Check a link before you click
One click usually decides whether a scam works. Reading an address correctly takes ten seconds, needs no software, and defeats most attempts outright.
Most scams need exactly one action from you: the click. Anyone who can read an address in ten seconds spots phishing before it becomes dangerous – and it costs nothing, needs no software and works on every device.
Step 1: Find the real domain
Scammers place well-known brand names where they look harmless. Only one part of the address decides where you actually go: the domain immediately before the first single slash.
| Address | Real domain | Verdict |
|---|---|---|
https://www.yourbank.com/account/login | yourbank.com | genuine |
https://yourbank.com.login-portal.top/account | login-portal.top | fake |
https://yourbank-security.com/verify | yourbank-security.com | unrelated domain |
https://[email protected]/ | malicious.tld | the @ trick |
yourbank.com.secure-login.top belongs to secure-login.top. A dot turns a brand name into nothing more than a subdomain someone else controls.Step 2: Reveal the destination without clicking
The visible link text is just a caption. Here is how to see the real target:
Showing where a link actually goes
- On a computer: hover over the link – the real address appears at the bottom of the browser. Same in most mail clients.
- On a phone: press and hold the link until a preview with the full address appears, then tap cancel.
- In email: if in doubt, view the message as plain text – the address is written out.
- Never “just take a quick look”: simply opening the page can confirm that your address is active.
Step 3: Expand short links
Shorteners hide the destination completely. That is normal in advertising – but in a message claiming to be from your bank or a delivery company it is a warning sign. Legitimate senders do not hide their own address.
With many shorteners, adding a + to the end of the URL opens a preview page instead of the destination. Otherwise, paste the address into a link expander or a scanning service, which opens it for you and reports where it leads.
Step 4: Check QR codes
A QR code is simply a link you cannot read, which makes it an ideal carrier for fraud. Stickers placed over genuine codes on parking meters, charging points and restaurant tables are a well-documented pattern.
Scanning a QR code safely
- Feel for a sticker: is one code pasted over another? Walk away.
- Use the built-in camera app, not an arbitrary scanner app.
- Read the preview before opening – the real domain sits before the first single slash.
- Never enter payment details on a page opened from a QR code in a public place.
Step 5: The padlock proves less than you think
The padlock in the address bar means the connection is encrypted. It says nothing about who owns the site. Still, one thing is worth doing: never click past a certificate warning. If the browser objects, stop.
The rule that replaces all the others
If a message pushes you towards a login, a payment or confirming personal data: do not use the link at all. Open the app or type the address yourself. If the request is genuine, you will find it there too.If you already clicked
A click alone is rarely the damage – entering data or downloading something is. Close the page and expect more attempts at your address. If you entered credentials, work through account hacked ; if payment details were involved, contact your bank immediately.
More on the messages that carry these links: how to spot phishing .
Frequently asked questions
How do I find the real domain in a long address?
Read from the right until the first single slash. The last part before that slash is the real domain. In yourbank.com.login-portal.top/account, the real domain is login-portal.top – not yourbank.com.
Does the padlock icon mean a site is trustworthy?
No. The padlock only means the connection is encrypted. Scam sites have valid certificates too. Encrypted is not the same as trustworthy.
Can I just click a suspicious link to see where it goes?
No. Use a link expander or a scanning service instead. That shows you the destination without opening the page and without confirming to the sender that your address is active.