facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··9 min read

Every day, billions of links travel through email inboxes, chat apps, and social feeds. Most are harmless, but a small percentage lead to phishing pages, malware downloads, or scam sites designed to empty your bank account. Knowing how to check if a link is safe before clicking is one of the most valuable digital literacy skills you can develop in 2026.

This guide walks you through the exact steps professionals use to vet suspicious URLs, including free tools, manual inspection techniques, and warning signs that should stop you from clicking altogether.

Why Checking Links Before Clicking Matters

A malicious link is a URL crafted to deliver harm the moment you visit it. That harm can include credential theft, drive-by malware installation, session hijacking, or redirection to a fake payment page. According to industry threat reports, more than 90% of successful cyberattacks begin with a single click on a deceptive link.

The stakes have risen because attackers now use AI to generate convincing phishing pages, clone brand websites pixel-for-pixel, and mask malicious destinations behind shortened URLs. Even tech-savvy users can be fooled if they don't take a few seconds to verify before clicking.

Common Risks of Clicking Unsafe Links

  • Phishing: Fake login pages that steal usernames and passwords.
  • Malware infection: Automatic downloads that install spyware, ransomware, or keyloggers.
  • Financial fraud: Fake checkout pages that capture credit card details.
  • Account takeover: Session cookie theft that bypasses two-factor authentication.
  • Identity theft: Data harvesting for later fraud or extortion.

Warning Signs of an Unsafe Link

Before running any tool, train your eye to catch obvious red flags. Most phishing links share visible patterns you can spot in under five seconds.

1. Misspelled or Look-Alike Domains

Attackers register domains that mimic trusted brands with subtle character swaps. Watch for:

  • paypa1.com instead of paypal.com (number 1 replacing letter l)
  • arnazon.com instead of amazon.com (rn instead of m)
  • micros0ft-support.com (zero instead of o, plus unnecessary hyphenation)
  • Cyrillic look-alikes such as аpple.com where the "a" is a foreign character

2. Suspicious Subdomains

A link like paypal.com.secure-login.xyz is not a PayPal link. The real domain is always the part immediately before the top-level extension (in this case, secure-login.xyz). Everything left of that is a subdomain the attacker controls.

3. Odd Top-Level Domains

Legitimate businesses generally use .com, .org, or country-specific TLDs. Be skeptical of financial or brand-related links ending in .xyz, .top, .click, .zip, or .mov unless you have a strong reason to trust them.

4. Urgency or Emotional Manipulation

Messages that demand you "click within 24 hours" or warn that your "account will be suspended" are engineered to bypass rational thinking. Legitimate companies rarely enforce clicks through panic.

5. Unexpected Attachments or Downloads

If hovering over a link reveals a direct file path ending in .exe, .scr, .zip, .iso, or .dmg, treat it as hostile until proven otherwise.

Step-by-Step: How to Check if a Link Is Safe

Follow these seven steps in order. The first three take seconds; the rest apply when you need deeper certainty.

  1. Hover before clicking. On desktop, place your cursor over the link without clicking. The true destination will appear in your browser's status bar or an overlay tooltip. On mobile, press and hold the link to preview the full URL.
  2. Read the domain carefully. Identify the root domain (the part right before the TLD) and confirm it matches the brand you expect.
  3. Check for HTTPS. A padlock icon means the connection is encrypted, but it does not guarantee the site is legitimate. Modern phishing sites almost always use HTTPS.
  4. Run the URL through a link scanner. Paste the URL into a trusted analyzer such as VirusTotal, Google Safe Browsing, URLVoid, or PhishTank. These check the link against dozens of threat databases.
  5. Expand shortened links. Services like CheckShortURL or Unshorten.it reveal where a shortened URL actually redirects, without visiting it.
  6. Search for the domain. A quick web search for the domain plus "scam" or "reviews" often surfaces warnings from other users.
  7. Verify with the source. If the link claims to be from your bank, employer, or a friend, contact them through a known channel to confirm they sent it.

Best Free Tools to Scan a Link in 2026

These tools analyze URLs against blacklists, sandbox them for behavioral analysis, and flag known phishing patterns. All are free for individual use.

ToolWhat It ChecksBest For
VirusTotalScans URL against 70+ antivirus and blacklist enginesComprehensive multi-engine verdict
Google Safe BrowsingGoogle's real-time malicious URL databaseQuick reputation check
URLVoidDomain reputation across 30+ blacklist servicesInvestigating unknown domains
PhishTankCommunity-verified phishing URLsConfirming phishing suspicions
URLScan.ioSandbox execution with screenshot and network traceAdvanced behavioral analysis
CheckShortURLExpands shortened URLs safelyRevealing hidden destinations

How to Use VirusTotal (Example Walkthrough)

  1. Go to virustotal.com.
  2. Select the "URL" tab.
  3. Paste the suspicious link into the input box.
  4. Press Enter and wait a few seconds for the scan to complete.
  5. Review the verdict: green ticks mean clean; red flags indicate detections. If more than one or two reputable engines flag the URL, avoid it.

How to Safely Inspect Shortened URLs

Shortened URLs from services like bit.ly, t.co, or tinyurl.com hide the real destination, which is convenient but potentially risky. Fortunately, most reputable shortening services offer preview features, and third-party expanders let you see where a link points without visiting it.

