Security

How to Check If a Website Is Safe Before You Click

The padlock icon doesn't mean a site is trustworthy. Here's what actually to check before you click a link or enter a password.

Onuorah Nnamdi Martins

Aug 11, 2026 · 9 min read

The padlock is not a trust badge

A huge number of people believe the padlock icon in their browser's address bar means a website has been verified as safe or legitimate. It does not. The padlock only indicates that the connection between your browser and that specific server is encrypted with HTTPS, so a stranger on the same network cannot easily read the traffic. It says nothing about who runs the site or whether they're honest. Attackers routinely register their own domains and enable HTTPS on phishing pages—doing so is free and automatic with most modern hosting. Understanding this one distinction clears up most of the confusion around "is this site safe."

Key terms

  • HTTPS: the encrypted version of a web connection, shown by a padlock; it protects data in transit but says nothing about the site owner's intent. See our full breakdown of HTTP vs HTTPS for the technical difference.
  • Domain: the core address of a site, such as example.com, which identifies who actually controls the page—this is the single most important thing to check.
  • Phishing: a fake site or message designed to trick you into entering credentials or personal information, often mimicking a real brand's design closely.
  • Safe Browsing: a system, most notably Google's, that maintains lists of known malicious or deceptive sites and warns browsers before they load one.
  • Malware: malicious software a site might try to get you to download or that could exploit a vulnerability in your browser automatically.

Step 1: read the domain, not just the page design

A convincing logo, matching color scheme, and familiar layout are trivial for a scammer to copy. What's much harder to fake convincingly is the actual domain, because a scammer cannot register the real bank's exact domain if it's already taken. Before entering any information, find the domain by locating the first single slash after "https://" and reading immediately to its left—everything else, including subdomains and paths, is far easier to manipulate to look official. Our guide to how URLs work walks through this in more detail with worked examples of common tricks.

Step 2: hover before you click

Most browsers and email clients show a link's actual destination in a small preview, usually in the bottom corner of the window, when you hover your mouse over it without clicking. On mobile, a long press often achieves the same preview. Compare that preview against what the link text claims to be—a mismatch between the two is one of the most reliable signs of a deceptive or malicious link.

Step 3: recognize a fake login page

Fake login pages are the most common form of phishing because credentials are valuable and pages are easy to clone. Warning signs include:

  1. A domain that's close to but not exactly the real service's domain.
  2. Urgent language pressuring you to "verify now" or "confirm within 24 hours."
  3. A page that looks slightly off—wrong logo resolution, outdated branding, or broken layout on mobile.
  4. A login form that appears after clicking a link from an unexpected email or text rather than one you navigated to directly.
  5. A request for information the real service wouldn't need for a simple login, like a full card number or a security-question answer.

Our dedicated guide to spotting fake login pages covers this exact scenario with more visual examples and a step-by-step verification process.

Step 4: use your browser's built-in warnings

Modern browsers include automated protection that checks sites against databases of known malicious pages. Google's Safe Browsing, built into Chrome and used by several other browsers, and similar systems in Firefox and Edge, will show a full-page red warning before loading a site flagged as dangerous or deceptive. Never click through this warning to proceed unless you have a specific, verified reason to trust the site anyway—these warnings have a low false-positive rate for a reason. Google explains how the system works in its own Safe Browsing overview.

Step 5: don't install unknown "security" tools from an ad

A common trap is clicking a pop-up or ad claiming your device is infected or that a site scan found a problem, then downloading a "cleaner" or "scanner" tool to fix it. These tools are frequently the actual malware, or at minimum aggressive, low-value software designed to scare you into paying. Legitimate security software is downloaded directly from a known vendor's official site or your device's app store, never from a pop-up claiming to have already scanned your device. If you're concerned about an actual infection, see our guide to malware and staying safe for how real detection and removal actually works.

A 30-second pre-click checklist

  1. Does the link preview match what the text or button claims?
  2. Is the domain exactly right, with no extra words, misspellings, or unusual subdomains?
  3. Is there HTTPS, and does the certificate match the expected organization if you check it?
  4. Did I navigate here myself, or did I arrive through an unexpected link or pop-up?
  5. Is the page pressuring me to act quickly or enter sensitive information immediately?

