Key Takeaways
- Most phishing attacks rely on users clicking without pausing to inspect the link first.
- You can evaluate a suspicious link in under a minute using free, built-in browser tools.
- URL structure, sender context, and domain age are the three most reliable quick-check signals.
- Never enter credentials on a page you reached through an unverified link.
- Link-checking tools add a useful layer but are not a substitute for basic visual inspection.
Summary
18 items · 5–10 minutes per link review
Why a Link Check Takes Less Than a Minute — and Why It Matters
Phishing attacks — attempts to steal your login credentials, financial information, or personal data by tricking you into visiting a fake site — remain one of the most common ways people get compromised online. The overwhelming majority succeed not through technical exploits, but because the target clicked a link without pausing to look at it.
The good news: most malicious links have visible tells, and spotting them requires no special software. This checklist walks you through what to look for before opening any link you didn't actively seek out — whether it arrived by email, text message, social media DM, or a chat app. For a deeper walkthrough of specific lookup tools, see how to verify a suspicious link step by step.
Mobile Devices Make URL Inspection Harder
On a smartphone, the full URL is often hidden or truncated in messaging apps and email clients. Long-pressing a link usually shows a preview, but the display can still be cut off. When in doubt on mobile, copy the link and paste it into a URL scanner rather than tapping it directly.
What You Need Before You Start
No special setup is required to work through this checklist. The tools below make the process faster or more thorough, but the core visual checks need nothing more than your eyes and the device you're already on.
URL expander service
Reveals the true destination behind shortened links before you visit them.
WHOIS lookup tool
Shows when a domain was registered, helping flag newly created fake sites.
Link scanner (e.g., Google Safe Browsing Transparency Report or VirusTotal)
Checks a URL against databases of known malicious sites and phishing pages.
Private or incognito browser window
Opens links in an isolated session that doesn't share cookies or saved credentials.
The Checklist
Work through these checks in order. If any item raises a red flag, stop and treat the link as unsafe until you can confirm otherwise. You do not need to complete every item on every link — the first group alone will catch the majority of obvious threats.
Inspect the URL Before Clicking
Evaluate the Source and Context
Use Available Tools to Go Deeper
Protect Yourself If You Do Open the Link
Never Enter Credentials Through an Unverified Link
Even if a page looks exactly like your bank's or email provider's login screen, entering your password on a phishing page hands your credentials directly to an attacker. If you arrived at a login page by clicking a link — rather than typing the address yourself — close the tab and navigate there manually. This single habit prevents the most common form of account takeover.
Strengthening your link habits pairs well with broader security hygiene. Our home network security audit checklist covers the router and device-level gaps that let attackers get a foothold in the first place, and the device security audit you can do in 15 minutes helps you review phone and computer settings that affect how safely you browse.
What to Do If a Link Looks Suspicious
If you've worked through the checklist and something doesn't add up, these steps reduce your risk without requiring you to visit the link at all:
- Go direct. If the link claims to be from your bank, shipping carrier, or a known service, navigate there manually by typing the address into your browser — don't click the link.
- Search the organization independently. Use a search engine to find the company's real contact page and verify whether the message is legitimate.
- Report and delete. Most email clients and mobile platforms allow you to report phishing. Doing so helps protect others. Then delete the message.
- Check app permissions if you did click. If you clicked before running these checks and something felt off, review the app evaluation checklist and consider whether any app was silently installed. Also review your scams and phishing resources for next steps.
Building this habit takes practice, but it quickly becomes second nature. A few seconds of inspection is a reasonable trade for the time and stress of recovering from a compromised account.
