How to check a link before you click it

Updated · 5 minute read · By the IsSiteLegit team · How we write our guides

Most online scams start with a link: in a text about a parcel, an email about your account, or a message from a "friend". A few simple habits let you see where a link really goes before it can do any harm.

Rule number one: don't click links you weren't expecting

If a message says there's a problem with your bank, a parcel, a tax refund or a streaming account, don't use the link in the message. Open the company's app, or type its address yourself, and log in there. If something really needs your attention, you'll see it. This one habit stops most phishing.

See where the link goes

  • On a computer: hover your mouse over the link without clicking. The real address appears in the bottom corner of the browser or email program.
  • On a phone: press and hold the link (don't tap). A preview shows the address — then tap outside the menu to close it.

The text of a link can say anything. Only the address it points to counts.

Read the address the right way

The part that matters is the main name just before the first single slash, together with its ending (like .com or .co.uk). Read it from the right:

  • https://www.paypal.com/signin — the site is paypal.com. Fine.
  • https://paypal.com.account-verify.net/signin — the site is account-verify.net. Everything before it is decoration. Not PayPal.
  • https://secure-paypal-login.com — the site is secure-paypal-login.com, which is not paypal.com, even though it contains the name.

Scammers rely on people reading from the left and stopping at the familiar word. Reading from the right, up to the first single slash, avoids the trick.

Watch for look-alike letters

Names like paypa1.com (a number one instead of an L), arnazon.com ("rn" instead of "m") or micros0ft.com (a zero) are made to fool a quick glance. Some even use letters from other alphabets that look identical. IsSiteLegit checks every address against well-known brands and flags these as Brand impersonation.

Short links and QR codes

Short links (like bit.ly/…) and QR codes hide the real address. If you weren't expecting one, don't open it. If you need to, many link shorteners show a preview when you add a + to the end of the link, and most phone cameras show the address of a QR code before opening it — read it first. Be especially careful with QR codes stuck on parking meters or posters, where a fake sticker can be placed over the real one.

Check the website before you trust it

If you want to know more about a site, copy the link (don't open it) and paste it into IsSiteLegit. We never send you to the site: we check it from our side, then show you its age, whether it's on a security blacklist for phishing or malware, whether it imitates a brand, and more. You can also see recently flagged high-risk sites.

Remember that a site can be real and still not be the one the message claims to be from. A link to a genuine file-sharing or form service can still lead to a fake login page someone created there.

If you already clicked

  • Clicking alone usually does little harm. Close the page and don't enter anything.
  • If you typed a password, change it right away (and anywhere else you use it), and turn on two-step verification.
  • If you entered card or bank details, call your bank using the number on your card. Our guide what to do if you paid a scam website has the full checklist.
  • If a file downloaded, don't open it. Delete it and run your device's security scan.

Check a website now

Free. We show every piece of evidence we find, so you can judge for yourself.

See real results