How to Check If a Link Is Safe Before You Click (2026) — EmailLeaked
Guides

How to Check If a Link Is Safe Before You Click (2026)

Check if a link is safe before you open it. Copy the real URL, look it up on threat lists, and avoid the fake buttons in emails and texts. Updated August 2026.

On this page

To check if a link is safe, reveal the full URL first — hover on a computer or long-press on a phone — then paste that address into a threat-list checker instead of tapping the button. If the hidden domain does not match the brand in the message, delete it. Last updated: August 2026.

The dangerous part of a scam email is usually not the story. It is the button. Display text says “Reset your password.” The real destination is a lookalike domain. Checking the link means checking that hidden address, not the logo.

FBI Internet Crime Complaint Center reports have listed phishing among the top complaint types for years, with losses in the billions of dollars as of the mid-2020s. As of 2026, more than 12 billion stolen credentials are also sitting in known breach data, which is how those messages get your name and inbox right.

On a computer: hover until the destination appears, usually in the bottom-left of the browser or in a tooltip. Right-click and copy the link address if you want to paste it somewhere else.

On a phone: long-press the link. Most mail and messaging apps show the full URL before you open it. If they do not, do not tap. Type the company domain yourself or wait until you are at a computer.

In SMS: the whole visible string is often the URL. Copy it. Do not tap. Scam texts use shortened domains and official-looking “delivery” or “bank” wording.

Then paste the copied address into the website and link checker.

What should you look for in the real URL?

Read the domain — the part just before the first path slash, after https://.

  • The brand should be the domain, not a folder: paypal.com/... is not the same as secure-login.com/paypal.
  • Extra words and hyphens are a common trick.
  • A different ending (.xyz, .top, .ru on a “US bank” page) is a stop sign unless you already know that company uses it.
  • @ in a URL can hide the real host. If you see it, do not click.

If the preview does not match the sender’s claimed brand, you do not need a second opinion. Delete it.

HTML emails can show any text on a button. Attackers copy the real company’s layout. They cannot copy the real domain without already controlling it.

That is why “it looks like my bank” is not a check. The link is the check. For the message around the link, use how to check if an email is a scam.

Copy the URL, don’t tap it: Check the link on EmailLeaked →

URL shorteners collapse the destination into a code. Honest newsletters use them. So do phishing kits. Expand or preview until you see the final domain. If you cannot, do not authenticate through that hop.

Messages from people you know are not automatically safe. After a breach or a hacked inbox, attackers send links to the contact list. Confirm odd requests on a phone call you placed, not on a callback number in the message.

If a friend might have been compromised, they should check whether their email was in a known breach and change leaked passwords.

What should you do if you already clicked?

  1. Close the tab. Do not explore the page.
  2. If you typed a password, change it on the real site from a bookmark. Make it unique. Use the password reuse change checklist if that login appeared elsewhere.
  3. Turn on two-factor authentication — or follow 2FA and passkeys after a breach if a leak started this.
  4. Check the password and check the email.
  5. If you downloaded a file, do not open it. Delete it. If you ran it, treat the device as untrusted until you can get it checked.

Do not call the number on the page. Do not pay a “fine” or “unlock fee.” For the full cleanup list, use what to do after a data breach.

When you started the visit: you typed the domain, used a bookmark, or opened an app you installed on purpose.

When a message created the visit, check the destination first. Even a clean website check is only one signal. Combine it with domain spelling and the rule that real companies let you log in from their homepage without a countdown.

Historical breaches of real companies — for example Adobe — do not make today’s official homepage a trap. They do mean old passwords from that era should not be reused anywhere. That is a password problem, not a “never click Adobe again” problem.

Frequently asked questions

How do I check if a link is safe before I click it?
Do not tap the button. Hover or long-press to reveal the full destination, copy that URL, and paste it into a link checker. If the hidden address does not match the brand in the message, delete the email. A shortened link should be expanded the same way — check the final destination, not the short code.
Is it safer to click a link on my phone or my computer?
Neither is automatically safer. Phones hide the real URL behind a button more often. Long-press the link to preview it. On a computer, hover until the destination shows in the corner or status bar. Then paste that address into a checker instead of opening it.
What if I already clicked a bad link?
Close the tab. Do not type passwords or card details on that page. If you already submitted a login, change that password on the real site from a bookmark, turn on two-factor authentication, and check whether the password or your email appeared in a known leak.
Are shortened links like bit.ly always scams?
No. Shorteners hide the destination, which is why scammers like them and why honest senders still use them. Treat every short link as unknown until you preview or expand it. If you cannot see the final domain, do not log in through it.
Can I trust links from people I know?
Only after you check the destination. Hacked accounts send malware and phishing to contacts. If a friend messages you a surprise login page or a file you did not ask for, check the URL and ask them on another channel before you click.
Does checking a link visit the website?
A proper lookup should not load the page as you, run its scripts, or download its files. It should only ask threat lists whether that address is already flagged. That is what our website checker does. Brand-new scams can still be missing from those lists.

Founder and editor of EmailLeaked. A software and web developer, he built the site's breach checker and its no-storage privacy model, and writes its plain-English guides for people who need a straight answer about a leak — not a data dump. LinkedIn

Our editorial standards →
Breach education

Read the data breach guide

Learn how breaches happen, how stolen data is used, and how to check your exposure.

Open the hub

Get monthly breach alerts — free

One email per month. Biggest breaches, what was exposed, what to do. No spam.

No spam · Unsubscribe anytime · Your email is never shared

Find out where you stand.

Check which breaches include your email — free, instant, never stored.

Check my email — free
No signup · Under 2 seconds · Never stored