Most of the time browsing the web is fine, but malicious links still turn up in ads, emails, messages and apps. They can try to trick you into giving away passwords, downloading malware or handing over money. Here’s a plain-English guide to checking links before you click and what to do if you make a mistake.
How to check a link before you click
- Hover or long‑press: On a PC or laptop, hover your mouse over a link and look at the address that appears — usually at the bottom of the browser. On mobile, press and hold the link to preview the URL. This shows where the link actually goes without opening it.
- Watch the domain: The domain (the main part of the web address) should match the organisation you expect. Be wary of tiny misspellings or extra words — for example, a familiar brand name plus odd characters or a different top-level domain (like .net instead of .com) can indicate a fake site.
- Check for HTTPS (and understand what it means): A padlock and an address that starts with https:// mean the connection is encrypted, which is important — but it doesn’t guarantee the site is trustworthy. Lack of HTTPS on pages that ask for passwords or payment details is a clear red flag.
- Expand shortened links: Shortened URLs (from services like bit.ly) hide the destination. Use a URL-expander or preview feature to reveal the full address before opening them.
- Be careful with pop-ups and adverts: Ads claiming you’ve won a prize, urging urgent action, or offering unrealistic rewards are classic tricks. If an advert blocks the page or makes it hard to close, don’t interact with it; close the tab or browser instead.
- Inspect certificate details if unsure: You can click the padlock in the browser address bar to view certificate information and see who owns the site. This is useful if a site claims to be a bank, shop or other trusted service.
What to do if you clicked a suspicious link
- Close the tab and don’t enter any details. If a download started, don’t open the file.
- Clear your browser cookies and cache. This removes tracking cookies and can help stop some unwanted behaviour.
- Run a malware scan on your device with up-to-date antivirus or anti-malware software. Many scanners offer free on-demand checks.
- Change passwords for accounts you think may be affected, starting with email and financial accounts. Use a password manager so you can set strong, unique passwords and enable two-factor authentication where possible.
- Check bank and card statements for unauthorised transactions and contact your bank immediately if you suspect fraud.
- If your device behaves strangely after a visit — unexpected pop-ups, new toolbars, or poor performance — back up important data and consider a factory reset after you’ve exhausted diagnostic steps.
A few practical rules to keep upfront: don’t click links in unsolicited emails, don’t enter payment details on unfamiliar sites, and prefer official apps from recognised app stores. Staying cautious and knowing these simple checks will protect you from the majority of malicious links you’ll encounter online.