Link Safety Checker: Is This Link Safe to Open?

This link safety checker reads a link you paste and tells you where it really goes, without opening it. It flags the tricks phishing links use: look-alike brand names such as paypa1.com, a real brand name tacked onto someone else’s site, text before an @, bare IP addresses, link shorteners and more.

It gives one of three answers: Looks risky, Be careful or No red flags found. No checker can prove a link is safe, so treat the last one as “no known warning signs”, not as a guarantee.

  1. Copy the link without opening it. On an iPhone or iPad, touch and hold the link to see the address, then choose to copy it. On a computer, hover over the link to see where it goes, then right-click it and copy the link address.
  2. Paste it into Paste the link you want to check.
  3. Select Check link.
  4. Read the verdict, then the list below it. Each point explains one thing the checker noticed, in red for warnings and green for good signs.
  5. Look at Where it really goes. If that isn’t the company the message claims to be from, don’t open the link.

The checker never visits the link. It reads the text of the address in your browser and sends nothing anywhere, so checking a dangerous link is safe.

What each warning means

WarningWhat it meansMade-up example
Looks like a brand but is spelled differentlyLetters swapped for look-alikes: 1 for l, 0 for o, rn for m, or letters from other alphabetspaypa1.com, rnicrosoft.com
Uses a brand name but is a different websiteThe brand is one word in someone else’s namewellsfargo-secure.com
Brand only at the start of the addressThe real site is at the end, just before the first slashpaypal.com.account-check.info belongs to account-check.info
Everything before the @ is ignoredBrowsers treat text before @ as a user name, not the sitehttps://www.paypal.com@203.0.113.9/ goes to 203.0.113.9
Bare number (IP address)No company name at allhttp://192.0.2.10/login
Link shortenerThe real destination is hidden behind a short linkbit.ly/…, tinyurl.com/…
Letters from other alphabetsThe name may copy a real one letter for letter; browsers store it as xn-- codexn--pypal-4ve.com, shown as pаypal.com
Uncommon endingEndings such as .zip, .top or .xyz are cheap and less familiar; check the rest closelydelivery-update.top
Not a web linkjavascript: and data: links run code or show a page from the link itselfjavascript:…

Other notes cover http (unencrypted) links, unusual port numbers such as :8443, very long links and long chains of sub-names before the real one. None of these proves a scam on its own. Together, they are a strong hint.

Seeing https is not a safety sign by itself. It means the connection is encrypted, and scam sites use it too. The part that matters is the site name just before the first single slash.

  • Did you expect this message? Surprise prizes, refunds, package problems and account alerts are classic lures, according to the FTC.
  • Does the real site name match the company? Apple warns about links that look right but don’t match the company’s website.
  • Does the sender match? Gmail Help suggests checking that the sender’s name and email address go together.
  • Is the message rushing you? Pressure to act right now is a warning sign in its own right.
  • Is it asking for a password, card number or code? Real companies don’t ask for those through a link in a text.
  • Still unsure? Skip the link. Open the company’s app, or type its address yourself.

Scam text examples

The FTC lists the kinds of text scammers send: fake prizes, gift cards and coupons, fake account alerts about “suspicious activity”, fake package delivery notices, and offers of cheap credit or student loan help that never arrives. Here is what they tend to look like. The links are made up, and broken on purpose so they can’t be opened:

  • “Your package is on hold due to an incomplete address. Update it within 12 hours: usps-redelivery[.]top/track” — USPS is not the site name here, and the ending is unusual.
  • “Unusual sign-in detected on your account. Verify now: amaz0n-security[.]com” — a zero in place of the letter o.
  • “You have a pending tax refund. Claim it here: irs.gov.refund-claim[.]info” — the real site is refund-claim.info.
  • “Congratulations! You won a gift card. Tap to claim: bit[.]ly/…” — a shortener hides where it goes.

Our guide to stopping spam texts shows how to filter these out on iPhone and Android, and holiday shopping scams covers fake deals and delivery notices.

Opening a link is not always the end of the world. What you did next matters more:

  1. Close the page. Don’t type anything else into it, and don’t contact anyone through it.
  2. If you entered a password, change it now on the real site or app, and anywhere else you use it. A password generator helps you pick a strong new one, and passkeys stop this trick working next time.
  3. If you shared a card or bank number, call the number on the back of your card. If you shared your Social Security number or bank details, the FTC points you to IdentityTheft.gov for step-by-step recovery.
  4. If you downloaded something or the link tried to install an app, the FTC says to update your security software, run a scan and remove what it finds.
  5. Watch your card and bank statements for charges you don’t recognize.
  6. If your phone acts strangely afterwards, work through our guide on how to tell if your phone is hacked.
  • Any scam: report it to the FTC at ReportFraud.ftc.gov.
  • Scam texts: forward the message to 7726 (SPAM) so your carrier can block similar ones, and use your messaging app’s report junk option.
  • Scam emails: forward them to reportphishing@apwg.org. In Gmail, open the message, click More next to Reply, then Report phishing.
  • Messages pretending to be Apple: Apple asks you to forward them to reportphishing@apple.com.
  • The website itself: report it to Google Safe Browsing at its phishing report page. You can also look up a site’s status in Google’s Safe Browsing site status tool. It only knows about sites Google has already found, so a clean result is not proof either.

If it doesn’t work

  • “That does not look like a link”: you may have copied part of the message, or the link was split across lines. Copy it again, from the first letter to the last.
  • iPhone or iPad: Apple says to touch and hold a link to preview its address. Copy it from there instead of tapping it.
  • Android or Galaxy: touch and hold the link in Messages or your email app to copy it.
  • Windows 11 or Mac: Gmail Help suggests hovering over a link to see where it goes. Right-click it to copy the address.
  • A QR code: when your camera shows the link, don’t tap it. Check the address shown on screen first, or type it into the checker. QR codes in unexpected places are a common scam, so treat them like any other link.

What this checker can’t tell you

The checker reads the address only. It can’t see the page, so it can’t spot a scam hosted on a real site, such as a fake form on a free website builder, a shared document, or a hacked small business site. It also can’t see behind a shortener, and its brand list is short. A clean result means none of the common warning signs are in the address. It doesn’t mean the page is safe.

Privacy: the link is checked by a script in your browser. Nothing is sent to Being Tricky, to the link’s site or to anyone else, and we only count, anonymously, that the tool was used. More guides are on the security hub and the messaging hub.

Related free tool: our QR code generator.

FAQ

Can a link safety checker prove a link is safe?

No. It can spot warning signs in the address, but it can’t see the page itself. Only open links you expected, from people you know.

Is it safe to paste a suspicious link here?

Yes. The checker never opens the link. It reads the text in your browser and sends nothing anywhere.

Why is a link with https still flagged?

Https only means the connection is encrypted. Scam sites use it too, so the checker looks at the site name instead.

How do I see where a short link goes?

Ask the sender for the full address, or use the link shortener’s own preview or a link expander. Then paste the full address here.

I clicked a phishing link. What now?

Close the page. If you typed a password, change it on the real site. If you shared card or bank details, call your bank. Report the message at ReportFraud.ftc.gov.

Sources