Before opening an unfamiliar link, use this practical scam website checker checklist to inspect the address, sender, redirects, page behavior, and verification options. These steps help you decide whether a link is safe to investigate, should be independently verified, or should be avoided and reported.
Overview
A suspicious link can arrive in an email, text message, social media post, online marketplace conversation, invoice, calendar invitation, or support chat. It may imitate a bank, delivery company, employer, retailer, payment service, or colleague. The visible message may look familiar while the destination quietly leads somewhere else.
When asking, “Is this a scam link?”, do not rely on one signal. A professional design does not prove legitimacy, and a spelling error does not prove fraud. Instead, combine several checks:
- Read the complete destination rather than trusting the link’s display text.
- Consider whether the message and request fit the sender’s normal behavior.
- Check for lookalike domains, unusual subdomains, and shortened URLs.
- Use a known, independent route to verify the claim.
- Stop if the page requests credentials, payment, security codes, or unnecessary personal data.
A link can be technically functional and still be unsafe. It can also point to a legitimate website that has been compromised or a real service being used in a misleading message. Treat the link, the message, and the requested action as separate parts of the investigation.
Checklist by scenario
Before opening a link in an email or text
- Pause before responding. Urgency, threats, unexpected refunds, account warnings, delivery problems, and limited-time offers are common pressure tactics. Do not let the message dictate your verification method.
- Inspect the actual URL. On a computer, hover over the link without clicking. On a phone, press and hold if your device shows a preview. Expand the message details where possible and examine the full address.
- Find the registered-looking domain. In
secure.example.com.account-check.example.net, the meaningful domain is generallyexample.net, not the familiar-looking words at the beginning. Be cautious with extra words, unusual spellings, added hyphens, and unfamiliar domain endings. - Compare it with a known address. Open a saved bookmark or type the organization’s address yourself. Do not use contact details or links supplied in the suspicious message to perform the check.
- Check the sender separately. A familiar display name can hide a different email address or phone number. For business messages, confirm unusual requests through a previously known channel.
For bank-related messages, use the verification approach in Bank Impersonation Scams: How to Verify Calls, Texts, and Emails Claiming Fraud. Delivery notices deserve similar caution; see Delivery Text Scams: Current Red Flags, Examples, and Safe Response Steps.
When the URL is shortened or redirected
Shortened links hide the final destination, so treat them as unverified. If you must investigate one, use a reputable URL-expansion or link-analysis tool, and avoid entering credentials or downloading anything during the process. A redirect chain can pass through several domains before reaching the visible page. Review the final destination and any intermediate domains when a tool makes that information available.
Do not submit private, one-time, password-reset, invitation, or internal company URLs to a public scanner. These addresses may contain tokens that grant access or reveal confidential information. For workplace investigations, use security tools approved by your organization.
When a page opens
- Check whether the address changed after loading.
- Look for a domain mismatch between the page’s branding and its URL.
- Be cautious if the page immediately requests a password, payment card, bank details, authentication code, or identity document.
- Do not install a browser extension, mobile application, remote-access tool, or “security update” because a page tells you to.
- Use browser warnings as a reason to stop, but do not treat the absence of a warning as proof that the site is safe.
For a broader page-level review, use the 12-Point Website Legitimacy Checklist.
When the link appears in a marketplace, social post, or support conversation
Keep communication and payment inside the platform where possible. Be especially careful when a buyer, seller, or supposed support agent sends a link to “release” funds, confirm identity, resolve a dispute, or unlock an account. Navigate to the service through its official app or a bookmark instead. A genuine transaction should not require you to bypass normal protections simply because the other person is creating urgency.
What to double-check
HTTPS is not a legitimacy certificate
The padlock or https:// indicates that the connection is encrypted in transit. It does not tell you who operates the site, whether the business is honest, or whether the page is a convincing phishing copy. Look at the domain, the request being made, and the way you reached the page.
Lookalike domains and subdomains
Scammers may use misspellings, substituted characters, extra words, or domains that place a trusted brand name before an unrelated registered domain. For example, a domain ending in example-support.com is not automatically controlled by example.com. Internationalized characters can also make a domain appear similar to a familiar one. If the address is difficult to interpret, leave the page and navigate independently.
Message context and timing
Ask what the sender wants you to do and why the link is necessary. A surprise request to change payment details, review an invoice, approve a login, or provide a verification code deserves a second channel check. Businesses should apply extra verification to supplier changes, wire instructions, payroll requests, and executive messages because a plausible link may support a broader business email compromise attempt.
Tools and browser signals
A suspicious link checker, reputation service, sandbox, or browser warning can provide useful evidence, but no single tool can identify every new or carefully targeted phishing scam. Use multiple signals and follow your organization’s security process. If the URL contains confidential information, analyze it privately or ask a security team for help.
Common mistakes
- Trusting the logo or writing style: branding and polished copy can be copied or generated quickly.
- Checking only the first part of the address: the registered-looking domain is more important than a familiar word in a subdomain or path.
- Assuming HTTPS means safe: encryption protects the connection, not the user’s decision.
- Calling the number in the message: use a number from a statement, official app, contract, or independently located website.
- Testing the link with real credentials: never “see what happens” by entering a password or authentication code.
- Forwarding a suspicious link without warning: label it clearly and avoid clicking it again; use your mail provider’s reporting function or your organization’s incident channel.
If you clicked a suspicious link, close the page and do not download files or provide additional information. If you entered a password, change it from the official site using a clean, trusted route and review other sessions where available. If payment or identity information was submitted, contact the relevant provider through verified contact details and document what happened. The Identity Theft Recovery Checklist can help organize next steps when personal information may be exposed.
When to revisit
Revisit this checklist whenever your organization changes email, browser, identity, payment, or collaboration tools; when a vendor changes domains; or when a new message pattern begins circulating. Security teams should refresh approved verification routes, reporting instructions, and internal escalation contacts before seasonal planning cycles, major promotions, tax or payroll periods, and other times when transaction volume increases.
Keep a short, printable version near the workflow where links are reviewed:
- Stop. What is the message asking me to do?
- Inspect the full URL, including the final domain and redirects.
- Compare the address and sender with an independently known source.
- Do not enter credentials, codes, payment details, or personal data on an unverified page.
- Open the service through its official app, bookmark, or manually typed address.
- Report the message and preserve relevant details if it appears fraudulent.
When the evidence is mixed, do not click just to settle the question. Treat uncertainty as a reason to verify through another channel. That habit is one of the most reliable forms of everyday online fraud prevention.