Learn how phishing URLs work, what warning signs to look for, and how to verify whether any link is safe before clicking it — including free tools to check any URL instantly.
You click a link in an email, or see a shortened URL shared on social media, and immediately wonder — is this safe? Malicious URLs are one of the most common vectors for phishing attacks, malware distribution, and credential theft. Knowing how to identify and check suspicious URLs before you click them is a fundamental online safety skill.
This guide explains how URL-based attacks work, what the warning signs look like, and how to verify whether any link is safe before you open it.
How URL-Based Attacks Work
Phishing
Phishing uses deceptive URLs to trick users into visiting fake versions of legitimate websites. The goal is usually to steal login credentials, financial information, or personal data. A phishing URL might look like paypa1.com (with the letter "l" replaced by the number "1") or secure-login.paypal.account-verify.com — where the actual domain is account-verify.com, not PayPal.
Malware Distribution
Malicious URLs link directly to files that install malware when downloaded, or to websites that exploit browser vulnerabilities to silently install software. These URLs are often disguised as software downloads, invoice PDFs, or media files.
URL Redirection Chains
Attackers use redirect chains to disguise the final destination. A link might look safe initially but redirect through multiple URLs before landing on a malicious site — making it harder to spot from the link alone.
Homograph Attacks
These attacks use Unicode characters that look identical to standard Latin letters. For example, the Cyrillic letter "а" looks identical to the Latin "a" but is a different character — allowing attackers to register domains that appear identical to legitimate ones in most fonts.
Red Flags in a URL
Before clicking any link, inspect these elements carefully:
The Domain Name
The real domain is the part immediately before the first single slash after https://. In https://paypal.secure-login.com/verify, the domain is secure-login.com — not PayPal. Attackers frequently add legitimate brand names as subdomains or in the URL path to create confusion.
Watch for:
- Brand names appearing as subdomains (
paypal.attacker.com) - Brand names appearing in the path (
attacker.com/paypal/login) - Numbers substituted for letters (
g00gle.com,paypa1.com) - Extra words added to a real domain (
amazon-secure.com,netflix-help.com) - Wrong top-level domain (
amazon.netinstead ofamazon.com) - Hyphens splitting a real domain (
face-book.com)
The Protocol
Legitimate sites use https:// (with the padlock). However, HTTPS alone does not guarantee safety — phishing sites can and do obtain SSL certificates. Never trust a site solely because it shows a padlock.
URL Length and Complexity
Extremely long, complex URLs with many parameters and random characters are sometimes used to obscure malicious destinations. Shortened URLs (bit.ly, t.co, etc.) hide the destination entirely until clicked — though most legitimate services use them too.
Suspicious File Extensions
URLs ending in .exe, .bat, .js, .vbs, .zip, or .iso that you weren't expecting should be treated with extreme caution. Attackers also disguise executable files with double extensions like invoice.pdf.exe.
How to Check if a URL Is Safe
Hover Before You Click
On desktop browsers, hovering over a link shows the actual destination URL in the bottom left of the browser window. Always check this before clicking links in emails, social media, or unfamiliar websites. If the displayed text shows one URL but the actual destination is different, that's a serious red flag.
Use a Safe URL Checker
A safe URL checker queries Google's Safe Browsing database and other threat intelligence sources to determine whether a URL has been flagged as malicious, phishing, or malware-distributing. Simply paste any URL to get an instant safety verdict.
This is especially useful for:
- Checking shortened URLs before following them
- Verifying links received in emails from unknown senders
- Checking links shared in messaging apps or social media
- Verifying download links for software or files
- Auditing links on your own website to ensure none have been compromised
Expand Shortened URLs
Before clicking a shortened URL (bit.ly, t.co, short.io, etc.), use a URL expander to see the full destination URL first. Many shortened URL services also offer preview pages — add a + at the end of a bit.ly link (e.g., bit.ly/example+) to see where it goes without visiting it.
Check the Domain Age
Phishing sites are often registered hours or days before an attack campaign. If a Whois lookup shows a domain was registered last week, be very suspicious — especially if it's claiming to be a major bank, retailer, or service provider. Legitimate company websites are almost never newly registered domains.
Search for the URL Independently
If you receive a link claiming to be from your bank or a service you use, don't click it. Instead, open a new browser tab and navigate to the site directly by typing the address yourself, or search for it in Google. Contact the company through their official channels if you're unsure about a communication.
Protecting Yourself from Malicious URLs
Keep Your Browser Updated
Modern browsers (Chrome, Firefox, Edge, Safari) have built-in Safe Browsing technology that warns you before visiting known malicious sites. These protections only work when your browser is up to date.
Enable Two-Factor Authentication
Even if a phishing attack successfully steals your password, 2FA prevents attackers from accessing your account without the second factor. Enable it on all accounts that support it.
Be Skeptical of Urgency
Phishing attacks almost universally create a sense of urgency — "Your account will be suspended in 24 hours," "Verify your payment now," "Immediate action required." This urgency is designed to make you click before thinking. Pause, verify independently, and never let urgency override caution.
Use a Password Manager
Password managers autofill credentials only on the correct domain. If you're on a phishing site that looks identical to your bank but has a slightly different domain, your password manager won't autofill — giving you an automatic warning that something is wrong.
Verify Email Senders Carefully
The display name of an email can say anything — "PayPal Security Team," "Your Bank," "IT Support." Always check the actual email address, not just the display name. And even a legitimate-looking email address can be spoofed — check the actual links inside the email rather than trusting the sender.
What to Do If You Clicked a Suspicious Link
- Don't enter any information on the page you landed on
- Close the tab immediately if you suspect it's malicious
- Run a malware scan with up-to-date antivirus software
- Change passwords for any accounts you may have been trying to access
- Enable 2FA on affected accounts if not already done
- Check for unauthorized activity on bank accounts and email if you entered any credentials
- Report the phishing URL to Google Safe Browsing at safebrowsing.google.com/safebrowsing/report_phish/