Internet & Apps

Before You Click: A Quick Security Check for Suspicious Links

A finger hovering over a laptop trackpad, cursor near a suspicious hyperlink in an email

Key Takeaways

  • Most phishing attacks rely on users clicking without pausing to inspect the link first.
  • You can evaluate a suspicious link in under a minute using free, built-in browser tools.
  • URL structure, sender context, and domain age are the three most reliable quick-check signals.
  • Never enter credentials on a page you reached through an unverified link.
  • Link-checking tools add a useful layer but are not a substitute for basic visual inspection.
5–10 min

Summary

18 items · 5–10 minutes per link review

Phishing attacks — attempts to steal your login credentials, financial information, or personal data by tricking you into visiting a fake site — remain one of the most common ways people get compromised online. The overwhelming majority succeed not through technical exploits, but because the target clicked a link without pausing to look at it.

The good news: most malicious links have visible tells, and spotting them requires no special software. This checklist walks you through what to look for before opening any link you didn't actively seek out — whether it arrived by email, text message, social media DM, or a chat app. For a deeper walkthrough of specific lookup tools, see how to verify a suspicious link step by step.

Mobile Devices Make URL Inspection Harder

On a smartphone, the full URL is often hidden or truncated in messaging apps and email clients. Long-pressing a link usually shows a preview, but the display can still be cut off. When in doubt on mobile, copy the link and paste it into a URL scanner rather than tapping it directly.

What You Need Before You Start

No special setup is required to work through this checklist. The tools below make the process faster or more thorough, but the core visual checks need nothing more than your eyes and the device you're already on.

Required

URL expander service

Reveals the true destination behind shortened links before you visit them.

Optional

WHOIS lookup tool

Shows when a domain was registered, helping flag newly created fake sites.

Optional

Link scanner (e.g., Google Safe Browsing Transparency Report or VirusTotal)

Checks a URL against databases of known malicious sites and phishing pages.

Required

Private or incognito browser window

Opens links in an isolated session that doesn't share cookies or saved credentials.

The Checklist

Work through these checks in order. If any item raises a red flag, stop and treat the link as unsafe until you can confirm otherwise. You do not need to complete every item on every link — the first group alone will catch the majority of obvious threats.

Inspect the URL Before Clicking

Hover over the link (on desktop) or long-press it (on mobile) to preview the actual destination URL before opening it. Must
Check that the domain name matches the organization it claims to represent — look for subtle misspellings like "paypa1.com" or extra words like "amazon-support.net". Must
Confirm the link uses HTTPS rather than plain HTTP, especially if it leads to a login or payment page. Must
Be cautious with shortened URLs (bit.ly, t.co, etc.) — expand them using a free URL-expander tool before visiting. Should
Watch for unusual top-level domains (e.g., .xyz, .click, .tk) on links claiming to be from well-known companies. Should

Evaluate the Source and Context

Ask whether you expected this message — unsolicited links from unknown senders deserve heightened scrutiny regardless of how professional they look. Must
Verify the sender's actual email address or phone number, not just the display name, which can be set to anything. Must
Be skeptical of urgency language such as "your account will be closed" or "claim your prize within 24 hours" — pressure tactics are a common phishing signal. Must
If the link came from a known contact, consider whether their account could have been compromised — an unexpected link from a friend still warrants a quick check. Should

Use Available Tools to Go Deeper

Paste the URL into a reputable link-scanning service (such as Google Safe Browsing's transparency report or VirusTotal) to check it against known threat databases. Should
Look up the domain's registration date using a WHOIS lookup tool — a domain registered within the past few weeks is a meaningful warning sign. Nice to have
If your browser or security software flags the page with a warning, do not click through or dismiss the warning without reading it carefully. Must

Protect Yourself If You Do Open the Link

Never enter a username, password, or payment information on a page you reached through an unverified link — navigate to the site directly instead. Must
Open unfamiliar links in a private or incognito browser window to limit cookie and session exposure. Should
If a page immediately asks you to download a file or install a browser extension, close the tab without complying. Must
After visiting a suspicious page, clear your browser's cache and cookies for that session. Should
Enable two-factor authentication (2FA) on important accounts so that a stolen password alone is not enough to gain access. Should
Consider using a dedicated browser profile or container for sensitive activities like banking, keeping it separate from general browsing. Nice to have

Never Enter Credentials Through an Unverified Link

Even if a page looks exactly like your bank's or email provider's login screen, entering your password on a phishing page hands your credentials directly to an attacker. If you arrived at a login page by clicking a link — rather than typing the address yourself — close the tab and navigate there manually. This single habit prevents the most common form of account takeover.

Strengthening your link habits pairs well with broader security hygiene. Our home network security audit checklist covers the router and device-level gaps that let attackers get a foothold in the first place, and the device security audit you can do in 15 minutes helps you review phone and computer settings that affect how safely you browse.

If you've worked through the checklist and something doesn't add up, these steps reduce your risk without requiring you to visit the link at all:

  • Go direct. If the link claims to be from your bank, shipping carrier, or a known service, navigate there manually by typing the address into your browser — don't click the link.
  • Search the organization independently. Use a search engine to find the company's real contact page and verify whether the message is legitimate.
  • Report and delete. Most email clients and mobile platforms allow you to report phishing. Doing so helps protect others. Then delete the message.
  • Check app permissions if you did click. If you clicked before running these checks and something felt off, review the app evaluation checklist and consider whether any app was silently installed. Also review your scams and phishing resources for next steps.

Building this habit takes practice, but it quickly becomes second nature. A few seconds of inspection is a reasonable trade for the time and stress of recovering from a compromised account.

Internet & Apps Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Internet & Apps Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.