A malicious link directs the user to a destination or action intended to steal information, install software, exploit a vulnerability, redirect payment, or support another scam. The visible words, button, QR code, or shortened address can hide the real destination.

How malicious links are used

Links may open fake login pages, trigger downloads, request browser-notification permission, launch an app action, or send the user through several redirects. They arrive through email, texts, ads, search results, social messages, documents, and compromised accounts.

A link to a legitimate site can still support fraud when the page hosts a scammer’s form or the sender lies about what the recipient should do.

How to check a link

Preview the destination and identify the registrable domain. Verify the sender and task through another channel. For an account warning, open the official app instead of using the link.

A URL checker can identify selected known technical risks. It cannot prove that the person, seller, payment, or offer is genuine.

What to do after clicking

Close the page and stop downloads or permission requests. Change submitted credentials, contact financial institutions for payment data, and remove suspicious apps or files. Match the recovery to what you entered, approved, installed, or paid.