Checking if a website is safe before you click takes under a minute: hover over the link to preview the real destination, confirm the domain is spelled correctly and uses HTTPS, and run the URL through a free reputation scanner like Google Safe Browsing. If anything looks off, do not click.
A safe link check starts with the URL itself, not the page behind it. Hover to reveal the true destination, read the domain from right to left to catch look-alikes, and require HTTPS for anything involving a login or payment. Free tools such as Google Safe Browsing, VirusTotal and a web directory listing add a second opinion in seconds. Phishing remains the most reported online crime, and most attacks fail the moment you slow down and inspect the address before clicking.
How do you check a link before clicking it?
Hover your mouse over any link and read the destination shown in the bottom corner of your browser, or press and hold the link on mobile to preview it. The visible text and the real address are often different, and that gap is where most scams live.
Attackers rely on you trusting the words in a link rather than the address underneath. A button that says “Confirm your account” can point anywhere. On a computer, hovering exposes the true target without loading anything. On a phone, a long-press opens a preview menu that shows the full URL so you can inspect it safely.
Read the domain from right to left. The real identity of a site sits just before the first single slash: in login.paypal.com.secure-check.ru the actual domain is secure-check.ru, not PayPal. Scammers stuff trusted brand names into the left side of the address precisely because most people read left to right and stop early.
Watch for subtle misspellings and swapped characters, a trick called typosquatting. Domains like arnazon.com, paypa1.com or faceboook.com are registered by the thousand to catch fast clickers. If a link arrived unexpectedly by email or text, treat it as guilty until proven safe.
Shortened links (bit.ly, tinyurl and similar) hide the destination on purpose, which is convenient for marketers and equally convenient for scammers. Before trusting one, paste it into a link-expander or preview service, or add a + to the end of many bit.ly links to see the real target and click statistics without visiting the page. If a message pressures you to open a shortened link “right now,” that urgency is itself a warning sign.
Does HTTPS and the padlock mean a site is safe?
HTTPS and the padlock mean your connection to the site is encrypted, not that the site itself is honest. Encryption stops outsiders from reading your data in transit, but scammers can obtain the same free certificates as anyone else, so the padlock alone proves very little.
Free certificate authorities issue millions of certificates automatically, and phishing operators use them too. Security researchers have repeatedly found that a large share of phishing pages now load over HTTPS, which means the padlock has quietly become a poor standalone signal of trust. Treat it as a minimum requirement, never as a seal of approval.
What HTTPS does guarantee is worth keeping: any page where you enter a password, card number or personal details should show it. A checkout or login screen served over plain HTTP is an immediate reason to leave. But once HTTPS is present, your real judgment work begins rather than ends.
For a fuller breakdown of why the padlock is so often misread, see our guide on how to tell if a website is trustworthy, which walks through the trust signals that actually correlate with a legitimate business.
Which free tools check whether a website is safe?
Several free scanners rate a site’s safety in seconds: Google Safe Browsing Site Status, VirusTotal, and reputation lookups such as a web directory profile. Each checks a different signal, so running two or three together gives a far more reliable verdict than any single result.
Google Safe Browsing powers the red warning screens in Chrome, Safari and Firefox and protects more than five billion devices, according to Google. Paste any URL into its public Site Status checker to see whether Google has flagged the page for malware or phishing. It is fast, neutral and needs no account.
VirusTotal aggregates more than seventy security engines and blocklists into one report. A clean scan across dozens of vendors is a strong positive signal; even a couple of detections is reason to stop. For a broader reputation picture, a directory profile on a service like the webwiki.com web directory shows how long a site has been listed, which category it sits in, and what visitors have said about it.
None of these tools is perfect on its own. Brand-new scam sites can appear clean for a few hours before blocklists catch up, which is exactly why the manual URL checks above matter as your first line of defense.
A “clean” result from a scanner is reassuring but not a guarantee. Freshly created phishing pages often go undetected for their first hours online because blocklists update on a delay. If a link arrived unexpectedly or pushes you to act urgently, do not rely on tools alone. Go to the company’s website directly by typing the address yourself rather than clicking the link you were sent.
