Knowledge · Check before you click or pay · 8 minutes

How to check if a link is safe before you click it

How to read a link's address without clicking, expand a short link, check the domain on the CERT Polska list and spot 'payment link' scams on marketplaces.

Last updated: October 5, 2026

What to check in a link before you click

A link is an address, and only one part of it really tells you something: the domain. It is the part just before the first single slash '/', read from the right. In 'https://olx.pl.parcel-delivery.com/collect' the domain is 'parcel-delivery.com'. The 'olx.pl' at the start is a subdomain that the owner can name anything.

The three tricks you see most often:

1. A known brand at the start of the address and an unrelated domain at the end (as above).

2. A domain similar to the real one: swapped letters, a hyphen, add-ons like '-pl', '-help', '-refund', a different ending.

3. An '@' sign in the address. The browser treats everything before it as a user name and opens what comes after it.

Some letters from other alphabets look exactly like Latin ones, for example the Cyrillic 'а' and the Latin 'a'. If a copied address contains a part starting with 'xn--', the domain uses non-Latin characters and deserves a closer look.

The text of a link and its address are two different things. The words 'www.mybank.com' in an email can lead somewhere else entirely.

How to preview a link without clicking

On a computer: hover the mouse over the link and do not click. The real address appears in the bottom left corner of the browser or in a tooltip in your mail app.

On a phone: press and hold the link. Choose 'Copy link' or 'Copy address', paste it into your notes and read it calmly. On an iPhone, holding a link in Safari shows a preview of the page and a menu; choose copy instead of open.

Text messages keep repeating the same pretexts: an extra parcel fee, an overdue electricity or gas bill, a fine, a tax refund, a blocked account, a prize. Each one is meant to make you click before you think. Check the real issue in the courier's, supplier's or bank's app, without the link from the message.

QR codes: the phone camera usually shows the address before opening it. Read it like any other link. A QR code stuck on a parking meter or a flyer can lead anywhere.

If you do not want to send the address anywhere, you can paste it into arLET'S: recognition happens in your browser and nothing is sent. You will see the domain and signals in the address itself (such as a shortener, non-Latin characters or login details in the address), but the link is not opened, so a short link is not expanded.

How to check if a link is safe online

1. The CERT Polska warning list (lista.cert.pl). In 2025 almost 245,000 domains were added to it. CERT Polska recommends that blocking systems download it every 5 minutes, and according to CERT it is used by the Polish operators Orange, Plus, Play and T-Mobile. A domain missing from the list is not proof the link is safe: fresh domains only appear after they are reported and analysed.

2. Domain age. For .pl domains, check the NASK registry WHOIS (dns.pl/whois); for others, ICANN Lookup (lookup.icann.org). A domain a few days old that imitates a courier, a bank or a classifieds site is a strong signal.

3. A free domain check in arLET'S. In domain mode you can check the CERT Polska warning list, the domain's age and status in the registry, similarity to known brands, email protection (SPF and DMARC), all in one result.

4. A URL scanner such as VirusTotal. It shows verdicts from many antivirus engines and, useful for short links, the redirect chain and the final address the link ends up on. Do not paste links that contain your own data, such as a password reset link or a link to a document, into external scanners.

Short links: how to check where they lead

A link shortener turns a long address into a short one and hides the real domain. That is not bad in itself, as companies use them in newsletters, but in a text from an unknown sender it is a way to hide where the link goes.

Do not open a short link 'just to see'. Expand it with a scanner that shows the redirect chain and the final address, and then check that address using the steps above. Remember that a link can redirect several times, and the final address can depend on the device you use.

How to check if a link in an email is safe

Start with the sender, not the link. If the sender's address is suspicious, so is the link. We explain how to check the sender, the domain and the headers in how to check if an email is real.

Then hover over the link and compare the address with the sender's domain. A bank writing from one domain and linking to a completely different one is a warning sign.

The simplest rule: if a link leads to a login, a payment or 'confirming your details', do not use it at all. Open the app or type the service's address yourself and check whether the same issue is waiting in your account.

How to check if an OLX link is safe

The 'fake buyer' scam goes like this: you sell something on OLX, Vinted or Allegro Lokalnie, a 'buyer' writes on WhatsApp or in chat and sends a link to 'receive payment' or 'confirm shipping'. The page looks like OLX, a courier or a bank and asks for card details or a banking login. Once you enter them, the account is emptied.

This is not rare. According to the CERT Polska report for 2025, campaigns misusing the OLX brand produced 28,462 incidents and Allegro 22,513. 28,562 domains impersonating OLX were added to the warning list.

Rules that cut this off: OLX replied on its blog (January 2023) that transactions with OLX delivery take place only on the OLX site or in its app, and that links sent by text or WhatsApp come from scammers. Vinted says you do not have to leave Vinted to confirm a payment or receive an order. A seller never needs to enter card details to get paid. Treat every buyer's link that takes you outside the app as a scam.

In Poland, forward such a text message to 8080, report the page at incydent.cert.pl, and send a fake message impersonating Vinted to phishing@vinted.com.

I clicked a suspicious link. What now?

Just opening a page is usually not enough to steal money, but it can lead to downloading a malicious file. Do not install anything the page asks for, and close the tab.

If you entered card or banking login details, call your bank straight away. Poland's Central Cybercrime Bureau also recommends freezing your national ID number (PESEL) in mObywatel. If you entered an email or service password, change it everywhere you used it. More next steps are in how to check if a website is safe and how to check if your data has been leaked.

In short

  • What counts is the domain before the first slash, read from the right. A brand name at the start of the address proves nothing.
  • You can preview an address without clicking: hover on a computer, press, hold and copy on a phone.
  • Expand a short link with a scanner that shows the final address, not by opening it.
  • A buyer's link to 'receive payment' on OLX or Vinted is a scam. These platforms handle transactions only in their own app and site.
  • A domain missing from the CERT Polska warning list is not proof it is safe.

Have a website, app or email address that looks suspicious?

Frequently asked questions

How can I check a link without opening it?

On a computer, hover over it and read the address at the bottom of the browser. On a phone, press and hold the link, copy it and paste it into your notes or a tool that checks the domain.

Does OLX send links to receive money?

No. According to OLX, transactions with OLX delivery take place only on the OLX site and app. A link from a 'buyer' on WhatsApp or by text message is a scam.

How do I check where a short link goes?

Paste it into a URL scanner that shows the redirect chain and the final address, such as VirusTotal. Do not paste links that contain your personal data.

Is just clicking a link dangerous?

The biggest risk usually comes when you enter data or install a file from the page. If you only opened the page, close it and install nothing. If you entered data, act as you would after a leak.

Where can I report a suspicious link?

In Poland, forward a text message with the link for free to 8080. Report a page or an email to CERT Polska via the form at incydent.cert.pl.

Sources

  1. CERT Polska: Annual report on CERT Polska activities in 2025
  2. CERT Polska: Warning list of dangerous websites
  3. OLX blog: Do not get scammed by a fake buyer (11 October 2022)
  4. Vinted: Recognize spoof and phishing messages
  5. VirusTotal: URL object documentation (final URL and redirect chain)
  6. Apple: Browse the web using Safari on iPhone
  7. Central Cybercrime Bureau (Polish Police): Report cyber fraud

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also