Skip to main content

Link Checker

Is this link safe?

A link can look completely normal and still lead to a page built to steal your password. Here is how to tell the difference in under a minute.

Short answer

You cannot judge a link by its text. The text is only a label — the destination is what matters. Expand the link, read the part immediately before the first single slash, and open it in isolation if you are still unsure. When in doubt, do not click: type an address you already trust instead.

Warning signs

  • The text and the destination disagreeA link that reads paypal.com but points somewhere else is the oldest trick there is. On a phone, press and hold the link; on a desktop, hover over it and read the bottom of the window.
  • A brand name appears somewhere other than the domainpaypal.com.secure-login.example belongs to example, not to PayPal. Only the part immediately before the first single slash is the real owner.
  • The address is trying to hurry youverify-now, account-suspended, final-warning. Real companies do not put urgency into a hostname — urgency is there to stop you reading it.
  • The link is shortened or redirectedShorteners hide the destination, and a redirect chain can end anywhere. Expand it before you trust it; a short link proves nothing on its own.

How to check it yourself

  1. Expand the linkOn mobile, press and hold, then preview or copy the address. On desktop, hover and read the status bar at the bottom of the window.
  2. Find the real domainLocate the first single slash after the scheme. Everything before it is the owner. Read right to left until you reach that slash.
  3. Compare it to the brandThe domain must match exactly. paypa1.com with a digit, paypal-secure.com and paypal.com.co are three different owners.
  4. Ignore everything that is not the domainSubdomains, query strings and fragments are decoration. login.paypal.com is PayPal; paypal.com.login.evil.tld is not.

Frequently asked questions

Can a link be safe just because it is HTTPS?

No. HTTPS only means the connection is encrypted, not that the owner is honest. Most phishing sites now hold valid certificates, so always read the domain itself.

Is it safe to click a link just to look at it?

Clicking is exactly what the attacker wants. Copy the address into our link checker first — it inspects the destination without visiting it as you.

What if the link came from a friend?

Their account may already be compromised — that is how these messages spread. Confirm through a second channel before opening anything.

I opened it and the page looked fine. Am I safe?

Not necessarily. A page can load cleanly and still harvest whatever you type into it. If you already entered a password, change it now and turn on two-factor authentication.