How to inspect a link’s destination without clicking it
A link can hide its real destination behind shortened text, a tracking address or a redirect chain. Learning how to inspect a link’s destination without clicking it helps you decide whether a page is worth opening and whether a message deserves your trust.
This matters when a link arrives by email, SMS, social media or a workplace chat. A familiar brand name in the visible text does not prove that the underlying address belongs to that organisation. A generic page displaying only “Click here to proceed” offers especially little context about where the next step may lead.
Australian internet users regularly encounter links through banking alerts, parcel notifications, marketplace messages and school or community groups. People checking messages on a phone while commuting through Sydney, Melbourne or Brisbane may have less screen space for examining an address carefully, making simple inspection habits valuable.
The aim is not to treat every unfamiliar link as dangerous. It is to gather enough information before opening it, compare the destination with the surrounding message and avoid entering credentials or payment details on a page that has not earned your confidence.
Start with the visible address
On a computer, move the pointer over a link without selecting it. Most browsers show the destination in the lower-left corner of the window. Read the complete address, paying attention to the actual domain rather than the words used in the link.
On a phone or tablet, press and hold the link to open a preview menu. Choose an option such as copying the link address rather than opening it. Paste the result into a plain-text note where you can inspect it safely. Avoid tapping a preview image if it automatically loads the linked page.
Find the registered domain
Web addresses are read from right to left in important sections. In secure.example.com.au, the meaningful registered domain is generally example.com.au, while secure is a subdomain chosen by the site owner. In example.com.au.attacker-site.com, the real domain is attacker-site.com, not example.com.au.
Look for misspellings, extra hyphens, unusual country-code endings and letters that resemble other characters. A link claiming to be from an Australian bank may use a strange domain or a foreign extension, although an overseas domain is not automatically fraudulent. The domain should match the organisation named in the message and the context in which you received it.
Read the path and query string
Everything after the domain can reveal useful clues. A path such as /login, /invoice or /account/verify may describe the intended page, while a long string after a question mark often contains tracking parameters. These parameters can identify a campaign or referral source without necessarily being harmful.
Shortened addresses need extra care because they conceal the final location. You can copy a shortened link into a reputable URL-expansion service, preferably one that displays the redirect chain without loading the destination in your normal browser. Be cautious with any tool that asks you to install software, sign in or provide personal information.
Recognise redirect and parked pages
Some domains lead to an intermediary page before sending visitors elsewhere. This can be part of advertising, affiliate tracking, a login flow or a domain parking arrangement. A minimal page with no business details, product information or clear purpose should be treated as an unknown gateway, not as proof of a legitimate service.
For additional background, redirect behaviour explained can help clarify why a link may pass through an intermediate page. The explanation does not establish that a particular destination is safe, so assess the address, message and requested action separately.
Use browser and security tools carefully
Modern browsers may display a warning before a known phishing or malware page loads. Antivirus software, password managers and email services can add further checks. These tools are useful layers, yet they can miss new scams, compromised legitimate websites or pages that simply collect information in misleading ways.
Technical users can inspect response headers and redirects with command-line tools such as curl -I, using a controlled environment and avoiding automatic script execution. A header check may show a Location value pointing to another address. It does not prove that the final page is trustworthy, and some servers respond differently to command-line tools and ordinary browsers.
Check the message around the link
A link should make sense within the conversation. Unexpected urgency, threats of account closure, claims about unpaid tolls or requests to confirm a delivery are common warning signs. Compare the sender’s address, spelling, branding and timing with what you normally expect from the organisation.
Scamwatch, operated by the Australian Competition and Consumer Commission, advises people to avoid clicking links in unexpected messages and to contact organisations through details found independently. If an SMS claims to be from Australia Post, open the official app or type the known website into the browser rather than using the supplied link.
Protect your details after inspection
Inspection is a screening step, not a guarantee. If a destination asks for a password, Medicare details, banking information, identity documents or a one-time authentication code, stop and verify the request through an independent channel. Australian privacy protections, including obligations under the Privacy Act, do not make every online form safe or prevent every data exposure.
Use unique passwords and multi-factor authentication, especially for email, banking and shopping accounts. Many Australians buy through local marketplaces or manage services from mobile apps, where a fake sign-in page can appear convincing. If you entered information into a suspicious page, change the affected password through the official service, contact your bank if payment details were involved and report the incident through the appropriate Australian channels.
A cautious workflow takes only a few seconds: copy the address, identify the real domain, examine the path, consider any redirects and compare the request with an independently verified source. For a generic gateway that provides little information, inspect the destination first rather than relying on a prominent proceed button. Make link checking a routine step before opening unfamiliar pages or submitting personal details.