How to check a link before you click
Most phishing depends on one moment: the click. These checks take under a minute and catch most fake links before they can do anything.
The short version
- Look at the real address, not the text of the link.
- The part that matters is the domain just before the first single slash, read from the right.
- A padlock only means the connection is encrypted. Phishing sites have padlocks too.
- When in doubt, do not click. Open the app, or type the address yourself.
Eight checks, in order
See the real address
On a computer, hover over the link and read the address in the bottom corner of the window. On a phone, press and hold the link until a preview shows the address. The blue text of a link can say anything.
Find the real domain
Take the part between :// and the next single slash, and read it from the right. In northbank.com.account-check.net, the site is account-check.net, and northbank.com at the front is just a label anyone can put there. (Northbank is a made-up example.)
Look for lookalikes
Swapped letters (rn for m, 0 for o, 1 for l), extra words (northbank-secure, northbank-support), or a different ending (northbank.co instead of northbank.com). Scammers register names that pass a quick glance.
Be careful with short links and QR codes
Shortened links and QR codes hide the address until you open them. A preview or a scan shows where they really go.
Do not trust the padlock
HTTPS and a padlock mean the connection is encrypted. They say nothing about who runs the site, and most phishing sites have them.
Read the message around the link
Urgency, a threat (account locked, parcel returned, fine due), a prize, or a request to confirm details are the usual lures. A real company can wait while you check.
Go direct when it matters
For your bank, email, courier or tax account, skip the link. Open the official app, or type the address you already know, and look for the same message there.
Scan it
Paste the link into the scan box below. Dralvia opens it in an isolated browser, so nothing runs on your device, and shows a Safe, Caution or Avoid verdict with the evidence behind it. How the Dralvia score works explains the verdicts.
When the link looks fine but something feels off
Some scams use real sites: a shared document, a form builder or a file-sharing page. The address is genuine, and the page still asks for your password or card. Ask why this page needs that. Your email password is only ever typed on your email provider's own sign-in page.
Check a link now, free
Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.
Questions people ask
- Is it safe to open a link just to see what it is?
- Opening a page is usually less risky than typing into it, but some pages try to download files or exploit an out-of-date browser. Scanning the link first shows you the page without opening it on your device.
- The link came from someone I know. Is it safe?
- Not always. Hijacked accounts send phishing to their contacts. If the message is unexpected, ask the person through another channel before you click.
More guides
What the Dralvia risk score from 0 to 100 means, where the points come from, what Safe, Caution and Avoid ask you to do, and what a score cannot tell you.
How fake QR codes on parking meters, posters, emails and PDFs steal logins and card details, and four habits that make scanning a QR code safe.
How fake online stores and social media ads take payments for goods that never arrive, and a quick check to run on any shop before you pay.