Guide
Is this sign-in link safe? How to check a magic link
More and more sites email you a link instead of asking for a password. Here is how these links work, and how to check one before you click.
You type your email, and the site says “Check your inbox.” A moment later an email arrives with a button: Sign in, Log in to Slack or Confirm it’s you. That button is a magic link. Click it, and you are in.
Short answer: only click a sign-in link you just asked for. Before you click, check that it opens the site you are signing in to. If either is off, don’t click. Go to the site yourself and ask for a new link.
What a magic link is
A magic link is a sign-in link with a secret, one-time key inside it. Only your inbox gets the email, so opening the link proves the inbox is yours. That replaces the password.
- It usually works once.
- It expires quickly, often within 10 to 30 minutes.
- On many sites, whoever opens it is signed in. So never forward one, and never share a screenshot of it.
Sites call them different things: magic links, sign-in links, login links, “one-time links” or “Is this you?” emails. They all work the same way.
Why fake ones work
People expect these emails and click them fast. A fake one looks the same, but its button opens a copy of the real site. That copy asks for your password, a code or your card. Whatever you type goes to whoever made it.
How to check a sign-in link in five steps
- Did you just ask for it? If you did not just try to sign in, don’t click. Someone typed your email address, by mistake or on purpose. Without the link they can’t get in, so ignore the email.
- Check the sender’s address, not the name. The name can say anything. Look at the address after the @.
- See where the button goes, without clicking. In most mail apps, rest the pointer on the button and the address appears. In Gmail in a browser, it shows in the bottom corner of the window. Or Control-click the button, choose Copy Link and paste it into a note.
- Read the site name the right way. Find the first single slash after
https://. The site is what comes just before it, read from the right. See the examples below. - After you click, look before you type. A real magic link signs you in. If the page asks for your password or card instead, close it.
Reading a link: real or not?
The site is the last two parts of the name before the first single slash. For addresses like bank.co.uk, it is the last three.
Say you asked Notion for a sign-in link:
https://www.notion.so/loginwithemail?token=…opens notion.so. That’s Notion.https://notion.so.sign-in.example/verifyopens sign-in.example. “notion.so” is only the start of the name.https://notion-so.com/loginopens notion-so.com. A lookalike name.https://example.com/r?u=notion.soopens example.com. Notion only appears after the slash.
One honest catch: some real emails send links through a mailing service first, so the address can look unrelated even when the email is genuine. You can’t tell these apart by looking. When you are not sure, open the site yourself and ask for a new link.
If you already clicked
- You typed nothing: close the page. Opening a page alone rarely does harm.
- You typed a password: change it on the real site now, and anywhere else you use it. Turn on two-step sign-in.
- You typed a code or card details: contact the service or your bank, and check the account for devices or payments you don’t know.
How CodeCatch helps on a Mac
I built CodeCatch to catch sign-in codes, and sign-in links come with the same chore. It reads your Apple Mail, Gmail and other mail, and shows each new sign-in link next to your codes. You see the site it opens before you decide.
- It never opens a link by itself. You click Open Link or Copy Link.
- It shows the site the link opens, read the right way.
- If that site differs from the sender’s address, it warns you, as in the picture above.
- It picks the sign-in button only, not unsubscribe or help links, and only secure
httpslinks. - Password reset links get the same check.
It is a hint, not a guarantee. The warning compares the link with the sender’s address, and a sender’s address can be faked. Step 1 still matters most: only click links you asked for.
Questions
Are magic links safer than passwords?
In one way, yes: there is no password to guess, reuse or leak. But your email inbox becomes the key to the account. Protect your email with a strong password and two-step sign-in.
Why did I get a sign-in link I didn’t ask for?
Someone entered your email address on that site, by mistake or on purpose. They can’t sign in without opening the link in your inbox. Don’t click it. Just delete the email.
How long does a magic link last?
Usually minutes, not hours. Many expire within 10 to 30 minutes, and most work only once. If one has expired, ask the site for a new one.
Can I check a link without clicking it?
Yes. Rest the pointer on the button to see the address, or Control-click it and choose Copy Link. Then read the site name as shown above.
Is it safe to forward a sign-in link?
No. On many sites, whoever opens the link is signed in to your account. Treat it like a password.

