Five checks to run before you tap a link in a text, email or QR code — and what to do if you already did.
Most scam texts and emails want one thing from you: a tap on the link. The FTC says phishing messages often ask you to click a link to make a payment, and the link leads to a fake page or malware. (FTC) The good news is that you can check most links without opening them. Here's how, in the order that catches the most scams.
| Check | What you're looking for |
|---|---|
| 1. Were you expecting it? | An unexpected message with a link and a deadline is the biggest warning sign of all |
| 2. Read the real domain | The part right before the first single slash — not the words around it |
| 3. Shortened link? | Short links hide where they go; treat them as unknown |
| 4. Look it up | Paste the address into a checker without opening it |
| 5. Go around it | Type the company's real address yourself instead of tapping |
Before looking at the link at all, look at the message. CISA, the U.S. cybersecurity agency, lists urgent or emotional language — “dire consequences” if you don't act now — and requests for personal or financial information as signs of phishing, and puts it simply: “If a message looks suspicious, it's probably phishing.” (CISA) Apple's advice for unexpected messages asking for personal information or money is that “it's safer to presume that it's a scam” and contact the company directly. (Apple)
Some companies also tell you outright that they don't send links. The U.S. Postal Inspection Service says USPS texts only go to people who signed up for tracking, and won't contain a link. (USPIS) So a “USPS” text with a link is answered before you even read the address.
This is the check most people skip, and it's the one that matters. Caltech's information security office explains the rule: the part after https:// and before the next single slash is the domain name, and that's who you're really visiting. (Caltech IMSS) Within that part, read the last two pieces — the name and its ending, like usps.com or chase.com.
Scammers rely on you reading from the left and stopping at a name you recognize. Three tricks to watch for:
Also watch for link text that doesn't match where it goes. Apple lists a link that “looks right, but the URL doesn't match the company's website” as a sign of phishing. (Apple)
A shortened link (a few random characters after a short domain) hides its destination. CISA lists “untrusted shortened URLs” among the signs of phishing. (CISA) A real company may use them in marketing, but in an unexpected text about a payment, a package or your account, there's no way to read the domain — so skip to check 5.
If you want a second opinion on a specific address, copy it without tapping it and paste it into a checker:
Know the limit: a list can only flag sites someone has already found. Scam sites in text campaigns are often brand-new, so “no unsafe content found” means “not on the list yet,” not “safe.” That's why checks 1 and 2 come first.
The safest link is the one you don't tap. The FTC's advice is to contact the company “using a phone number or website you know is real — not the information in the email.” (FTC) CISA says the same: go to the company's website yourself and get its contact details there. (CISA) If your bank, carrier or a delivery company really needs something from you, it'll be waiting when you sign in to the app or type the address yourself.
A QR code is just a link you can't read until you scan it. In September 2026 the FTC warned about QR codes stuck in public places, and said to inspect the link your phone previews before opening it: “Make sure there are no spelling mistakes or switched letters in the link before you click.” (FTC) The same domain check from step 2 applies — and if a QR code on a parking meter or a flyer asks for payment, paying through the official app or website is the safer route.
Opening a page isn't the end of the world; what matters is what you did next. The FTC's steps: (FTC)
After a QR code scam, the FTC also says to review your bank statements for charges you don't recognize and report it at ReportFraud.ftc.gov. (FTC) Then report the message itself — our guide on how to report a scam text shows where.
You don't need an app for any of the checks above. Shieldr is for when you'd rather not decode a web address yourself, or you're checking for a parent. Share the text, email or link to Shieldr and it checks the link against Google's list of known malicious sites and reads the message around it — the sender, the urgency, what it's asking for — then answers safe, suspicious or scam with a one-sentence reason. The same limit applies: a brand-new site may not be on Google's list, which is why Shieldr looks at the whole message, not just the link. Shieldr is a paid iPhone app; if you'd rather use something free, Google's tool above and our comparison of scam-checker apps are good places to start.
Share the text, email or voicemail to Shieldr and get a plain-English verdict — safe, suspicious or scam — with the reasons it spotted. It's one more check before you tap anything, not a guarantee.
Get Shieldr on the App StoreYes. Google's Safe Browsing site status tool lets you paste a web address and see Google's latest Safe Browsing result for it without visiting the page. A clean result doesn't prove a link is safe, though: a brand-new scam site may not be on any list yet.
Let your camera show the link preview first and read it before you tap. The FTC says to make sure there are no spelling mistakes or switched letters in the link, and the same domain check applies: read the part right before the first single slash.
Close the page, don't enter anything, and keep your phone's software up to date. If you did type a password, change it and turn on two-factor authentication; if you entered card details, call your card issuer using the number on the back of the card.
Related: the USPS “package on hold” text and the fake DMV ticket text, two scams that live or die on whether you tap the link.