How to Verify a Suspicious Link Before You Click (2026 Guide)

How to Verify a Suspicious Link Before You Click (2026 Guide)

Scam links are no longer obvious. They arrive in polished bank alerts, fake delivery notices, social media DMs, calendar invites, job offers, QR codes, and ads that look like normal search results.

The goal is simple: get you to click before you think.

This guide gives you a fast, practical way to inspect a suspicious link without trusting it, opening it, or handing over information. Use it whenever a message creates urgency, promises a reward, threatens an account closure, or asks you to sign in through a link.

You can also paste suspicious message text into HelloAlpha's free scam checker at helloalpha.ai/scam-check.


Before clicking any unexpected link, run this quick check:

  1. Pause if the message creates urgency
  2. Look at the real destination, not the button text
  3. Check the domain from right to left
  4. Watch for lookalike spelling
  5. Go directly to the official site instead

If any step feels wrong, do not click.


Step 1: Treat Urgency as a Warning Sign

Scam links usually come with pressure:

  • "Your account will be closed today"
  • "A package is waiting for address confirmation"
  • "Payment failed, update now"
  • "Suspicious login detected"
  • "You have been selected"
  • "Final notice"

Urgency is not proof of fraud by itself, but it is a reason to slow down. Real companies may send alerts, but they do not need you to panic. Scammers do.

Rule: The more urgent the message feels, the less you should trust the link inside it.


Buttons and blue text can lie. A message can show:

https://www.paypal.com

while the actual destination is something completely different.

On Desktop

Hover your mouse over the link without clicking. Look at the preview in the lower corner of your browser or email app.

On Mobile

Press and hold the link. Most apps show a preview or menu. Do not tap the preview page. You only want to inspect the destination.

In Text Messages

Be extra careful. Short links, strange domains, and "tracking" links are common in SMS scams.


Step 3: Read the Domain From Right to Left

Scammers rely on people reading URLs too quickly.

The real domain is the part immediately before .com, .net, .org, or another top-level domain.

Safe Example

https://account.google.com/security

Real domain: google.com

Dangerous Example

https://google.com.security-check-login.example.com

Real domain: example.com

The word "google" appears, but it is not the domain.

Another Dangerous Example

https://paypal.com.billing-update.secure-login.net

Real domain: secure-login.net

This is not PayPal.

Rule: The brand name must be part of the real domain, not just somewhere in the URL.


Step 4: Watch for Lookalike Domains

Many phishing links use tiny spelling changes:

  • paypaI.com where the last character is a capital I
  • arnazon.com where the "m" is replaced by "rn"
  • micros0ft.com with a zero instead of an "o"
  • gooogle.com with an extra letter
  • account-google.com instead of google.com

They may also add trust words:

  • secure
  • verify
  • support
  • billing
  • account
  • login

Trust words do not make a link trustworthy. The domain does.


Short links hide the destination:

  • bit.ly
  • tinyurl.com
  • t.co
  • shorturl.at
  • random branded short domains

Short links are not always malicious, but they remove the most important thing you need to inspect: where the link really goes.

If a bank, delivery company, government agency, or payment app sends a short link, treat it as suspicious. Go directly to the official website or app instead.


Step 6: Do Not Trust QR Codes Automatically

QR codes are just links you cannot read at a glance.

Scammers place fake QR codes on:

  • Parking meters
  • Restaurant tables
  • Flyers
  • Package notices
  • Event posters
  • Crypto promotions
  • Fake invoices

Before opening a QR code, check whether the destination shown by your camera app matches the official organization. If the QR code is on a sticker placed over another QR code, walk away.


Step 7: Use the Official App or Website Instead

This is the safest habit:

  1. Do not click the message link
  2. Open your browser or official app manually
  3. Type the known website yourself
  4. Sign in from there
  5. Check alerts, billing, orders, messages, or deliveries inside the account

If the alert is real, it will usually appear inside your account.

If it only exists in the email or text message, that is a major warning sign.


Stop immediately if a link asks for:

  • Passwords
  • One-time codes
  • Social Security number
  • Banking details
  • Credit card number
  • Crypto wallet seed phrase
  • Remote access installation
  • Photo ID upload

Especially watch for pages that ask for both your password and your two-factor code. That is a common way attackers hijack accounts in real time.


Message: "Your package cannot be delivered. Confirm address."

Risk: The page asks for a small redelivery fee, then steals your card details.

Safer move: Open the official carrier site or app and enter the tracking number manually.

Fake Bank Alert

Message: "Suspicious transaction detected. Verify now."

Risk: The link opens a fake login page and captures your credentials.

Safer move: Call the number on the back of your card or open the bank app directly.

Fake Subscription Renewal

Message: "Your payment failed. Update billing."

Risk: The page collects card information or account credentials.

Safer move: Visit the service directly and check billing inside your account.

Fake Shared Document

Message: "A file has been shared with you."

Risk: The link sends you to a fake Microsoft, Google, Dropbox, or DocuSign login.

Safer move: Check whether the sender is expected and verify through a separate channel.

Fake Search Ad

Message: You search for a support number and click the first sponsored result.

Risk: The ad leads to an impostor support page.

Safer move: Use the company's official app, printed card, or verified website.


What to Do If You Already Clicked

Clicking is not always the disaster. The bigger risk is what happened next.

If You Only Opened the Page

  • Close the page
  • Do not download anything
  • Do not enter information
  • Clear the browser tab if it keeps redirecting

If You Entered a Password

  • Change that password immediately from the official site
  • Sign out of all sessions
  • Turn on two-factor authentication
  • Change the password anywhere else you reused it

If You Entered a Card Number

  • Call your bank or card issuer immediately
  • Ask for a new card
  • Review recent transactions
  • Watch for small test charges

If You Installed Software

  • Disconnect from the internet if remote access was involved
  • Uninstall suspicious software
  • Run a malware scan
  • Change passwords from a different trusted device

Do not use links in unexpected messages to sign in, pay, verify, or recover an account.

Open the official app or website yourself.

That one habit blocks a huge percentage of phishing attempts because it removes the scammer's fake page from the process.


Use HelloAlpha Before You Click

If a link arrived inside a suspicious text, email, or DM, paste the message into HelloAlpha's free AI scam checker. It can help you spot urgency, impersonation, mismatched domains, payment tricks, and other common fraud patterns.

Stay calm. Verify first. Click last.

🔍 Think You've Been Targeted?

Use our free AI-powered scam detector to analyze suspicious messages, emails, or screenshots instantly.

Check for Scams — Free