Paste a link from a text, an email or a message and see where it actually goes, and what about it looks wrong.
You can paste the whole text message. We will find the link in it.
It can tell you what the address itself says. Which domain actually owns it, whether the name you recognise is really the owner or just a label, whether the characters are what they appear to be, and whether the link hides its destination.
It cannot tell you a link is safe. It does not open the link, follow redirects, or check anyone's list of known bad sites, because doing that would mean sending your link to a server. A brand new scam page on a perfectly ordinary looking domain will pass every check here. Nothing stood out is not the same as this is fine.
If you are unsure, the answer is always the same and it always works: do not tap it. Go to the company yourself, through their app, your own bookmark, or the number printed on your card.
This is the most reliable check there is, and you can do it without any tool at all.
yourbank.example/alerts/verify belongs to yourbank
yourbank.secure-verify.example/alerts belongs to secure-verify
yourbank-support.example a different domain anyone can buy
Tapping a link is usually not the moment things go wrong. Entering something is. If you did not type a password, a card number or a code, the realistic risk is low: close the page, and do not go back to it.
If you did enter something, move quickly. Change that password from a different device, starting with your email, then call your bank on the number printed on your card. There is a full walkthrough on the scam library page, including who to report it to.