Online Safety Guide

How to Tell If a Link Is a Scam

Scam links are designed to make you act before you have time to notice something is wrong. Learning a few simple warning signs can help you avoid phishing pages, fake payment sites, impersonation scams, and credential theft.

Why scam links can be difficult to spot

Modern phishing pages can copy the branding, colors, logos, and layout of legitimate websites. The link may arrive in an email, text message, social media DM, QR code, fake invoice, delivery notice, or payment request.

Instead of judging a page by how professional it looks, inspect where the link actually leads and whether the request makes sense.

Warning signs

6 signs a link may be a scam

1

The domain name looks slightly wrong

Scammers often register domains that look similar to real brands. Watch for extra words, missing letters, unusual spelling, numbers replacing letters, or an unexpected domain ending.

2

The message creates urgency or fear

Messages such as 'your account will be suspended today' or 'verify immediately' are commonly used to pressure you into clicking before thinking.

3

The site asks for sensitive information

Be cautious when an unexpected link asks for passwords, card numbers, PINs, one-time passwords, recovery codes, identity documents, or other private information.

4

The link came from an unexpected sender

Even when the sender name looks familiar, verify unexpected links independently. Accounts can be impersonated or compromised.

5

You are promised money, prizes, or refunds

Unexpected giveaways, investment profits, refunds, job offers, and prize claims are common ways scammers convince people to open malicious links.

6

The website does not match the organization

A bank, delivery service, marketplace, or government organization should normally use its official domain. A completely unrelated domain is a major warning sign.

Check the domain before trusting the page

The most important part of a website address is the actual domain. Scammers may add trusted brand names into a long URL while the real domain belongs to someone else.

Example

secure-bank.example-scam-site.com

Even though the address contains words such as "secure" and "bank", the important domain is the one actually controlling the website.

Do not trust a link only because it has HTTPS

HTTPS protects the connection between your browser and the website. It does not verify that the website owner is honest. A phishing website can have HTTPS and still be dangerous.

Treat the padlock as connection security, not proof that the website itself is trustworthy.

What to do when you receive a suspicious link

1.

Do not click immediately.

2.

Check the domain and spelling carefully.

3.

Verify the sender using a known phone number, app, or official website.

4.

Avoid entering passwords, payment information, or verification codes.

5.

Use TrustLens to review the URL and available warning signals.

6.

If you are still unsure, avoid the link and contact the organization directly.

What if you already clicked the link?

Simply opening a page does not automatically mean your accounts are compromised, but do not continue if the page looks suspicious.

If you entered a password, change it through the legitimate website or app. If you reused that password elsewhere, change it on those accounts too. Review account activity and enable stronger authentication where available.

If you submitted payment information or sent money, contact your bank, card provider, wallet provider, or payment service using its official support channel.

TrustLens Phishing Link Checker

Have a link you are unsure about?

Run it through TrustLens and review the available scam, phishing, community, and URL warning signals before deciding what to do.

Open Phishing Link Checker

Frequently asked questions

Scam link FAQ

Can a website with HTTPS still be a scam?

Yes. HTTPS means the connection is encrypted, but it does not prove that the person or company behind the website is trustworthy. Scam websites can also use HTTPS certificates.

What should I do before clicking a suspicious link?

Check the domain carefully, verify the sender through an independent channel, and use a link checker such as TrustLens before opening the destination.

What if I already clicked a scam link?

Avoid entering any information. If you entered a password, change it using the official website or app and review your account security. If you entered payment information, contact the relevant financial provider promptly.

Does a short URL mean it is a scam?

Not necessarily. Legitimate services use shortened links too, but shortening can hide the real destination. Treat unexpected shortened URLs with extra caution.

More TrustLens tools

Check other suspicious content