🐟 Phishy
HomeScam guides

How to tell if a link is safe before you click

By Moti Shay · updated July 25, 2026

Almost every digital scam runs through a single vector: a link. The text, email or WhatsApp message is just the wrapper — the theft happens on the site the link takes you to. Knowing how to read a link and spot a trap domain is therefore the number-one protection skill today. Here's how to do it — and how to check any link for free, in seconds, without ever clicking it.

🔍 Suspicious message? Paste it here and check for free
🔒 Your message is only checked, never stored. Phishy collects no personal data.

First: how to read a web address

What matters in a URL is the domain — the part between "//" and the first "/" after it. In https://secure.paypal.com/login, the domain is paypal.com: legitimate. But in https://paypal.secure-verify.com/login, the real domain is secure-verify.com — "paypal" is just a prefix meant to fool you. Scammers bank on the fact that most people only read the start of the address.

5 signs of a dangerous link

• A deliberate typo in the domain: paypa1.com (a 1 instead of the L), amaz0n-support.com, netflix-billing.xyz • A long domain with the brand name as a prefix: post.tracking-secure.xyz • A shortened link (bit.ly, tinyurl, cutt.ly…) in a message that asks for payment or details — the shortener hides the destination • An unusual extension for a known company: .xyz, .top, .icu • http:// without the "s" — an unencrypted connection. But note: the https padlock doesn't guarantee a site is honest, only that the connection is encrypted. Most phishing sites today use https.

Shortened link: don't click "just to see"

Many people click "to see where it goes." That's a mistake: simply visiting a malicious page can be enough to fingerprint your device, show a fake login page tailored to your bank, or trigger a download. Checking must be done from the outside: the Phishy checker follows the shortened link in an isolated environment, on our side, and reveals the final destination — without your phone ever touching it.

Check a link for free in seconds

1. Long-press the message or link → Copy (don't open it!) 2. Paste it into the free Phishy checker on this page 3. In seconds: safe / suspicious / phishing — with the explanation The tool checks the link against global fraud databases (Google Safe Browsing, VirusTotal and others), follows redirects and disguises, and also analyses the message text around the link. No signup, no install.

And links that look perfectly normal?

A careful scammer can register an innocent-looking domain. So always cross-check with context: who sent it? Were you expecting this message? Is there time pressure or a request for payment? Unexpected message + link + urgency = mandatory check. And if the message claims to be from an official body (bank, post office, tax office), go there yourself by typing the official address — never through the link.

Already clicked? Do this

• Entered nothing: close the page. The risk is low in most cases; watch for any odd device behaviour. • Password entered: change it immediately on the real service — and anywhere you used the same one. Turn on two-step verification. • Card entered: block it immediately and dispute the charges with your bank. • File or app downloaded: delete without opening, run a security scan. • Report the site to your national cybercrime portal.

Want Phishy to check every message automatically — for your parents and kids too?
The free app scans your texts and WhatsApp automatically and warns you before you tap. Download now:
App Store — iPhone▶ Google Play — Android

FAQ

Can I check a link without installing software?

Yes: paste the link into the free checker on this page — no signup or install, answer in seconds.

Is a link with the padlock (https) always safe?

No. The padlock means the connection is encrypted, not that the site is honest. Most phishing sites today use a perfectly valid https.

How do I find out where a shortened link goes without opening it?

Paste it into Phishy: the tool follows the shortener in an isolated environment and shows the final destination, plus how dangerous it is.

I clicked a suspicious link but entered nothing — is it serious?

In most cases, no. The real danger comes from entering details or downloading a file. As a precaution, check the link in the tool to learn what you were dealing with.

The link came from someone I know — is it safe?

Not necessarily: hijacked accounts send links to all their contacts. If the link is unexpected or the style is unusual, check it and confirm with the sender through another channel.

Want Phishy to check every message automatically — for your parents and kids too?
The free app scans your texts and WhatsApp automatically and warns you before you tap. Download now:
App Store — iPhone▶ Google Play — Android
More guides:What is smishing (SMS phishing)?Deepfake scams: how to spot AI voice and video fraudThe Facebook romance scam: when a beautiful stranger messages firstKeeping kids safe on Roblox and online gamesHow to protect elderly parents from online scamsHow to protect your kids from online scams"Your parcel is on hold" — the fake customs-fee scamText "from your bank" — how to spot the impersonationSuspicious WhatsApp message — check before you reply"Congratulations, you've won" — the fake-prize scamCrypto and investment scams — the guide