How to Check a Suspicious Link Without Clicking It
How to see where a link really goes before you open it, on a phone or computer, and how to read a web address so lookalike and disguised links do not fool you.

Most phishing attacks depend on one click. The link text says one thing and the real destination is something else, a fake login page, a fake shop or a download. The good news is that you can usually see where a link really goes before you open it, and with a little practice you can read a web address as easily as a postal address.
Step 1: See the real address
On a phone
- Press and hold the link, without tapping it. Most phones show a preview or a menu with the full address at the top.
- Choose Copy link if you want to paste it somewhere to check it.
- In some apps, the preview may start loading the page. If that happens, close it without typing anything.
On a computer
- Hover your mouse over the link without clicking. The real address appears in the bottom corner of the browser or email window.
- Right-click and choose "Copy link address" to paste it into a checker.
The text of a link can say anything. "www.yourbank.com" written in a message can point to a completely different site. Always look at the real destination.
Step 2: Find the real domain
The domain is the part that shows who owns the site. To find it:
- Ignore
https://at the start. - Find the first single slash
/after that. Everything after it is just a page on the site. - Just before that slash, read the last two parts (sometimes three, for addresses like
.co.uk). That is the domain.
| Address | Real domain | Verdict |
|---|---|---|
https://www.example-bank.com/login | example-bank.com | Belongs to the bank, if that is its real domain. |
https://example-bank.com.secure-login[.]net/verify | secure-login.net | Not the bank. The bank's name is just a label at the front. |
https://login-example-bank[.]com | login-example-bank.com | A different domain that includes the bank's name. |
https://examp1e-bank[.]com | examp1e-bank.com | A lookalike, with the number 1 in place of the letter l. |
These are illustrative addresses; the scam ones are deliberately broken so they cannot be opened.
Step 3: Look for common disguises
- Lookalike spellings: swapped letters, extra letters, numbers for letters, or characters from other alphabets.
- Brand names in the wrong place: at the start or in the path, not in the domain.
- Unusual endings: a bank you know as
.comsuddenly using.info,.topor.xyz. - Short links: services that shorten links hide the destination. So do QR codes.
- Long, messy addresses full of random characters designed to push the real domain out of view on a small screen.
Step 4: When in doubt, go direct
The safest check of all needs no link. If a message says there is a problem with your account, a delivery or a payment, open the organization's official app or type its web address yourself, and look there. If the problem is real, you will find it.
What a padlock does and does not mean
The padlock or https means your connection to the site is encrypted. It does not mean the site is honest. Scam sites use padlocks too.
If you already clicked
- If you only opened the page: close it, do not enter anything, and keep your device updated.
- If you entered a password: change it immediately, starting with your email, and turn on two-step verification.
- If you entered card details: call your bank on the number on your card.
- If you downloaded something: do not open it, delete it, and run a security scan.
- If it was on a work device: tell your IT team straight away. See clicked a phishing link at work?
Want a second opinion? Copy the link without opening it and paste it into CyberWatch AI Scan for a free check. See how to use CyberWatch AI Scan.
Checking links is one of the most useful habits you can build. For the rest of the routine, read our guide on how to identify and avoid online scams.
Frequently asked questions
Is it dangerous just to open a suspicious link?
Usually the bigger risk is what you do on the page, such as entering a password or downloading a file. But some pages try to exploit browser weaknesses, so it is best not to open links you doubt, and to keep your phone and browser updated.
What part of a web address shows who owns it?
The main domain: the part just before the first single slash, read from right to left, such as example.com in login.example.com/account. Everything before it can be chosen by whoever owns that domain.
Do shortened links hide the real address?
Yes. Short links and QR codes hide the destination. Use a preview or a checker, or better, go to the organization's website yourself.
Sources
- How to Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
- Report a phishing page, Google Safe Browsing


