How to Check if a Link Is a Scam Before You Click
link safetyphishingwebsite verificationonline safetyscam checker

How to Check if a Link Is a Scam Before You Click

FFraud.link Editorial Team
2026-08-07
7 min read

Use this practical checklist to inspect suspicious links, spot phishing signs, verify senders safely, and respond after clicking.

A link can look familiar and still lead to a phishing page, a fake login screen, or a payment scam. This reusable checklist shows how to inspect a suspicious URL, verify the sender and destination safely, use scanning tools without treating them as proof, and respond if you already clicked.

Overview

When someone asks, “Is this a scam?”, the link itself is only one part of the answer. A reliable check combines the URL, the message context, the requested action, and the business or person supposedly behind it. Do not let a familiar logo, a polished page, or an HTTPS connection make the decision for you.

The safest default is simple: pause, do not sign in or submit information, and verify the request through a separate trusted channel. If a message claims to be from a bank, marketplace, employer, delivery company, payment service, or colleague, open the organization’s known app or type its established web address yourself. Do not use the contact details supplied in the suspicious message.

This workflow is useful for email, text messages, direct messages, QR codes, invoices, shared documents, and workplace notifications. It also supports an expanded website legitimacy checklist when you need to assess the page itself.

Checklist by scenario

On a computer, hover over a link without clicking to reveal its destination. On a phone, press and hold only if your device displays a preview safely; avoid opening the link simply to inspect it. A text scam, or smishing scam, may use a short message such as a delivery or toll notice to push you toward a payment page. Treat unexpected delivery and toll links as unverified until confirmed independently. See the guide to delivery text scam red flags for a scenario-specific review.

When the URL is shortened or redirected

Shortened links hide the final domain, so they deserve an extra step. Do not assume that a familiar short-link service makes the destination trustworthy. If the message is unexpected, verify the request through the official app or website instead of expanding the link.

Redirects can also pass through several domains before reaching a final page. If you are authorized to investigate the link, use an isolated browser or a reputable URL-scanning service that does not require you to log in. Compare the reported destination with the organization’s genuine domain, but remember that a scanner result is an indicator, not a guarantee.

Business users should be especially cautious with links involving payroll, invoices, supplier banking details, cloud document sharing, or account recovery. A believable display name does not prove that the underlying email account or website is genuine. Use the vendor verification checklist for higher-risk business requests.

When the message involves a bank or payment account

Never use a link in an unexpected “fraud alert” to resolve the alert. Instead, contact the institution through a number printed on a card, a statement, or its known official website. This applies to bank, PayPal, Cash App, Zelle, and other payment impersonation attempts. A legitimate concern can still be handled through a trusted channel. The bank impersonation verification guide provides a separate call, text, and email workflow.

What to double-check

Read the domain from right to left

Focus on the registered domain near the end of the address. In support.example.com, the relevant organization is generally represented by example.com. In example.com.attacker.test, the destination is controlled under attacker.test, not example.com. Attackers may also use lookalike characters, deliberate misspellings, or a brand name placed in a subdomain or URL path.

Be cautious with internationalized domain names and unfamiliar characters that resemble letters. If you cannot confidently identify the organization controlling the domain, stop and verify through another route.

Do not overtrust HTTPS

HTTPS protects the connection between your browser and the site; it does not establish that the site owner is honest. Scam pages can use HTTPS too. Treat the padlock as a transport-security signal, not as a reputation or identity check.

Separate safe inspection from risky interaction

Do not enter credentials, payment details, one-time codes, or personal information while testing a suspicious page. Do not download an unexpected file or allow browser notifications. For workplace investigations, preserve the original message and URL, follow your organization’s security process, and use a sandbox or analysis environment where appropriate. A link scanner may miss a newly created page, a page that changes by location, or a destination that requires a specific session.

Consider the request, not just the page

A real website can still be used in a fraudulent message, and a genuine account can be compromised. Ask what the sender wants you to do and whether that action is normal. Requests to bypass procedure, keep a transaction secret, move a conversation off-platform, or provide a one-time verification code are warning signs even when the link appears clean.

Common mistakes

  • Checking only the logo: Visual design is easy to copy. Confirm the domain and the request through an independent channel.
  • Assuming HTTPS means legitimate: Encryption does not validate ownership, reputation, or intent.
  • Clicking to “see what happens”: A page may trigger downloads, capture credentials, or record a visit. Inspect without interacting where possible.
  • Trusting a search result automatically: Search listings and advertisements can also lead to impersonation pages. Type a known address or use a saved bookmark for important accounts.
  • Relying on one scanner: No scanner can establish permanent safety. Check the context, destination, and requested action as well.
  • Replying to challenge the sender: A reply can confirm that your address or number is active. Report the message through the relevant platform or security process instead.
  • Ignoring a click because no page appeared: Close the tab, avoid entering information, and watch for unusual account activity. If credentials were entered, change them from the known official site and review active sessions.

If you entered payment or identity information, contact the relevant provider promptly through a trusted channel. Secure affected accounts, preserve the message and URL, and document what happened. For broader recovery steps, use the identity theft recovery checklist. Reporting options vary by country and service, so use the platform, financial institution, employer, or local consumer-protection process that applies to the incident.

When to revisit

Keep this checklist available for recurring high-risk moments: seasonal shopping, tax or payroll cycles, major account changes, travel bookings, school or workplace enrollment, and periods when your organization changes vendors or payment procedures. Fraud tactics change, and a safe-looking workflow can become risky when an app, browser, email system, or scanning tool changes.

Review your personal and workplace process whenever:

  • a trusted service changes its domain, login flow, or notification style;
  • your team adopts a new link-scanning, email-security, or browser tool;
  • an incident reveals a gap in domain verification or payment approval;
  • you begin using QR codes, shortened links, shared documents, or new messaging platforms; or
  • a message type becomes common enough that people may start treating it as routine.

Before acting on any unexpected link, run the short version: pause, inspect the full domain, assess the request, verify independently, and avoid entering information until the source is confirmed. If any answer remains uncertain, do not proceed. A delayed transaction is usually easier to resolve than a stolen account or irreversible payment.

Related Topics

#link safety#phishing#website verification#online safety#scam checker
F

Fraud.link Editorial Team

Online Safety Editors

Senior editor and content strategist. Writing about technology, design, and the future of digital media. Follow along for deep dives into the industry's moving parts.