Is this link safe? How to check a link before you click it

A link in a text or email you don't trust? Here is how to see where it really goes without opening it: read the domain the right way, deal with short links, and what to do if you already tapped it.

The twenty-second version

  1. Find the real domain. It is the part just before the first single slash, and you read it from the right.
  2. If it is a short link (bit.ly, tinyurl and the like), assume you cannot see where it goes until something expands it.
  3. Ask what the message wants from you. Pay, log in, "verify", or install something means stop.
  4. Still not sure? Copy the link, don't open it, and paste it into a checker that opens it somewhere other than your phone.

Everything below is the reasoning behind those four steps, because a rule you understand is a rule you still use when the text looks convincing.

Read the domain from the right

A web address can say anything on its left side. Only the end of it tells you who owns the site.

Take https://www.paypal.com.account-review.help/login. It starts with "paypal.com", but the site is account-review.help. Everything to the left of the last two parts is a label the owner of account-review.help typed in, and they can type whatever they like there.

A few more that are built the same way:

  • amazon.com-orders.shop is a site called com-orders.shop
  • usps.redelivery-support.com is a site called redelivery-support.com
  • yourbank-secure-login.online is not your bank. Your bank has one address, and it does not need three extra words to prove it

Look-alikes are the other trick: paypa1.com with a number one, rnicrosoft.com where "r" and "n" pretend to be an "m", or the real name with an extra word stuck on. On a phone screen these are easy to miss, which is exactly why they are used.

The ending matters too. Newer endings such as .top, .xyz, .shop and .online make up about a tenth of all registered domains but around half of the domains reported for phishing, according to Interisle's 2025 phishing study. That is not proof of anything on its own, but your bank and your delivery company are not texting you from one.

Short links hide the destination

A short link, like bit.ly/3xYz or tinyurl.com/abc, is a redirect. You tap it, and it forwards you somewhere else. Real companies use them, and so do scammers, for the same reason: it keeps the long address out of sight.

Some links redirect more than once. A scam text might send you through a short link, then a tracking page, then the page that actually asks for your card. The address you were shown and the address you end up at can have nothing in common.

So treat a short link as unread. You do not know where it goes until something has followed it to the end.

What the message is asking you to do

The link is only half of it. Read the message around it and ask one question: what does it want me to do next?

Scam texts in the US keep coming back to the same few stories: an unpaid toll, a package that "could not be delivered", a charge you supposedly made, an account that will be locked today, a job that pays too well for too little. The details change every month. The shape does not: something urgent, a link, and then a request to pay, to sign in, or to "confirm" your details.

A real company can reach you about a real problem without you tapping its link. Close the message, open the company's own app or type its address yourself, and look. If the problem is real, it will be there.

Two facts that settle the most common ones. The US Postal Inspection Service says USPS only texts you if you asked for tracking, and even then the text will not contain a link (USPIS). And for "unpaid toll" texts, the FTC's advice is to contact your state's tolling agency using a number or website you know is real, not the one in the text (FTC).

Copy the link, don't open it

On a phone, press and hold the link and choose Copy. On a computer, right-click and copy the link address, or hover over it and read the address your browser shows at the bottom of the window. In an email, the words of a link and the address behind it can be completely different, so read the address, not the words.

Be careful with previews. On some phones, pressing and holding a link shows a small preview of the page, and that preview has already loaded it. If you see one, read the address at the top and tap outside it to close.

What a link checker can and can't tell you

Paste the link into our link checker and we open it for you, in a browser that is not yours. We follow every redirect to where it really ends and tell you what is there: the final domain and how old it is, whether it is on public blocklists, whether the page imitates a well-known brand, asks for a password or a payment, or pushes an app download, and whether people have reported it to us. You get one of four levels with every reason listed. It is free and there is no sign-up.

What no checker can do is promise that a link is safe. A scam page can look clean in its first hours, before anyone has reported it, and any page can change after it has been checked. If a page asks for a password, a one-time code or money you did not plan to send, that is your answer, whatever any checker says.

If you already tapped it

Don't panic. What you do next depends on how far you got.

  • You opened it and typed nothing. Close it. The most it usually tells the sender is that your number reaches a real person, so expect more texts and ignore them.
  • It started a download, or you installed something. Delete it, and don't open anything it installed.
  • You typed a password. Change it now, on the real site, and anywhere else you use the same one. Turn on two-step verification.
  • You entered card or bank details. Call the number on the back of your card, or your bank's number from its official website, and ask them to block the card and watch the account.

Then report it, so the next person is warned. Forward a scam text to 7726 (it spells SPAM), and report the scam to the Federal Trade Commission at reportfraud.ftc.gov.

"Low risk" means the checks we ran found nothing wrong at the moment we looked. It is not a promise that a site is safe.

Check a link before you click it

Paste the link or scan the QR code. We open it for you and show the real destination, the redirects on the way, and whether anyone has reported the seller behind it.

Check a link
Add Glar as a friend on LINE and have him check links for you