Methods to Reveal the Real Destination

  • Add a preview suffix. For bit.ly links, add a + at the end (e.g., bit.ly/abc123+) to see the destination and click statistics.
  • Use CheckShortURL or Unshorten.it. Paste the shortened URL and receive the full destination, screenshot, and safety rating.
  • Choose transparent shorteners. Reputable providers publish clear terms and don't allow spam. If you're creating short links yourself, using a trustworthy service like Lunyb ensures your recipients aren't scared off by unfamiliar domains. You can read our honest Lunyb review for details, or compare options in our 2026 URL shortener buyer's guide.

Manual Techniques for Advanced Users

When automated scanners aren't enough, these manual checks help you evaluate a link's trustworthiness.

WHOIS Lookup

A WHOIS query reveals when a domain was registered, by whom (when not privacy-protected), and where it is hosted. Domains registered within the last 30 days that impersonate major brands are almost always malicious. Use whois.domaintools.com or who.is for quick lookups.

Check the SSL Certificate

Click the padlock icon in your browser's address bar to inspect the certificate. A legitimate company will hold a certificate issued to its verified business name. A generic "Let's Encrypt" certificate on a bank-look-alike site is a red flag.

Analyze the Full URL Structure

Break the URL into its parts:

  • Protocol: http or https
  • Subdomain: anything before the main domain
  • Root domain and TLD: the actual site owner
  • Path and parameters: what page and data are being loaded

Long, random-looking parameter strings after a suspicious domain often carry tracking or exploit payloads.

Sandbox the Link

If you must open a link but aren't certain it's safe, use an isolated environment such as a disposable browser session, a virtual machine, or an online sandbox like URLScan.io or Any.Run. These render the page without exposing your real system.

How to Protect Yourself Beyond Link Checking

Link inspection is one layer of defense. Combine it with these practices for stronger protection.

Enable Browser and DNS Protections

  • Keep browser Safe Browsing or SmartScreen features enabled.
  • Use an encrypted DNS resolver such as Cloudflare 1.1.1.1 for Families or Quad9, which block known malicious domains at the network level.
  • Install a reputable ad and tracker blocker to reduce exposure to malvertising.

Keep Software Updated

Most drive-by malware exploits known vulnerabilities in outdated browsers, plugins, or operating systems. Enable automatic updates to close these gaps.

Use Strong Authentication

Even if you click a phishing link and enter credentials, hardware-based two-factor authentication (such as a passkey or security key) can prevent account takeover.

Back Up Important Data

Regular offline backups mean that even if ransomware slips through, you can recover without paying attackers.

What to Do If You Already Clicked a Suspicious Link

If you clicked before checking, don't panic. Take these steps immediately:

  1. Disconnect from the internet. This halts any active downloads or data exfiltration.
  2. Do not enter any information. Close the tab if a login or payment form appeared.
  3. Run a full antivirus scan. Use your primary security tool plus a second-opinion scanner such as Malwarebytes.
  4. Change passwords. Start with the account the link impersonated, then any accounts that share the same password.
  5. Enable multi-factor authentication on affected accounts if it wasn't already active.
  6. Monitor bank and email accounts for unauthorized activity for at least 30 days.
  7. Report the link to Google Safe Browsing, PhishTank, and the impersonated brand so others are protected.

Quick Reference: Safe vs. Suspicious Link Checklist

SignalLikely SafeLikely Suspicious
Domain spellingMatches brand exactlyContains typos or extra characters
TLD.com, .org, .gov, country codes.xyz, .top, .click, .zip
HTTPS padlockPresent with verified organizationPresent but generic certificate
Message toneInformational, no urgencyThreatens loss, demands quick action
Scanner verdictClean across all enginesFlagged by two or more services
Domain ageSeveral years oldRegistered in last 30 days

Frequently Asked Questions

Is a link with HTTPS always safe to click?

No. HTTPS only means the connection between your browser and the server is encrypted. Attackers routinely obtain free SSL certificates for phishing sites, so the padlock icon alone is not proof of legitimacy. Always verify the domain name alongside the padlock.

Can I get a virus just by clicking a link without downloading anything?

Yes, in some cases. "Drive-by" attacks exploit unpatched browser or plugin vulnerabilities to install malware silently on visit. Keeping your browser and operating system updated dramatically reduces this risk, but the safest habit is still to verify links before clicking.

Are shortened URLs inherently dangerous?

Not at all. Shortened URLs from reputable providers are widely used by legitimate businesses for cleaner links and click analytics. The risk comes from not knowing where any short link points. Use an expander tool for unfamiliar shortened links, and when creating your own, choose a trusted shortener so recipients feel confident clicking.

What is the fastest way to check if a link is safe?

Hover over the link to reveal its destination, then paste the URL into VirusTotal or Google Safe Browsing. This two-step process takes about 15 seconds and catches the vast majority of malicious links.

Should I click links in emails from companies I do business with?

Whenever possible, avoid it. Instead, open a new browser tab and navigate directly to the company's website by typing the address yourself. This eliminates the risk of clicking a spoofed link, even if the email looks perfectly authentic.

Final Thoughts

Learning how to check if a link is safe is a small habit with an outsized payoff. A five-second hover, a quick paste into a scanner, and a healthy skepticism toward urgent messages will neutralize the majority of online threats you'll encounter. Combine these habits with updated software, strong authentication, and encrypted DNS, and you'll be well ahead of the average internet user in 2026.

Stay curious, verify before you click, and remember: the extra seconds you spend checking a link are always cheaper than the hours you'd spend recovering from a compromised account.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles