Runs in your browser: nothing you enter or choose is uploaded.
This link safety checker reads a link you paste and tells you where it really goes, without opening it. It flags the tricks phishing links use: look-alike brand names such as paypa1.com, a real brand name tacked onto someone else’s site, text before an @, bare IP addresses, link shorteners and more.
It gives one of three answers: Looks risky, Be careful or No red flags found. No checker can prove a link is safe, so treat the last one as “no known warning signs”, not as a guarantee.
How to use the link safety checker
- Copy the link without opening it. On an iPhone or iPad, touch and hold the link to see the address, then choose to copy it. On a computer, hover over the link to see where it goes, then right-click it and copy the link address.
- Paste it into Paste the link you want to check.
- Select Check link.
- Read the verdict, then the list below it. Each point explains one thing the checker noticed, in red for warnings and green for good signs.
- Look at Where it really goes. If that isn’t the company the message claims to be from, don’t open the link.
The checker never visits the link. It reads the text of the address in your browser and sends nothing anywhere, so checking a dangerous link is safe.
What each warning means
| Warning | What it means | Made-up example |
|---|---|---|
| Looks like a brand but is spelled differently | Letters swapped for look-alikes: 1 for l, 0 for o, rn for m, or letters from other alphabets | paypa1.com, rnicrosoft.com |
| Uses a brand name but is a different website | The brand is one word in someone else’s name | wellsfargo-secure.com |
| Brand only at the start of the address | The real site is at the end, just before the first slash | paypal.com.account-check.info belongs to account-check.info |
| Everything before the @ is ignored | Browsers treat text before @ as a user name, not the site | https://www.paypal.com@203.0.113.9/ goes to 203.0.113.9 |
| Bare number (IP address) | No company name at all | http://192.0.2.10/login |
| Link shortener | The real destination is hidden behind a short link | bit.ly/…, tinyurl.com/… |
| Letters from other alphabets | The name may copy a real one letter for letter; browsers store it as xn-- code | xn--pypal-4ve.com, shown as pаypal.com |
| Uncommon ending | Endings such as .zip, .top or .xyz are cheap and less familiar; check the rest closely | delivery-update.top |
| Not a web link | javascript: and data: links run code or show a page from the link itself | javascript:… |
Other notes cover http (unencrypted) links, unusual port numbers such as :8443, very long links and long chains of sub-names before the real one. None of these proves a scam on its own. Together, they are a strong hint.
Seeing https is not a safety sign by itself. It means the connection is encrypted, and scam sites use it too. The part that matters is the site name just before the first single slash.
How to check if a link is safe before you click
- Did you expect this message? Surprise prizes, refunds, package problems and account alerts are classic lures, according to the FTC.
- Does the real site name match the company? Apple warns about links that look right but don’t match the company’s website.
- Does the sender match? Gmail Help suggests checking that the sender’s name and email address go together.
- Is the message rushing you? Pressure to act right now is a warning sign in its own right.
- Is it asking for a password, card number or code? Real companies don’t ask for those through a link in a text.
- Still unsure? Skip the link. Open the company’s app, or type its address yourself.
Scam text examples
The FTC lists the kinds of text scammers send: fake prizes, gift cards and coupons, fake account alerts about “suspicious activity”, fake package delivery notices, and offers of cheap credit or student loan help that never arrives. Here is what they tend to look like. The links are made up, and broken on purpose so they can’t be opened:
- “Your package is on hold due to an incomplete address. Update it within 12 hours:
usps-redelivery[.]top/track” — USPS is not the site name here, and the ending is unusual. - “Unusual sign-in detected on your account. Verify now:
amaz0n-security[.]com” — a zero in place of the letter o. - “You have a pending tax refund. Claim it here:
irs.gov.refund-claim[.]info” — the real site is refund-claim.info. - “Congratulations! You won a gift card. Tap to claim:
bit[.]ly/…” — a shortener hides where it goes.
Our guide to stopping spam texts shows how to filter these out on iPhone and Android, and holiday shopping scams covers fake deals and delivery notices.
What to do if you clicked a link
Opening a link is not always the end of the world. What you did next matters more:
- Close the page. Don’t type anything else into it, and don’t contact anyone through it.
- If you entered a password, change it now on the real site or app, and anywhere else you use it. A password generator helps you pick a strong new one, and passkeys stop this trick working next time.
- If you shared a card or bank number, call the number on the back of your card. If you shared your Social Security number or bank details, the FTC points you to IdentityTheft.gov for step-by-step recovery.
- If you downloaded something or the link tried to install an app, the FTC says to update your security software, run a scan and remove what it finds.
- Watch your card and bank statements for charges you don’t recognize.
- If your phone acts strangely afterwards, work through our guide on how to tell if your phone is hacked.
How to report a phishing link
- Any scam: report it to the FTC at ReportFraud.ftc.gov.
- Scam texts: forward the message to 7726 (SPAM) so your carrier can block similar ones, and use your messaging app’s report junk option.
- Scam emails: forward them to
reportphishing@apwg.org. In Gmail, open the message, click More next to Reply, then Report phishing. - Messages pretending to be Apple: Apple asks you to forward them to
reportphishing@apple.com. - The website itself: report it to Google Safe Browsing at its phishing report page. You can also look up a site’s status in Google’s Safe Browsing site status tool. It only knows about sites Google has already found, so a clean result is not proof either.
If it doesn’t work
- “That does not look like a link”: you may have copied part of the message, or the link was split across lines. Copy it again, from the first letter to the last.
- iPhone or iPad: Apple says to touch and hold a link to preview its address. Copy it from there instead of tapping it.
- Android or Galaxy: touch and hold the link in Messages or your email app to copy it.
- Windows 11 or Mac: Gmail Help suggests hovering over a link to see where it goes. Right-click it to copy the address.
- A QR code: when your camera shows the link, don’t tap it. Check the address shown on screen first, or type it into the checker. QR codes in unexpected places are a common scam, so treat them like any other link.
What this checker can’t tell you
The checker reads the address only. It can’t see the page, so it can’t spot a scam hosted on a real site, such as a fake form on a free website builder, a shared document, or a hacked small business site. It also can’t see behind a shortener, and its brand list is short. A clean result means none of the common warning signs are in the address. It doesn’t mean the page is safe.
Privacy: the link is checked by a script in your browser. Nothing is sent to Being Tricky, to the link’s site or to anyone else, and we only count, anonymously, that the tool was used. More guides are on the security hub and the messaging hub.
Related free tool: our QR code generator.
FAQ
Can a link safety checker prove a link is safe?
No. It can spot warning signs in the address, but it can’t see the page itself. Only open links you expected, from people you know.
Is it safe to paste a suspicious link here?
Yes. The checker never opens the link. It reads the text in your browser and sends nothing anywhere.
Why is a link with https still flagged?
Https only means the connection is encrypted. Scam sites use it too, so the checker looks at the site name instead.
How do I see where a short link goes?
Ask the sender for the full address, or use the link shortener’s own preview or a link expander. Then paste the full address here.
I clicked a phishing link. What now?
Close the page. If you typed a password, change it on the real site. If you shared card or bank details, call your bank. Report the message at ReportFraud.ftc.gov.
Sources
- How to recognize and avoid phishing scams — FTC Consumer Advice
- How to recognize and report spam text messages — FTC Consumer Advice
- Recognize and avoid social engineering schemes including phishing messages — Apple Support
- Avoid and report phishing emails — Gmail Help
- Google Safe Browsing
- URL: hostname property (internationalized names) — MDN Web Docs
