer, hover your mouse over the link (don't click) and the real destination appears in the corner of your browser or email window. On a phone, press and hold the link to preview it. The text of the link means nothing — 'Sign in to PayPal' can point anywhere. Only the previewed address counts.

2. Find the real domain

In a web address, the domain is the part immediately before the first single slash: in secure-login.paypal.com.evil-site.ru/verify, the domain is evil-site.ru — everything before it is decoration. Scammers rely on people reading the friendly words at the start. Train your eye to find the last two chunks before the first slash, and check them against the company's real domain.

3. Know the lookalike tricks

Common disguises: swapped characters (amaz0n, paypaI with a capital i), extra words (paypal-secure.com, apple-id-verify.net), and wrong endings (amazon-support.co instead of .com). Real companies use their plain, boring domains. Anything with urgency words, hyphens, or additions in the domain is a strong scam signal on its own.

4. The login-page rule

The single highest-value habit: never arrive at a sign-in page from an email or text link. Fake login pages are now visually perfect — checking the page itself won't save you. Instead, open the company's app or type the address yourself. If the alert in the email was real, the same alert will be inside your account. This one habit defeats the majority of credential phishing.

5. Use a free reputation checker

For a second technical opinion, paste the link (never click it) into VirusTotal (virustotal.com) or Google's Safe Browsing site status tool. These check the address against databases of known malicious sites. A clean result lowers the risk but doesn't eliminate it — brand-new scam sites may not be flagged yet — so treat 'no detection' as reassuring, not conclusive.

6. Ask a human

For emails specifically, the simplest check requires no technical skill at all: forward the message to check@spamcheck.com. We examine the sender, the real link destinations, and the message itself, and reply in plain English — usually in under a minute — telling you whether it's safe and what to do next. Your first check is free, and no signup is needed.

If you already clicked

Clicking alone usually does nothing — the damage happens at the next step. If you entered a password, change it immediately on the real site and enable two-factor authentication. If you entered card details, call the number on the back of the card. If a file downloaded, don't open it; see our guide 'I Downloaded an Attachment From a Suspicious Email' for the full cleanup steps.

Frequently asked questions

Are shortened links (bit.ly etc.) always suspicious?
Not always — legitimate organizations use them in texts and social posts — but they hide the destination, which is exactly what scammers want. Treat a shortened link in an unexpected message as untrusted until verified another way.
Does the padlock or 'https' mean a site is safe?
No. The padlock only means the connection is encrypted — scam sites use https too. It tells you nothing about whether the site is genuine. The domain name is what matters.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides