How to Spot Suspicious Links Before You Click
The trick to spotting a fake link is reading the domain right to left. How to find a link's real destination on a Mac before you click it.
The most reliable way to judge a link is to read the domain right to left. The part that tells you where a link truly goes is the name sitting immediately before the first single slash, and everything to the left of it can say anything the sender wants. Learn to find that one piece and most phishing falls apart in a couple of seconds.
Read the domain right to left
Take a link like paypal.com.account-verify.xyz/login. It looks like PayPal
at a glance, but read it from the right and the real site is
account-verify.xyz. The paypal.com part is just a label the attacker
stuck on the front, the same way you might name a folder anything you like. The
registrable domain is the two words joined by a dot that sit right before that
first single slash, and that’s the only part that decides where you land.
Once you train your eye to jump to that spot, the disguises stop working. A real brand name buried in the middle or the front of a long address is a warning sign, not a reassurance.

See where a link actually goes on a Mac
You don’t have to click to find the destination. On a Mac, hover your pointer over a link and the real address appears in the status bar at the bottom of the window. Safari hides that bar by default, so turn it on once with View > Show Status Bar and leave it there. In Mail, hovering over a link pops up the full URL the same way.
This matters because the words you see and the place they lead are two separate
things. A link can display the text www.yourbank.com while pointing somewhere
else entirely, because the visible label and the underlying address are set
independently by whoever wrote the message. The status bar shows you the real
address rather than the label, which is the entire reason to look before you
commit.
On an iPhone or iPad, touch and hold a link instead of tapping it. A preview appears with the address at the top, which lets you read the domain before anything loads. This one habit, checking before committing, catches the majority of bad links on its own.
The patterns that should stop you
A few signals reliably mark a link as worth a second look. Urgency paired with money is the classic: a message insisting your account closes in 24 hours or a payment failed is trying to rush you past the reading step. Lookalike characters are another, where “rn” stands in for “m” or a capital I poses as a lowercase l, so a domain reads correctly only if you don’t look closely.
Then there are legitimate brand names used as subdomains on strange roots, which the right-to-left habit already exposes. Shorteners and QR codes deserve their own caution, because you can’t inspect where they lead before you follow them. Treat any address you can’t read as an unknown, and don’t open it just because it’s convenient.
Search results deserve the same scrutiny, since a paid ad or a well-optimized lookalike can sit above the real site for a brand you’re searching by name. Reading the domain applies just as much to a result you clicked as to a link someone sent you.
Why the padlock doesn’t mean honest
The padlock icon has been oversold, and it’s worth being precise about what it promises. It means the connection between your Mac and that website is encrypted, so nobody in between can read it. It says nothing about who’s on the other end. Certificates are free and automatic now, so a phishing site sets one up as easily as a bank does, and it earns the same padlock.
An encrypted connection to a scammer is still a connection to a scammer. Read the domain; ignore the lock.
The move that beats every inspection
When something feels off, the strongest response isn’t a better inspection, it’s to not click at all and reach the site yourself instead. If an email says your bank found a problem, don’t follow its link. Open the bank’s site from your own bookmarks or type the address you already know, and check for the alert there. A real problem will be waiting for you when you arrive on your own.
This one rule sidesteps the entire game. It doesn’t matter how convincing the message is if you never use its link.
Where a checking tool helps
There are times you genuinely have to open something unfamiliar, and that’s where an extra layer earns its place. A security tool that runs reputation lookups and scans a link’s destination can flag a known-bad site before it loads, which is useful for the cases your own eyes can’t resolve. It’s a backstop for judgment, not a replacement for it.
The habits still come first. If you want to go a step further on the software side, our look at whether Macs need antivirus covers what macOS already blocks and where the gaps are, and a short monthly security pass keeps the rest of your setup from quietly drifting out of date.
Common questions
I clicked a phishing link but didn't enter anything. Am I in trouble?
Almost certainly fine. On a Mac that's kept updated, loading a web page rarely does any harm by itself; the danger is what you type or download afterward. Don't enter credentials if a login form appears, and close the tab. Watch for follow-up emails trying to lure you back, and if you're unsure, run a scan on anything you downloaded.
Are QR codes safe to scan?
Scanning one is safe; the destination it points to is the risk. A QR code is just a link you can't read with your eyes, so treat it like a shortened URL from a stranger. On an iPhone, the camera shows the address before it opens, so read that first and don't proceed if the domain looks off.
Does the HTTPS padlock mean a site is safe?
No. The padlock means your connection to that site is encrypted, not that the site is honest. Phishing pages get valid certificates for free, so a scam site can show the same padlock a real one does. Encrypted and trustworthy are two different properties, and only one of them shows up in the address bar.
Recommended next step
Make everyday Mac care easier with BlueHammer
Clean up storage, organize files, browse privately, and keep everyday protection in one place.
Add safer browsing checks