What are the warning signs of an unsafe link?
The clearest red flags are unexpected arrival, urgency, misspelled or look-alike domains, requests for passwords or payment, and mismatches between the link text and its real destination. Any one of these justifies caution; two or more together almost always signal a scam.
Unsolicited messages create false urgency because pressure short-circuits careful thinking. “Your account will be closed in 24 hours” and “Confirm this delivery now” are designed to make you click before you inspect. Legitimate companies rarely threaten immediate consequences over a single unconfirmed link.
Other tells include links that use raw IP addresses instead of a domain name, an unusual or mismatched top-level ending such as a banking “site” on a free subdomain, and pages that ask for information the sender would already have. To understand how these links fit into larger fraud campaigns, our overview of the most common online scams in 2026 maps the tactics behind them.
How can you open a suspicious link more safely?
If you must check a questionable link, never enter any personal data on the page, use a device you can easily reset, and prefer previewing the URL over loading it. When in doubt, reach the organization through its official app or a manually typed address instead.
Modern browsers already sandbox pages, so simply landing on a page rarely infects an up-to-date device on its own. The real damage happens when you type credentials, download a file, or approve a prompt. Keeping your browser and operating system current closes most of the gaps that drive-by pages try to exploit.
For anything genuinely uncertain, expand the short link, scan the full URL with the tools above, and only then decide. If the destination claims to be your bank, your delivery service or a marketplace you use, skip the link entirely and open the site the way you normally would.
My takeAfter reviewing thousands of site profiles, the single most reliable habit is boring: read the domain out loud before you click. Almost every phishing link we see fails that test in the first two seconds because the real domain is wrong, foreign, or clearly not the brand it imitates. Tools are useful as backup, but they lag behind fresh threats by hours. Your own two-second read of the address is the only check that works in real time, on any device, with no account and no install. Slow down for that one breath and you defeat the overwhelming majority of unsafe links before they ever load.
- Hover or long-press to reveal a link’s real destination before clicking.
- Read the domain from right to left; the true identity sits before the first single slash.
- HTTPS and the padlock mean encryption, not honesty; require them but do not trust them alone.
- Run the URL through Google Safe Browsing, VirusTotal and a directory profile for a second opinion.
- Unexpected arrival plus urgency is the most common scam pattern; type the address yourself instead.
Frequently asked questions
Is it dangerous to just click a link once?
Usually the click itself is low risk on an updated device, because browsers isolate pages. The danger comes from what you do next: entering a password, downloading a file, or approving a permission prompt. Keep software current and never submit data on a page you reached from an unexpected message.
How can I see where a shortened link really goes?
Use a link-expander or preview service, or with many bit.ly links add a + to the end of the URL to view the destination and statistics without opening it. If a service pressures you to click a shortened link immediately, treat that urgency as a warning sign.
Does antivirus software check links for me?
Many security suites and browsers include real-time link scanning that blocks known malicious pages, which helps against established threats. It is a valuable layer, but it reacts to threats already on blocklists, so new scam pages can slip through. Combine it with a manual read of the URL.
Is a website with a padlock always safe to buy from?
No. The padlock confirms your connection is encrypted, not that the seller is legitimate. Scammers obtain the same free certificates. Check the domain spelling, look for real contact details and reviews, and confirm the store’s reputation before entering any card information. For a worked example on a major marketplace, see our review of whether AliExpress is legit.
Sources and further reading
- Google Safe Browsing, Site Status transparency report and coverage figures, google.com/transparencyreport
- VirusTotal, multi-engine URL and file reputation scanner, virustotal.com
- Anti-Phishing Working Group (APWG), Phishing Activity Trends Reports, apwg.org
- webwiki.com, How to Tell If a Website Is Trustworthy and The Most Common Online Scams in 2026
Read next: Is AliExpress Legit? Full Review, Ratings and Safety Check (2026). A closer look at is aliexpress legit.
