Email Scams
How to Check If a Link Is Safe Before You Click
The link is where scams happen. Six ways to check one — from a two-second hover to asking a human.
Quick answer
Six ways to check a link: (1) hover or long-press to preview the real destination before clicking; (2) read the actual domain — the part just before the first single slash — and check it's the company's real one; (3) watch for lookalikes (amaz0n, paypal-secure.info, extra words before the real name); (4) never use an email link to reach a login page — open the app instead; (5) paste the link into a reputation checker like Google's Safe Browsing tool (transparencyreport.google.com) or VirusTotal; (6) when it's an email and you're still unsure, forward the whole message to check@spamcheck.com and get a plain-English verdict in under a minute. When in doubt, don't click — real notices survive independent checking.
1. Preview before you click
On a computer, hover your mouse over the link (don't click) and the real destination appears in the corner of your browser or email window. On a phone, press and hold the link to preview it. The text of the link means nothing — 'Sign in to PayPal' can point anywhere. Only the previewed address counts.
2. Find the real domain
In a web address, the domain is the part immediately before the first single slash: in secure-login.paypal.com.evil-site.ru/verify, the domain is evil-site.ru — everything before it is decoration. Scammers rely on people reading the friendly words at the start. Train your eye to find the last two chunks before the first slash, and check them against the company's real domain.
3. Know the lookalike tricks
Common disguises: swapped characters (amaz0n, paypaI with a capital i), extra words (paypal-secure.com, apple-id-verify.net), and wrong endings (amazon-support.co instead of .com). Real companies use their plain, boring domains. Anything with urgency words, hyphens, or additions in the domain is a strong scam signal on its own.
4. The login-page rule
The single highest-value habit: never arrive at a sign-in page from an email or text link. Fake login pages are now visually perfect — checking the page itself won't save you. Instead, open the company's app or type the address yourself. If the alert in the email was real, the same alert will be inside your account. This one habit defeats the majority of credential phishing.
5. Use a free reputation checker
For a second technical opinion, paste the link (never click it) into VirusTotal (virustotal.com) or Google's Safe Browsing site status tool. These check the address against databases of known malicious sites. A clean result lowers the risk but doesn't eliminate it — brand-new scam sites may not be flagged yet — so treat 'no detection' as reassuring, not conclusive.
6. Ask a human
For emails specifically, the simplest check requires no technical skill at all: forward the message to check@spamcheck.com. We examine the sender, the real link destinations, and the message itself, and reply in plain English — usually in under a minute — telling you whether it's safe and what to do next. Your first check is free, and no signup is needed.
If you already clicked
Clicking alone usually does nothing — the damage happens at the next step. If you entered a password, change it immediately on the real site and enable two-factor authentication. If you entered card details, call the number on the back of the card. If a file downloaded, don't open it; see our guide 'I Downloaded an Attachment From a Suspicious Email' for the full cleanup steps.
Frequently asked questions
- Are shortened links (bit.ly etc.) always suspicious?
- Not always — legitimate organizations use them in texts and social posts — but they hide the destination, which is exactly what scammers want. Treat a shortened link in an unexpected message as untrusted until verified another way.
- Does the padlock or 'https' mean a site is safe?
- No. The padlock only means the connection is encrypted — scam sites use https too. It tells you nothing about whether the site is genuine. The domain name is what matters.
Sources
SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.
About SpamCheck
SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.
Related guides
I Clicked a Phishing Link — What Should I Do?
Clicking a phishing link is usually recoverable — especially if you did not type anything on the page that opened. Work through these steps in order.
How to Check If an Email Is Legitimate
Verifying a legitimate email is a different job from spotting an obvious scam. Here is how to confirm a message really came from who it claims.
Is This Email a Scam? How to Check
You have a suspicious email open right now. Here is the fastest reliable way to decide whether it is a scam, without clicking anything in it.
7 Red Flags That an Email Is a Scam
You don't need to be technical. These seven signs catch the overwhelming majority of scam emails before you click.
USPS Scam Texts and Emails: How to Spot Them
'Your package could not be delivered' is the most sent scam text there is. Here is why USPS never charges you that way.
The 10 Most Common Email Scams of 2026 (And How to Spot Each One)
Scammers reuse the same ten plays because they keep working. Learn the one tell that breaks each of them.