Scam guide

How to Check a Suspicious Link Before You Click

A suspicious URL can arrive by text, email, social media, or a messaging app. You do not need to decide from a logo or a lock icon alone: inspect the address and reach the real service independently before you sign in, pay, or share information.

Quick answer

To check a suspicious link, do not open it from the message that sent it. Look for misspellings, lookalike domains, strange subdomains, URL shorteners, or an unexpected request to log in or pay. Then open the official app or type the known website address yourself. HTTPS does not automatically mean a site is trustworthy.

Why phishing links are hard to judge

A phishing URL can imitate a familiar brand, use a similar spelling, or hide behind a short link. It may arrive with a fake account-security alert, delivery problem, refund, or payment request. A valid-looking lock icon only means the connection uses HTTPS; it does not prove the site is the real organization.

Fictional example “Your account needs verification. Sign in at account-security-review.example to avoid a lock.” This is fictional. An unexpected login request and a domain that does not match the official service are reasons to stop and navigate independently.

Red flags in a suspicious URL

  • A misspelling, added word, unusual top-level domain, or lookalike domain.
  • A strange subdomain that puts a familiar name before an unrelated domain.
  • A URL shortener that hides the destination.
  • An unexpected login page, payment page, or security alert reached from a message.
  • Pressure to act immediately, enter a one-time code, or confirm card details.
  • A mismatch between the sender’s claim and the official app or account you can open yourself.

How to inspect a link without opening it

  1. Do not tap the link from an unexpected text, email, chat, or social message.
  2. Read or copy the visible address without following it where your device allows.
  3. Check the registered-looking domain, not just a familiar word earlier in the address.
  4. Open the official service’s app or type its known website address into a new browser window.
  5. Use that official channel to check account notices, orders, payments, or support options.

If you already clicked or entered details

Close the page and do not download files or install software it suggests. If you entered credentials, change the password through the real service and anywhere it was reused. If you entered card or payment information, contact the payment provider promptly through a trusted channel. If a link led to an account-security issue, use the official provider’s security tools rather than a callback or follow-up message.

Get a second opinion with Is This a Scam? AI

Is This a Scam? AI can analyze a suspicious URL you choose to submit and provide an AI-assisted risk assessment, risk signals, and suggested next steps. It is a second opinion, not a guarantee that a link is safe or malicious. Sensitive financial, account, and security issues should always be independently verified through official channels.

Use Is This a Scam?

Check Before You Trust. The safest route to an account is the one you open yourself.

Phishing link checker FAQ

Is a shortened link automatically malicious?

No. But a short link can hide the destination, so it is a reason to verify the purpose through an official channel before opening it.

Can a phishing site have HTTPS?

Yes. HTTPS does not establish that a website is the legitimate service you intended to use.

What if I only clicked a suspicious link?

Close the page without entering information or downloading anything. Then use an official app or known address to check the underlying request independently.

Want a second opinion?

Check a message, link, or screenshot with Is This a Scam?.