To check if a link is safe, reveal the full URL first — hover on a computer or long-press on a phone — then paste that address into a threat-list checker instead of tapping the button. If the hidden domain does not match the brand in the message, delete it. Last updated: August 2026.
The dangerous part of a scam email is usually not the story. It is the button. Display text says “Reset your password.” The real destination is a lookalike domain. Checking the link means checking that hidden address, not the logo.
FBI Internet Crime Complaint Center reports have listed phishing among the top complaint types for years, with losses in the billions of dollars as of the mid-2020s. As of 2026, more than 12 billion stolen credentials are also sitting in known breach data, which is how those messages get your name and inbox right.
How do you preview a link without opening it?
On a computer: hover until the destination appears, usually in the bottom-left of the browser or in a tooltip. Right-click and copy the link address if you want to paste it somewhere else.
On a phone: long-press the link. Most mail and messaging apps show the full URL before you open it. If they do not, do not tap. Type the company domain yourself or wait until you are at a computer.
In SMS: the whole visible string is often the URL. Copy it. Do not tap. Scam texts use shortened domains and official-looking “delivery” or “bank” wording.
Then paste the copied address into the website and link checker.
What should you look for in the real URL?
Read the domain — the part just before the first path slash, after https://.
- The brand should be the domain, not a folder:
paypal.com/...is not the same assecure-login.com/paypal. - Extra words and hyphens are a common trick.
- A different ending (
.xyz,.top,.ruon a “US bank” page) is a stop sign unless you already know that company uses it. @in a URL can hide the real host. If you see it, do not click.
If the preview does not match the sender’s claimed brand, you do not need a second opinion. Delete it.
Why do email buttons hide unsafe links?
HTML emails can show any text on a button. Attackers copy the real company’s layout. They cannot copy the real domain without already controlling it.
That is why “it looks like my bank” is not a check. The link is the check. For the message around the link, use how to check if an email is a scam.
Copy the URL, don’t tap it: Check the link on EmailLeaked →
What if the link is shortened or comes from a friend?
URL shorteners collapse the destination into a code. Honest newsletters use them. So do phishing kits. Expand or preview until you see the final domain. If you cannot, do not authenticate through that hop.
Messages from people you know are not automatically safe. After a breach or a hacked inbox, attackers send links to the contact list. Confirm odd requests on a phone call you placed, not on a callback number in the message.
If a friend might have been compromised, they should check whether their email was in a known breach and change leaked passwords.
What should you do if you already clicked?
- Close the tab. Do not explore the page.
- If you typed a password, change it on the real site from a bookmark. Make it unique. Use the password reuse change checklist if that login appeared elsewhere.
- Turn on two-factor authentication — or follow 2FA and passkeys after a breach if a leak started this.
- Check the password and check the email.
- If you downloaded a file, do not open it. Delete it. If you ran it, treat the device as untrusted until you can get it checked.
Do not call the number on the page. Do not pay a “fine” or “unlock fee.” For the full cleanup list, use what to do after a data breach.
When is it safe to click a link?
When you started the visit: you typed the domain, used a bookmark, or opened an app you installed on purpose.
When a message created the visit, check the destination first. Even a clean website check is only one signal. Combine it with domain spelling and the rule that real companies let you log in from their homepage without a countdown.
Historical breaches of real companies — for example Adobe — do not make today’s official homepage a trap. They do mean old passwords from that era should not be reused anywhere. That is a password problem, not a “never click Adobe again” problem.