Online Security

Verifying a Suspicious Link Before You Click It

A hand pausing over a laptop trackpad before clicking a suspicious-looking URL in a browser

Key Takeaways

  • Hovering over a link reveals its true destination before you click it.
  • Shortened URLs can hide malicious destinations — always expand them first.
  • Free online tools let you check a URL's reputation without visiting the site.
  • Mismatched or misspelled domain names are a reliable signal of phishing.
  • When in doubt, navigate directly to a site rather than following a link.
3–10 min
Beginner

What you will need

A desktop or laptop browser (hover previews work best on non-touch devices)
Access to a search engine or a free URL-checking tool such as Google Safe Browsing's transparency report or VirusTotal
A URL shortener expander (several free web-based tools are available)

Phishing links — URLs crafted to steal credentials or install malware — routinely arrive by email, text, social media, and even calendar invites. They often look indistinguishable from legitimate messages at a glance. Understanding what makes a link dangerous is the foundation of staying safe. For broader context on the types of scams that use malicious links, see our complete consumer guide to online scams and phishing.

The core problem is that the visible text of any hyperlink can say one thing while the actual destination is something completely different. Attackers exploit that gap. The tools and techniques below let you inspect what's really behind a link — quickly, and without risk.

Never Click to Test a Suspicious Link

There is no safe way to 'just peek' at an untrusted link by clicking it. Even loading a malicious page can trigger drive-by downloads or tracking scripts. Always use the verification methods below before any click takes place.

These checks take under a minute once they become habit. Pairing them with safe browsing habits makes them even more effective over time.

Work through the steps below in order. You can stop as soon as the link either clears all checks or fails one — there is no need to complete every step if the answer becomes obvious early.

What you will need

A desktop or laptop browser (hover previews work best on non-touch devices)
Access to a search engine or a free URL-checking tool such as Google Safe Browsing's transparency report or VirusTotal
A URL shortener expander (several free web-based tools are available)
Required

Browser hover preview (status bar)

Reveals the full destination URL when you rest your cursor over a link — no external tool required.

Required

URL expander service

Unshortens compressed links so you can read the real destination domain before visiting.

Optional

Google Safe Browsing Transparency Report

Checks whether Google has flagged a URL as dangerous or deceptive.

Optional

VirusTotal URL scanner

Submits a URL to dozens of security engines simultaneously and reports any threat detections.

Optional

WHOIS lookup tool

Shows when a domain was registered and who owns it — useful for spotting newly created impersonation sites.

1

Hover over the link to preview the destination

On a desktop browser, rest your cursor over the link without clicking. The full URL appears in the status bar at the bottom-left of the browser window. Look at the domain — the core website address — and ask: does it match the organization the message claims to represent? A link labeled "PayPal Security Alert" should show a domain ending in paypal.com, not paypa1.com or paypal-security-alerts.net.

Tip: On mobile, press and hold the link to reveal a preview of the URL before opening it.
2

Scrutinize the domain for impersonation tricks

Attackers use several predictable techniques to make fake domains look legitimate. Watch for: typosquatting (amazom.com instead of amazon.com), subdomain tricks (paypal.com.malicious-site.net — the real domain is malicious-site.net), character swaps (using the numeral 0 instead of the letter O), and extra words (apple-support-login.com). If anything looks off, treat the link as unsafe.

Warning: The display text of a hyperlink can say anything — always read the actual URL, not the linked text.
3

Expand shortened URLs before proceeding

Copy the shortened link (right-click → Copy link address, or long-press on mobile). Paste it into a free URL-expander service in a new browser tab. The tool will follow the redirect chain and show you the final destination without loading it in your browser. Evaluate that expanded URL using the same domain checks from Step 2.

Warning: Do not paste a suspicious URL into your address bar to expand it — that will load the page immediately.
4

Run the URL through a reputation checker

Copy the full URL and paste it into a reputable scanner. Google's Safe Browsing Transparency Report and VirusTotal are two widely used, free options. These tools cross-reference the URL against databases of known malicious sites and report any flags. A clean result is reassuring but not a guarantee — brand-new phishing pages may not yet be indexed.

Tip: VirusTotal shows results from multiple security vendors at once, so a single detection among many may be a false positive — look at the overall pattern.
5

Check the domain's registration age with a WHOIS lookup

If the URL passed the previous checks but still feels off, look up the domain on a WHOIS lookup tool. A domain registered within the last few weeks impersonating a major brand is a strong phishing indicator — legitimate companies typically own their domains for years. Note the registrar, registration date, and whether contact information has been deliberately hidden.

6

Decide: visit, delete, or report

After your checks, make a clear decision. If the URL is verified and expected, proceed. If anything raised concern, delete the message without clicking. You can also report phishing links to your email provider (most have a 'Report phishing' button), to the APWG at reportphishing@apwg.org, or forward SMS scams to 7726 (SPAM) in the US. Reporting helps protect others facing the same attack.

Tip: If you clicked before completing these checks, see our guide on what to do after clicking a phishing link for immediate next steps.

When Unsure, Go Directly to the Source

If a link claims to come from your bank, a retailer, or a government agency, skip the link entirely. Open a new browser tab, type the organization's official address manually, and log in from there. This single habit sidesteps the majority of phishing attempts.

Shortened URLs Obscure Real Destinations

Services that shorten URLs (producing links like bit.ly/xyz) completely hide the actual domain. Treat every shortened link as unverified until you expand and inspect it. Do not rely on the surrounding text or sender name as proof of safety.

For a faster reference version of these checks — useful when you're on a mobile device or short on time — see the quick security checklist for suspicious links. And if you want to build these checks into a broader set of protective habits, our guide on habits that protect you from scams covers the full picture.

Online Security Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Online Security Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.