Inspect the destination, not the button text
How to Check an Email Link Before Clicking It
Check the real destination, hostname and context of an email link, but for sensitive account actions the safest path is often to avoid the link and navigate to the service independently.
A blue button can say 'View invoice' while pointing somewhere completely different. Link checking is therefore a URL problem, not a design problem. But inspection has limits: redirects, URL shorteners, compromised sites and carefully chosen lookalike domains can all make a suspicious link appear less obvious than classic phishing examples.
Before you click
- Reveal the destination URL using your mail client's preview or link-copy feature without opening it.
- Identify the hostname—the domain that actually controls the destination—not just a familiar brand word elsewhere in the URL.
- Watch for misspellings, added words, deceptive subdomains and unrelated domains.
- Treat URL shorteners and tracking redirects as obscured destinations unless you can verify where they lead.
- Ask whether the message was expected and whether the requested action makes sense.
- For payments, password resets and sensitive account changes, open the service's app or type a known-good address yourself instead of using the email link.
Learn to find the hostname inside a long URL
The meaningful ownership clue is the hostname after the scheme and before the next slash. In https://accounts.example.com/security, the site is controlled under example.com. In https://example.com.attacker-site.test/login, the controlling domain is attacker-site.test even though 'example.com' appears at the beginning of the hostname.
A long path can also contain trusted brand names without giving that brand control of the site. Read the hostname first, then treat everything after the first slash as content inside that site.
Link checks that help—and their limits
| Check | What it catches | What it can miss |
|---|---|---|
| Compare the visible domain | Typos and obvious unrelated hosts | A newly registered lookalike can still appear convincing |
| Preview the URL | Mismatched button text and destination | A redirect can hide the final site |
| Look for HTTPS | Whether the connection can be encrypted | HTTPS does not prove the site is honest |
| Use a reputation scanner | Previously known malicious destinations | A new or compromised URL may not be classified yet |
| Navigate independently | Removes dependence on the message's destination | You still need to know the legitimate service you intended to reach |
Why perfect visual detection is unrealistic
Modern phishing does not need a bizarre URL. Attackers can register plausible domains, compromise real websites or send through legitimate platforms. That is why the FTC's advice emphasizes independent verification rather than asking users to become forensic URL analysts for every message.
A careful URL inspection is still valuable because it catches many simple attacks. It should be one layer in a decision, not a promise that a clean-looking URL is safe.
Use link inspection to reject obvious traps, then use independent navigation for sensitive actions. The objective is not to prove every link safe—it is to avoid letting an unexpected message choose where you authenticate or pay.
Put this threat in context
Sources and further reading
Need a separate inbox for a short-lived interaction?
Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.
Create temporary email