Key Takeaways
- Hovering over a link reveals its true destination before you click it.
- Shortened URLs can hide malicious destinations — always expand them first.
- Free online tools let you check a URL's reputation without visiting the site.
- Mismatched or misspelled domain names are a reliable signal of phishing.
- When in doubt, navigate directly to a site rather than following a link.
What you will need
Why Suspicious Links Are Worth a Closer Look
Phishing links — URLs crafted to steal credentials or install malware — routinely arrive by email, text, social media, and even calendar invites. They often look indistinguishable from legitimate messages at a glance. Understanding what makes a link dangerous is the foundation of staying safe. For broader context on the types of scams that use malicious links, see our complete consumer guide to online scams and phishing.
The core problem is that the visible text of any hyperlink can say one thing while the actual destination is something completely different. Attackers exploit that gap. The tools and techniques below let you inspect what's really behind a link — quickly, and without risk.
Never Click to Test a Suspicious Link
There is no safe way to 'just peek' at an untrusted link by clicking it. Even loading a malicious page can trigger drive-by downloads or tracking scripts. Always use the verification methods below before any click takes place.
These checks take under a minute once they become habit. Pairing them with safe browsing habits makes them even more effective over time.
How to Verify a Link Step by Step
Work through the steps below in order. You can stop as soon as the link either clears all checks or fails one — there is no need to complete every step if the answer becomes obvious early.
What you will need
Browser hover preview (status bar)
Reveals the full destination URL when you rest your cursor over a link — no external tool required.
URL expander service
Unshortens compressed links so you can read the real destination domain before visiting.
Google Safe Browsing Transparency Report
Checks whether Google has flagged a URL as dangerous or deceptive.
VirusTotal URL scanner
Submits a URL to dozens of security engines simultaneously and reports any threat detections.
WHOIS lookup tool
Shows when a domain was registered and who owns it — useful for spotting newly created impersonation sites.
Hover over the link to preview the destination
On a desktop browser, rest your cursor over the link without clicking. The full URL appears in the status bar at the bottom-left of the browser window. Look at the domain — the core website address — and ask: does it match the organization the message claims to represent? A link labeled "PayPal Security Alert" should show a domain ending in paypal.com, not paypa1.com or paypal-security-alerts.net.
Scrutinize the domain for impersonation tricks
Attackers use several predictable techniques to make fake domains look legitimate. Watch for: typosquatting (amazom.com instead of amazon.com), subdomain tricks (paypal.com.malicious-site.net — the real domain is malicious-site.net), character swaps (using the numeral 0 instead of the letter O), and extra words (apple-support-login.com). If anything looks off, treat the link as unsafe.
Expand shortened URLs before proceeding
Copy the shortened link (right-click → Copy link address, or long-press on mobile). Paste it into a free URL-expander service in a new browser tab. The tool will follow the redirect chain and show you the final destination without loading it in your browser. Evaluate that expanded URL using the same domain checks from Step 2.
Run the URL through a reputation checker
Copy the full URL and paste it into a reputable scanner. Google's Safe Browsing Transparency Report and VirusTotal are two widely used, free options. These tools cross-reference the URL against databases of known malicious sites and report any flags. A clean result is reassuring but not a guarantee — brand-new phishing pages may not yet be indexed.
Check the domain's registration age with a WHOIS lookup
If the URL passed the previous checks but still feels off, look up the domain on a WHOIS lookup tool. A domain registered within the last few weeks impersonating a major brand is a strong phishing indicator — legitimate companies typically own their domains for years. Note the registrar, registration date, and whether contact information has been deliberately hidden.
Decide: visit, delete, or report
After your checks, make a clear decision. If the URL is verified and expected, proceed. If anything raised concern, delete the message without clicking. You can also report phishing links to your email provider (most have a 'Report phishing' button), to the APWG at reportphishing@apwg.org, or forward SMS scams to 7726 (SPAM) in the US. Reporting helps protect others facing the same attack.
When Unsure, Go Directly to the Source
If a link claims to come from your bank, a retailer, or a government agency, skip the link entirely. Open a new browser tab, type the organization's official address manually, and log in from there. This single habit sidesteps the majority of phishing attempts.
Shortened URLs Obscure Real Destinations
Services that shorten URLs (producing links like bit.ly/xyz) completely hide the actual domain. Treat every shortened link as unverified until you expand and inspect it. Do not rely on the surrounding text or sender name as proof of safety.
For a faster reference version of these checks — useful when you're on a mobile device or short on time — see the quick security checklist for suspicious links. And if you want to build these checks into a broader set of protective habits, our guide on habits that protect you from scams covers the full picture.
