For you and your family

How to check if a link is fake or safe (WhatsApp, SMS, email)

To check if a link is fake, find its real domain (the part just before the first single slash) and confirm it is exactly the official one; treat short links, odd spellings and APK files as warning signs. When in doubt, paste the link into a free checker before opening it, and remember that a padlock (https) does not mean a site is safe.

By the Secuvexa team, I.T. Experts, Gujarat · Updated

To check if a link is fake, look at the real domain name, not the words around it. The real domain is the part just before the first single "/" after https://, and it must be exactly the official one (for example onlinesbi.sbi or incometax.gov.in), with nothing extra in front pretending to be the brand. If the link is shortened, ends in .apk, has a misspelt name, or comes with a threat or a prize, treat it as unsafe and check it with a link checker before you open it.

Quickest check: paste the link into our free Secuvexa link checker. It looks at the link text and a threat database, and flags look-alike bank, UPI and government domains, shorteners, APK links and punycode tricks. No checker catches everything, so still use the steps below.

How to read a URL: find the real domain in 3 steps

Take this example: https://sbi.co.in.kyc-update.top/login

  1. Remove the start: ignore https:// (or http://).
  2. Stop at the first single slash: you get sbi.co.in.kyc-update.top. That part is the hostname.
  3. Read it from the right: the last two parts, kyc-update.top, are the real domain. Everything to the left (sbi.co.in.) is just a subdomain the scammer created. This site belongs to whoever owns kyc-update.top, not to SBI.

For Indian addresses that end in a two-part ending such as .co.in, .gov.in or .org.in, read the last three parts: in www.rbi.org.in the domain is rbi.org.in.

Link (example, not real)Real domainVerdict
https://www.incometax.gov.in/iec/foportal/incometax.gov.inOfficial income tax site
https://incometax.gov.in-refund.co/claimin-refund.coFake: ".gov.in" is only part of a subdomain
https://paytm-kyc-help.xyzpaytm-kyc-help.xyzFake: brand name plus extra words on a random domain
https://onlinesbi.coonlinesbi.coSuspicious: wrong ending for a bank
https://bit.ly/3xYzAbcbit.ly (a shortener)Unknown: you cannot see where it goes

Fake link kaise check kare: 7 warning signs

  1. Subdomain trick. The brand appears at the start (sbi., amazon., gov.in.) but the real domain at the end is something else.
  2. Look-alike spelling. paytrn instead of paytm (r + n looks like m), 0 instead of o, 1 or l instead of i, extra hyphens such as hdfc-bank-netbanking.
  3. Punycode. Some letters from other alphabets look identical to English letters (a Cyrillic "а" vs an English "a"). Such domains are written in a coded form starting with xn--. If you see xn-- in a link that claims to be a bank or brand, do not open it.
  4. Shortened links. bit.ly, tinyurl.com and similar hide the destination. Banks and government departments rarely send short links for KYC or payments.
  5. Strange endings. Indian government sites use .gov.in or .nic.in. Be extra careful with cheap endings often used for scams, such as .xyz, .top, .online, .click, or an IP address like http://45.12.x.x/.
  6. APK downloads. A link that downloads a file ending in .apk installs an app from outside the Play Store. See the APK section below.
  7. The message itself. Urgency ("blocked today"), fear (police, power cut), or greed (prize, cashback, part-time job) are the scammer's real weapons.

Https does NOT mean safe

The padlock and https only mean the connection between your phone and that website is encrypted, so others on the network cannot read it. They say nothing about who owns the site. Scammers get free https certificates for fake bank pages within minutes. So a padlock is necessary for any site where you type a password, but it is never proof that the site is genuine. A plain http:// link asking for login details is a definite red flag.

Free tools to check a link before opening it

  • Secuvexa link checker: built for Indian scams (KYC, bank, UPI, courier, electricity bill links). Paste the link; you get a verdict and reasons in plain English.
  • Google Safe Browsing site status: shows whether Google currently lists a site as dangerous. "No unsafe content found" only means Google has not flagged it yet; new scam sites are often not listed.
  • VirusTotal: checks a URL against many security vendors' lists and shows the final address after redirects. Do not submit links that contain your personal details or login tokens, because submitted URLs can be visible to the security community.

If you want to check a whole website you own, not a single link, use our website security scanner or read how to check if a website is safe.

APK links on WhatsApp and SMS

An APK is an Android app file. Scammers send them as "wedding invitation.apk", "RTO challan.apk", "SBI KYC.apk" or "electricity bill.apk". Once installed, such apps can read your SMS (including OTPs), show fake bank screens and even send the same file to your contacts. Police have warned about fake traffic challan APKs (The Tribune, July 2025) and fake wedding invitations sent as APKs (The Tribune, November 2025), noting that real invitations come as images or PDFs.

Simple rule: never install an APK sent in a message, even from a friend or relative (their phone may already be infected). Install apps only from the Google Play Store or Apple App Store, and keep "Install unknown apps" switched off.

QR codes are links too

A QR code can hide the same fake link, or open a UPI payment screen. Before you act:

  • Use your camera or scanner app's preview to read the address before tapping, and apply the domain checks above.
  • If a QR opens your UPI app, read the name and amount. Remember that you never scan a QR or enter your PIN to receive money.
  • In shops and parking areas, check that a sticker has not been pasted over the original QR.

Clicked a fake link? What to do now

  1. Only opened it, entered nothing: close the tab. Do not download anything it offers. Your risk is usually low.
  2. Entered a password: change that password right away, and anywhere else you used it. Turn on two-step verification.
  3. Entered card, bank details or an OTP: call your bank's official helpline to block the card or net banking, and call 1930 if any money has moved. Our first-hour fraud guide has the full steps.
  4. Installed an app: switch on flight mode, uninstall the app, and check for apps with accessibility, SMS or "display over other apps" permission (see risky app permissions). Then check WhatsApp linked devices.
  5. Report the link and the sender on Chakshu at sancharsaathi.gov.in.

Examples of common bank and KYC scam texts are in our guide to KYC fraud messages.

Frequently asked questions

Does https or a padlock mean a website is safe?

No. The padlock only means the connection is encrypted. Scammers get free https certificates for fake sites in minutes, so a fake bank page can show a padlock too.

Is it safe to just open a link to see what it is?

Opening a link on an updated phone is usually not enough to hack it, but the page can trick you into entering details, downloading an APK or approving a payment. It is safer to check the link first and never type passwords or OTPs on a page you reached from a message.

How do I check a short link like bit.ly without opening it?

Do not open it. Paste it into a checker: VirusTotal visits the link and its report shows the final address it leads to, and Secuvexa's link checker flags shorteners as a risk. If you still cannot tell where it goes, ask the sender for the full official link.

Fake link kaise check kare?

Link mein asli domain dekhiye, spelling dhyan se padhiye, .apk wali file kabhi mat kholiye, aur shak ho to link ko kholne se pehle Secuvexa link checker ya Google Safe Browsing par check kijiye.

I clicked a fake link. What should I do?

If you only opened it, close the tab and clear recent browsing data. If you entered a password, change it; if you entered bank details or an OTP, call your bank and 1930 immediately; if you installed an app, uninstall it and check its permissions.

This guide is general information, not legal advice. If you have lost money to fraud, call 1930 immediately or report at cybercrime.gov.in.