How to Check If a Link Is Safe
Published February 01, 2025 · GoTo.now Team
TL;DR - Most link scams work because people click first and think second. Flip the order: preview where a link really goes, check the domain spelling, and look for HTTPS before you tap. A free link checker does the heavy lifting in seconds.
Key points
- Paste any suspicious link into a link checker to see its real destination without visiting it
- Hover over links on desktop to preview the true URL
- Watch for look-alike domains - Amaz0n.com is not amazon.com
- HTTPS means the connection is encrypted, not that the site is honest
- QR codes are links too; the same checks apply before you scan and tap
That text about a package you don't remember ordering. The email saying your account is locked. The DM from a friend that just says "is this you??" with a link. All of them are betting you'll click before you think. Here's how to check any link in a few seconds, so the bet stops paying off.
Why one bad click matters
A malicious link usually does one of three things: it opens a fake login page to steal your password, it starts a malware download, or it walks you into a scam checkout. The pages look real - Logos, fonts, the works - Because copying a real site takes a scammer about an hour.
The good news is that the link itself almost always gives the game away. Scammers can fake a page, but they can't fake the real domain. Learn to read the link, and you've disarmed most of the trick.
Five checks that take five seconds each
- Run it through a checker. Paste the link into a URL checker and see where it actually leads before your browser ever goes there. This is the safest move because nothing gets visited - Free to use, no account needed, one of several free tools that work right in your browser.
- Hover before you click. On a computer, rest your mouse on the link and read the real URL in the corner of the browser. If the text says "yourbank.com" but the corner says something else, that's your answer.
- Read the domain carefully. The only part that matters is the last piece before the first single slash.
yourbank.com.secure-login.xyzisn't your bank - It'ssecure-login.xyzwearing a costume. Look for swapped letters too:paypa1,arnazon,rnicrosoft. - Check for HTTPS - But don't stop there. The padlock means the connection is encrypted. Scammers can get padlocks too. No HTTPS is a red flag; HTTPS alone is not a green one.
- Question the pressure. "Your account closes in 24 hours." "You've won - Claim now." Urgency is the scammer's favorite tool, because rushed people don't check links. The pressure itself is the tell.
Red flags at a glance
| What you see | What it likely means |
|---|---|
| Misspelled or look-alike domain | Phishing site imitating a real brand |
| Urgent threat or too-good prize | Pressure tactic to stop you from checking |
| Random string of characters | Could be fine - Preview it before clicking |
| Link text doesn't match the hover URL | The link is lying about its destination |
| Unexpected attachment plus a link | Classic malware delivery combo |
| Login page reached from an email link | Go to the site directly instead |
None of these alone is proof. Two or three together? Close the tab.
What about shortened links?
Short links hide their destination by design - That's the honest cost of making links tidy. So treat unknown short links like sealed envelopes: open them with a tool, not with your browser. Any GoTo.now link can be previewed in the checker, which shows you the exact destination, and links that lead somewhere harmful get reported and shut down.
If you're the one sharing links, this cuts the other way: readable links earn more trust. A custom ending like goto.now/menu tells people where they're headed before they tap. Making links like that is free - Shorten yours at GoTo.now and pick endings a human can read. And remember QR codes are just links wearing pixels: the same preview-first rule applies to that code on a parking meter or a random flyer.
If you already clicked
It happens. Move fast and in this order: don't type anything on the page that opened. Close the tab. If you did enter a password, change it now on the real site, and everywhere else you reused it. Turn on two-factor authentication while you're there. Run an antivirus scan, and if money's involved, tell your bank right away - Speed matters more than embarrassment.
Make checking links a reflex
Safe clicking isn't about paranoia - It's about a two-second habit. Hover, read the domain, and when in doubt, paste the link into the checker before your browser touches it. Do that for a week and it becomes automatic, like glancing before crossing the street. The scams keep coming; they just stop working on you.
Step-by-step guides for this topic