FrançaisEnglishEspañolالعربيةहिन्दीবাংলা中文

← Back to the blog

Published on 2026-07-25

How do you actually read a link before you tap it?


A web address hides its real owner in plain sight. Learn where to look in a URL, and why the padlock icon proves far less than most people assume.

A link arrives with a message that sounds urgent enough to justify a tap: your account, your delivery, your refund. Most of us glance at the text around the link, not at the link itself. That's exactly backwards. The words in a message can say anything the sender wants. The web address underneath them is the one part that's harder to fake convincingly, if you know where to look.

Read it from the ending, not the beginning

A web address is built like a house number: everything meaningful sits right before the first single slash. Take 'yourbank.com/login' and the owner is yourbank.com. Now take 'yourbank.com.secure-login.support' and the owner isn't yourbank.com at all, it's support, with yourbank.com and secure-login just tacked on in front as a costume. The part right before that first slash, and specifically the section right before the final dot-something, is the one that counts. Everything to the left of it can be written by anyone, for free, in seconds.

This is exactly what scammers lean on. A subdomain can be any word at all: 'apple-id.verify-account.info' has nothing to do with Apple, no matter how official the first word looks. The trick works because our eyes land on the familiar brand name at the start and stop reading right there, satisfied. The FBI's cybercrime reporting unit has had to warn people about this directly: scammers copy a legitimate site closely enough, including a domain that looks right at a glance, that visitors hand over names, addresses and banking details without noticing the swap.

Shorteners and lookalikes

Two more disguises are worth knowing. A link shortener replaces a long address with a short, meaningless code, which is handy and completely opaque: you cannot tell where it leads until you're already there. And a lookalike domain swaps one detail for another close enough to pass a quick glance, an extra word, a missing letter, an unfamiliar ending in place of the usual one. Britain's National Cyber Security Centre points to exactly this pattern in its guidance on shopping safely online, citing a domain built to be 'easily mistaken for a genuine' one as a common trap in fake stores and fake delivery pages alike.

A link can wear any brand's name. Only the address right before the first slash tells you who actually owns the door.

What the padlock is quietly not telling you

There's a second habit worth breaking: treating the little padlock or the 'https' at the start of an address as a stamp of trust. That icon has one job, and one job only: it confirms that whatever you type on that page travels there scrambled, so nobody snooping on the connection can read it in transit. It says nothing about who built the page or what they intend to do with what you type. A convincing fake page can be just as encrypted as your real bank, because the certificate that produces the padlock is cheap and quick to obtain for anyone, including the person who built the fake page an hour ago.

Put differently: encryption protects the pipe, not the destination. A scam site with a padlock is still a scam site, just one that locks the door behind you as you walk into it. Certificates that produce that little green icon used to be harder to get and cost real money, which made the padlock a rough proxy for a serious operation behind the site. That gap has closed. These days a fake storefront and a genuine bank can display the exact same icon, so the icon has stopped telling the two apart.

The habit that actually protects you

None of this requires special tools. Both the FBI's cybercrime unit and the UK's National Cyber Security Centre give the same simple advice for a suspicious link: don't follow it at all. Type the address you already trust directly into your browser, or open the app you know is genuine, instead of tapping the one that arrived in a text or an email. It costs an extra ten seconds. Reading the domain itself, right before that first slash, catches most of what a fast glance at the whole message would miss. It's a small habit, and it's the one that actually holds up against a convincing fake.

Topics : phishing links digital safety

Sources

Keyboard shortcuts

?Open this help
EscClose the panel or this help
1-3Pick an answer during the quiz
EnterNext case, once you've read the answer
TabMove from link to link: the whole site works by keyboard