Check a link before you click
In short
Read the domain name — the part just before the first slash — and read it from right to left. It is the only part of the address its owner cannot freely choose. And when the link leads somewhere you have to sign in or pay, don't use it at all: reach the service through a bookmark or its app.
Why this works
From a security point of view, everything else in an address is decoration: the subdomain, the path, the parameters, the text displayed instead of the link, and even the padlock — which only shows that the connection is encrypted, not that the site is honest. An attacker can write “mybank.com” anywhere in an address they don't own. The only thing they actually have to own is the domain name, so that is the only thing you need to read.
Step by step
Reveal the real address
On a computer, hover over the link without clicking: the address appears at the bottom of the window. On a phone, press and hold to open a preview. The visible text of the link means nothing — it can show one address and point to another.
Find the domain name
Find the first slash after “https://”: everything before it is the domain, and what counts is its END. In “login.mybank.com.dubious-example.test/”, the site belongs to “dubious-example.test” — the “mybank.com” in the middle is decoration, placed there to be read first. So read from right to left until you reach the organization's name: if it doesn't come straight away, you are not on its site. Watch out for compound extensions such as “.gouv.fr” or “.co.uk”, where the real name is the word just before: in “impots.gouv.fr” (France's tax site), it is “impots”.
Compare it with what you expected
One extra letter, an added hyphen, a different extension: these are separate domains, owned by someone else. An address starting with “xn--” signals non-Latin characters, which is not fraudulent in itself but has no business being there when you expected an ordinary name.
For a login or a payment, take another route
Never sign in from a link you received, even after checking it. Open a saved bookmark or the official app. Your password manager is a quiet ally here: it ties your credentials to the real domain, so if it stays silent on a site you normally use, that is a warning.
The most common mistakes
- Believing the padlock vouches for the site: it only vouches for the encryption of the connection.
- Reading the start of the address instead of the end of the domain name.
- Trusting a shortened link, which hides exactly the destination.
- Checking a message using the contact details that message provides.
- Typing a password by hand because the manager doesn't offer it: that is bypassing the only warning you got.
A tool to do it
The attacks this defeats
Official sources
Other guides · Last updated: 2026-09-02.