A suspicious link is a web address that may lead to phishing, malware, a fake sign-in page, or another deceptive destination. It can arrive by email, text message, social media, a QR code, an online ad, or a compromised account belonging to someone you know.
Common warning signs of an unsafe link
Check for misspelled domains, unexpected subdomains, unusual characters, shortened URLs, and a mismatch between the message and the destination. Urgent claims about a delivery, refund, password, unpaid toll, subscription, or account suspension are common lures.
HTTPS and a padlock mean the connection is encrypted; they do not prove that the site itself is legitimate.
Suspicious links often imitate routine situations: a package waiting for an address update, an unpaid road toll, a document shared by a coworker, a security alert, a refund, or a subscription renewal. The scenario may be plausible even when the destination is fraudulent.
Where suspicious links appear
They can arrive through email, SMS, social media direct messages, online ads, calendar invitations, QR codes, search results, or compromised accounts. A link from someone you know is not automatically safe. Their account may have been taken over, or they may have forwarded something without verifying it.
QR codes deserve the same scrutiny as visible URLs. A sticker placed over a parking meter, restaurant menu, or payment sign can redirect a phone to a different site.
How to inspect a link safely
On a computer, hover over the link without clicking. On a phone, press and hold to preview the address when the app supports it. Read the domain from right to left and identify the registered site name. If the message claims to come from a company, open its official app or type the known address yourself.
Do not enter a password, payment card, Social Security number, or verification code on a page reached through an unexpected message.
Break the decision into three questions: Who sent it? Where does it actually lead? Does the request make sense? If any answer is uncertain, use another route. For example, open the bank or retailer app directly instead of following an alert link.
What a link checker does
A link checker compares a destination with known threat information and may analyze characteristics associated with phishing or malware. It can provide useful evidence before a visit, especially when the full address is difficult to interpret.
The result must be understood in context. A site can be technically clean while hosting a misleading offer, and a newly created phishing page may not yet appear in threat databases. Link analysis does not confirm a payment request, seller, job offer, or caller.
What to do if you clicked
Close the page and do not download anything. If you entered a password, change it from a trusted device and sign out of other sessions. Enable multifactor authentication and review recent activity. If you downloaded a file or app, disconnect from sensitive accounts and run trusted security checks.
If payment or identity information was submitted, contact the relevant financial institution and follow the recovery steps at IdentityTheft.gov. Preserve the message, URL, screenshots, and time of the event before deleting anything that may be useful for a report.
How to reduce exposure to suspicious links
CISA recommends recognizing and reporting phishing rather than interacting with suspicious messages. CISA recommends recognizing and reporting phishing. Keep the browser, Android, and apps updated. Enable spam filtering and multifactor authentication. Use bookmarks or official apps for important accounts. Avoid searching for customer-support phone numbers through sponsored results when an official statement or app provides a verified contact method.
Can a link checker guarantee safety?
No. A link checker can identify known threats and suspicious patterns, but a clean result is not proof that a request, seller, payment, or person is legitimate. Newly created or targeted pages may not yet be classified.
Frequently asked questions
Are all shortened links dangerous?
No, but they hide the destination. Expand or verify the link before opening it when the context is unexpected.
Can a QR code contain a malicious link?
Yes. Treat a QR code like any other link and inspect the destination before continuing.
Can a link from a friend be dangerous?
Yes. Their account may have been compromised, or they may have forwarded the link without checking it.
Is a link safe if the page has a professional design?
No. Attackers can copy logos, layouts, and sign-in pages. Verify the domain and the reason for the request.
I clicked but did not enter information. Is there still a risk?
The risk is lower, but a download, browser exploit, notification permission, or redirect may still have occurred. Close the page, review downloads and permissions, update the device, and run appropriate checks.
Can a shortened URL be checked?
Some services can reveal the destination before a visit. Even after expansion, evaluate the final domain and context.
Common link scenarios in the United States
Delivery scams claim that USPS, UPS, or FedEx needs a small redelivery fee or an address confirmation. Toll scams imitate a state tolling authority and threaten late fees. Banking messages claim that a card or account has been suspended. Tax-season phishing can imitate the IRS or a tax-preparation service. Job scams may send an interview form or employment document that leads to credential theft.
The appropriate response is not to replace one suspicious link with another search result. Open the official app, use a saved bookmark, or type a verified government or company domain. Sponsored search results can also be misleading.
Reading a domain correctly
In accounts.example.com, the registered domain is generally example.com; âaccountsâ is a subdomain. A fraudulent address may place a trusted name earlier in a longer domain, such as bank.security-example.com, where security-example.com controls the site. Misspellings, substituted letters, added hyphens, and unusual top-level domains can also imitate a brand.
The visible text of a link can differ from its actual destination. Email and webpages can display example.com while sending the visitor elsewhere. That is why previewing the destination matters.
Links in documents, ads, and QR codes
PDFs, shared documents, online advertisements, and calendar invitations can contain the same phishing links found in email. A document stored on a reputable cloud platform is not automatically trustworthy; the platform may only be hosting content uploaded by a user.
Before scanning a QR code in a public place, check whether the code appears to be a sticker placed over the original. After scanning, read the destination before opening it. The FBI recommends typing IC3.gov directly because criminals have spoofed official complaint websites. The FBI specifically recommends typing IC3.gov directly because criminals have spoofed even official complaint websites. Do not install an app or configuration profile merely because a QR code instructs you to do so.
A practical response based on what happened
- You received but did not open the link: report and delete the message.
- You opened the page but entered nothing: close it, review downloads and permissions, and update the browser and device.
- You entered a password: change it from a trusted device, end other sessions, and secure recovery methods.
- You entered card or bank information: contact the institution using a verified channel and monitor transactions.
- You provided identity information: follow an appropriate recovery plan at IdentityTheft.gov.
- You installed an app or profile: remove it, review powerful permissions, and run security checks.
More questions about suspicious links
Does a `.gov` address prove that a site is official?
A genuine `.gov` domain is restricted to U.S. government organizations, but users must still read the complete domain and watch for text that only resembles `.gov`.
Can a legitimate website be compromised?
Yes. A normally trustworthy site or account can temporarily distribute malicious content. Consider both the destination and the unexpected behavior.
Should I open a link in private-browsing mode?
Private browsing limits local history and cookies; it does not make a malicious destination safe.
Can a link steal information without a form?
A page can collect technical information and may attempt downloads or browser exploitation. Current software and prompt response reduce risk, but do not justify opening an untrusted link.
A repeatable link-safety routine
Separate inspection from action. First preview and read the destination. Then verify the sender and stated reason without using the link. Open the official app or a saved bookmark and check whether the same alert appears there. If the request involves money, credentials, identity information, software installation, or a security-code prompt, require stronger verification.
Organizations can reduce link risk by using consistent domains, authenticated email, clear notification practices, and employee reporting channels. Individuals can reduce it by keeping software current, using a password manager that recognizes legitimate domains, and reporting suspicious messages rather than forwarding them broadly.