When your browser already blocked something

If a Safe Browsing-style warning appears, don't dismiss it out of frustration. Close the tab, and if you believe the warning is a mistake for a site you trust, report it through your browser's official feedback mechanism rather than disabling the protection entirely. Disabling built-in safety warnings to "get past" one annoying block removes protection for every future visit, not just this one.

▶ Watch: How the Web and Browser Security Actually Work (open on YouTube)

A padlock, a nice logo, and a familiar layout tell you almost nothing on their own—the domain, the way you arrived at the page, and whether it's pressuring you to act fast are what actually separate a safe click from a costly one.

A beginner's verification checklist

Good advice about website safety should be practical, specific, and easy to undo when it is wrong for your situation. Before changing a setting, installing an app, or sharing information, identify the official source. An official source is the organization that runs the service, makes the product, or is responsible for the policy—not a sponsored search result, a social-media reply, or an unknown download mirror. Read the page address carefully and use a bookmark or manually typed address for important accounts.

Keep a small record

Write down the date, the device involved, and the exact setting you changed. Take a screenshot of the old setting if it is safe to do so. This gives you a rollback plan and makes it easier to ask qualified support for help. Do not include passwords, recovery codes, full account numbers, or private addresses in screenshots you share.

When a guide asks you to enter credentials, understand the difference between signing in and giving away a secret. Sign in only on the known service page or its official app. A password, one-time code, recovery code, and security-key approval are secrets: support staff, friends, and legitimate companies should not need you to send them in chat. If someone creates urgency—"act in five minutes," "your account will be deleted," or "keep this secret"—pause and independently verify the claim.

Make changes one at a time

Changing several things at once makes troubleshooting difficult. Use this simple method:

  1. State the problem in one sentence and note when it happens.
  2. Choose the least invasive official fix first.
  3. Change one item, then test the original problem.
  4. Keep the change only if it helps and does not create a new risk.
  5. Revert it or seek official support if the result is unclear.

For example, if an app suddenly behaves differently, check its update notes and account-security page before installing a "fix" from a video comment. If a device asks for an update, install it from the device's own settings or the maker's site. An update is a vendor-provided software change that repairs defects or adds features. Updates are especially important when they fix security vulnerabilities—mistakes in software that an attacker could exploit.

Use trustworthy help

Prefer a manufacturer's manual, a government consumer-protection agency, a recognized library, or the platform's help center. Check the publication date because menus and policies change. Independent reviews can be useful for experience and comparisons, but they do not override product documentation or local law. Be skeptical of pages that make guaranteed promises, hide who operates them, or demand payment before explaining the issue.

Protect your accounts and devices

Most everyday online safety begins with a few repeatable habits. Use a password manager to create a unique password for every important account. Turn on multi-factor authentication wherever available. Keep automatic updates enabled for your operating system, browser, apps, and router. Back up important files and periodically confirm you can restore one. A backup is a separate copy that lets you recover from loss, damage, or ransomware; copies kept only on the same device do not protect against device failure.

Treat unexpected links, attachments, QR codes, login prompts, and payment requests as things to verify rather than obey. If a message claims to be from a company, open the official app or call the number on a statement you already have. Never solve an urgent digital problem by installing remote-control software for a stranger.

Know when to stop

Stop and contact official support, a trusted local professional, or the relevant authority when a step could expose private data, money, an account, or someone else's equipment. If you believe fraud or a crime is happening, preserve lawful evidence such as dates, screenshots, and receipts, then report it through the proper channel. Do not retaliate, "hack back," or publish accusations without reliable proof.

The goal is informed, lawful control of your own technology. Small, documented steps are safer and more effective than shortcuts.

Onuorah Nnamdi Martins

Backend-focused software developer building practical products and writing about engineering, APIs, and shipping cleaner systems.

Follow / view profile

Discussion (0)

Log in to join the discussion.

    Keep reading