SleekShield Blog
Phishing Email Checker

What To Check Before Clicking a Suspicious Link

Links can hide lookalike domains, tracking redirects, and credential capture pages.

A suspicious link can appear in an email, a text message, a social media comment, or even a legitimate-looking website. Before clicking any link you did not expect or did not specifically request, a quick check can tell you a great deal about whether it is safe. This guide covers the key things to verify without opening the link.

Hover text versus destination

On a desktop computer, hovering your mouse pointer over a hyperlink reveals the actual destination URL in the browser's status bar — usually in the bottom left corner of the screen. This is the most basic and most useful check. The visible text of a link (what is underlined or highlighted) can say anything, but the status bar shows where the link will actually take you.

Compare what you see in the status bar with what the link claims to be. If you receive an email that says "Click here to verify your Commonwealth Bank account" and the status bar shows a URL on a domain like commonwealthbank-verify.online or cb-account-check.net, that is a clear mismatch. The real Commonwealth Bank sends from and links to commbank.com.au.

On a mobile device, you can press and hold a link to reveal the URL before opening it. This is the mobile equivalent of hovering on desktop. Take the extra second to read the domain before tapping.

Short links and encoded URLs

URL shorteners like bit.ly, t.co, and tinyurl.com are legitimate services used by social media platforms and marketing emails, but they are also used to hide malicious destinations. A short link is opaque — you cannot tell from the link itself where it goes.

Services like checkshorturl.com or adding a + to the end of a Bitly link (e.g., bit.ly/examplelink+) will expand the URL and show you the destination before you click it. VirusTotal also scans shortened URLs and reports any known malicious associations with the destination.

Some phishing links use URL encoding — replacing characters with their percent-encoded equivalents — to obscure the actual domain. A URL that looks like https://paypa%6C.com.verify.example.net/login is not going to PayPal; the encoded character is part of a subdomain, and the actual domain is example.net. Always read the domain carefully, paying attention to everything between the https:// and the first single /.

When to use a separate device or not open it at all

If a link arrives unexpectedly in a message that claims to be urgent, arrives at an unusual time, or references a service you do not remember signing up for, the safest option is to not click it at all. Navigate directly to the service's official website by typing the URL yourself, or call the organisation using a number from their official website to verify whether the message is genuine.

If you need to investigate a suspicious link further, use a browser sandbox, an online URL scanner, or a disposable virtual machine rather than your main work device. URLVoid, VirusTotal, and Google Safe Browsing all allow you to check a URL for known malicious associations without visiting the page directly.

Phishing Email Checker

Links can hide lookalike domains, tracking redirects, and credential capture pages.

Check a suspicious email

Related guides

Reference links