Is This URL Safe? The 30-Second Routine That Catches Most Phishing Links

Is this URL safe? How to check any link before you click

HTTPS doesn't mean safe. It means the criminal encrypted your connection to his fake bank.

That's the thing most people learn after the click — not before. And phishing attacks are built almost entirely around that gap.

Here's how to close it.


The email looked like it came from her bank. The logo was right, the formatting was right, and when she hovered over the link, the address started with "https." She'd been told to look for that. So she clicked.

Three days later she was on hold with fraud prevention, explaining that she hadn't given her password to anyone. She had typed it herself — into a page that looked exactly like her bank's login screen, sitting behind an HTTPS address that Chrome had given a padlock.

The padlock didn't mean the site was safe. It meant the connection was encrypted. And that misread is what most phishing attempts are built on.


HTTPS is not a trust signal

This was half-true for a while. Years ago, HTTPS certificates were expensive and difficult to set up, so scammers mostly didn't bother. That stopped being true around 2018. Anyone can get one now, for free, in minutes — including people running fake bank login pages.

The padlock icon tells you your data is encrypted in transit. It says nothing about who's on the other end of the connection. Phishing sites use HTTPS routinely. Treat it as a baseline, not a verdict.


Five things that actually matter

1. The domain — not the whole URL

URLs can be long and complicated. What matters is the domain: the part right before the first single slash.

In `https://login.paypal.com.phishing-site.com/verify`, the domain is `phishing-site.com`. Not `paypal.com`. The paypal.com here is a subdomain of a different site entirely. Scammers use this structure because people read the beginning and end of URLs, not the middle.

Before clicking: find the domain. Ask yourself whether that's actually a site you trust.

2. The one-letter trap

`paypa1.com`. `arnazon.com`. `bankofamerica-login.com`.

Scammers register domains that look like real ones and count on you reading fast. A `1` instead of an `l`. A hyphen and the word "login" appended. An extra character buried in the middle.

Don't ask yourself if it "looks right." Spell it out, character by character, and check whether it's exactly right.

3. Shortened URLs hide the destination

`bit.ly/3aF9xQ` tells you nothing — which is the point.

Link shorteners are legitimate for social media. They're also a clean way to conceal where a link actually goes. Before clicking a shortened URL, expand it: paste it into unshorten.it, or hover over it in most email clients to see the real destination. If you don't recognize the domain it resolves to, treat it as unknown.

4. New domains are riskier

Scammers register domains fast and abandon them after use. A domain registered two weeks ago carries more risk than one that has been around for five years. A free WHOIS lookup shows you the registration date for any domain. It is not a definitive signal — new legitimate businesses exist — but a new domain paired with anything else on this list is worth stopping for.

5. What the URL is asking you to do

The most important check is not technical. It is: what does this page want from me?

Legitimate sites rarely ask you to log in via a link in an unexpected email. They don't ask you to confirm your payment details out of nowhere or verify your account under time pressure. A clean URL and a convincing-looking page don't change what the request is. The request itself is usually the clearest tell.


The 30-second routine

When a link arrives — in email, text, or social media — run through this before clicking:

1. Who sent this, and was I expecting it?

2. What is the actual domain? Read it character by character.

3. Is that a site I know and trust, or one I've never heard of?

4. If it's shortened, where does it actually go?

5. What is this page going to ask me to do when I get there?

If anything stops you at any step: don't click. Navigate directly to the site by typing it into a new browser tab yourself.


Three links, graded

3 / 10 — LOW: `https://newsletter.nike.com/spring-sale`

Domain is `nike.com`. Newsletter subdomain is standard for marketing email. No typos, no suspicious structure, no unusual ask. Consistent with how a brand sends promotional mail.

6 / 10 — CAUTION: `https://secure-paypal-verification.com/login`

"Secure" and "verification" sound reassuring. HTTPS is present. But the domain is `secure-paypal-verification.com` — not `paypal.com`. PayPal doesn't send login links from third-party domains. This warrants a full stop.

9 / 10 — HIGH RISK: `https://paypa1.com/account/confirm`

The `1` in `paypa1.com` is easy to miss at speed. HTTPS is present, the path looks routine. But the domain is wrong — and one-character substitution attacks are among the most effective phishing patterns running right now precisely because the error is so small.


If you've already clicked

Clicking a bad link doesn't automatically mean damage has been done. What matters is what happened next.

Landed on a page and closed it without entering anything — you're probably fine. Don't change anything.

Entered a password — change it immediately, and change it everywhere you used the same one. Start with your email account; email access is usually the key to everything else.

Entered payment details — call your bank or card issuer now and report a potential compromise. Most issue a new card number within a day.


When you need a fast answer

The routine above works when you have a moment. Phishing links tend to arrive when you don't — when you're busy, distracted, or being pushed to act quickly.

That's what Scamanot's URL Safety Investigator is for. Paste the link, get a verdict before you click anything.

Investigate Any URL — Free →

If the link arrived in a text message, run the message itself through the Scam Text Investigator — it covers the full context, not just the URL.


Common questions

Is it safe to hover over a link without clicking it?

Yes. Hovering reveals the destination in your browser's status bar without loading the page. It's one of the best free checks you have.

Does a padlock icon mean a site is safe?

No. It means the connection is encrypted. The padlock tells you nothing about who's running the site. Phishing sites use it routinely.

What if the URL looks fine but something about the email feels off?

Trust the feeling. Phishing detection is pattern recognition, and you're often picking up on something real. Navigate directly to the site rather than clicking the link.

Can I get infected just by hovering over a link?

In theory, unpatched browser vulnerabilities can trigger on hover. In practice, modern updated browsers have this risk extremely low. Standard hovering to check a destination is safe.


Up to 50 investigations a day. For everyone you protect.

Get Guardian — $9/mo →


Use the tools mentioned in this article: URL Safety Investigator · Scam Text Investigator · Phone Number Investigator

Not sure if a link is safe? Run it through Scamanot — free, no account required.

Investigate Something Now

Not sure if something is a scam? Run it through Scamanot — free investigations available, no account required.

Investigate Something Now