How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide
Every click carries risk. A single malicious link can drain a bank account, install ransomware, or hand your credentials to an attacker on the other side of the world. Yet most people still click first and ask questions later. This guide walks you through exactly how to check if a link is safe before clicking, using free tools, browser features, and quick manual checks that take seconds.
Why Checking Links Before Clicking Matters
A safe link is one that leads to a legitimate destination, uses secure protocols, and does not attempt to deliver malware, harvest credentials, or redirect you to a fraudulent page. Verifying links before clicking is the single most effective habit for avoiding phishing, drive-by downloads, and identity theft.
According to industry reports, over 90% of successful cyberattacks begin with a phishing email or malicious link. Attackers rely on urgency, curiosity, and disguise. If you slow down for even ten seconds to inspect a URL, you neutralize the majority of these attacks before they start.
Common Threats Hidden Behind Links
- Phishing pages that mimic banks, social networks, or workplace logins
- Drive-by malware downloads triggered simply by visiting a page
- Credential harvesters disguised as document sharing or invoice links
- Cryptocurrency drainers that empty wallets after a single signature
- Tracking and fingerprinting scripts that follow you across the web
Step 1: Read the URL Carefully Before Clicking
The fastest way to check if a link is safe is also the simplest: hover over it and read the full URL. On desktop, hovering displays the destination in the bottom-left of your browser. On mobile, press and hold the link to preview it.
What to Look For in a URL
- The actual domain name. The real domain is the part immediately before the top-level domain (like .com or .org). In
https://accounts.google.com.security-check.ru, the true domain issecurity-check.ru, not Google. - Misspellings and lookalikes. Watch for
paypa1.com,arnazon.com, ormicros0ft.com. Attackers swap letters with numbers or use similar-looking Cyrillic characters. - Suspicious subdomains. Real companies rarely use subdomains like
login-verify-account.example.com. - HTTPS presence. A padlock icon and
https://mean the connection is encrypted, but not that the site is trustworthy. Many phishing sites now use HTTPS too. - Unusual top-level domains. Be cautious with free or rarely used TLDs like .tk, .ml, .zip, or .mov when they appear in unexpected contexts.
Step 2: Expand Shortened Links Before Visiting
Shortened links (bit.ly, t.co, tinyurl, and others) hide their final destination behind a redirect. This is convenient for legitimate use, but it also gives attackers cover. Before clicking any shortened link from an unknown source, expand it first.
Free Tools to Preview Shortened URLs
- CheckShortURL.com — reveals the final destination and shows a page preview
- Unshorten.It — expands the link and runs it against reputation databases
- URLScan.io — provides a full technical analysis, screenshot, and threat verdict
- Where Does This Link Go? — a quick preview tool with a clean interface
If you regularly use short links yourself, it helps to work with a shortener that publishes transparent analytics and does not hide destinations from recipients. Reputable platforms like Lunyb are designed with recipient trust in mind, and you can compare options in our 2026 buyer's guide to URL shorteners.
Step 3: Use a Link Scanner Before Clicking
A link scanner analyzes a URL against threat intelligence databases and returns a safety verdict without you having to visit the page. This is the most reliable single check you can perform.
Best Free Link Safety Checkers
| Tool | What It Checks | Best For |
|---|---|---|
| Google Safe Browsing | Phishing, malware, unwanted software | Quick verdict on most URLs |
| VirusTotal | 90+ antivirus engines and URL blocklists | Second-opinion scanning |
| URLScan.io | Live page render, DOM, network requests | Technical analysis and screenshots |
| PhishTank | Community-verified phishing database | Confirming known phishing URLs |
| Norton Safe Web | Reputation score and community reviews | Ecommerce and consumer sites |
| Sucuri SiteCheck | Malware, defacement, blocklist status | Checking suspected hacked sites |
How to Use VirusTotal in 30 Seconds
- Go to
virustotal.com - Click the URL tab
- Paste the suspicious link (do not click it)
- Press Enter and wait for the scan
- Review the detection ratio — anything flagged by multiple vendors is a strong warning sign
Step 4: Verify the Sender and Context
Even a technically clean URL can be dangerous if it arrived through a suspicious channel. Context is half the safety check.
Red Flags in the Message Around the Link
- Urgency: "Your account will be closed in 24 hours"
- Unexpected attachments paired with links
- Generic greetings like "Dear Customer" from a company that knows your name
- Mismatched sender addresses — a display name of "PayPal" but an email from a random Gmail address
- Requests for credentials, payment, or personal info through a link
- Grammar or formatting errors in what should be a professional message
When in doubt, contact the sender through a channel you already trust — a phone number from your bank card, a bookmarked website, or an in-app message — rather than replying to the message itself.
Step 5: Check the Domain's Age and Reputation
Legitimate businesses usually have domains that are years old, while phishing domains are often registered days or hours before an attack. A quick WHOIS lookup can tell you a lot.
How to Perform a WHOIS Check
- Visit
who.isorwhois.domaintools.com - Enter the domain (not the full URL)
- Look at the creation date — anything under 90 days deserves extra scrutiny
- Check the registrar and country — mismatches with the claimed brand are a warning sign
- Review whether contact info is redacted (common) or clearly fake (suspicious)
Step 6: Use Browser and DNS-Level Protection
Modern browsers and secure DNS resolvers block known malicious sites automatically. Turning these on gives you a safety net for the moments when you forget to check manually.
Built-in Browser Protections
- Chrome and Edge: Enable Enhanced Safe Browsing in privacy settings
- Firefox: Turn on "Block dangerous and deceptive content" under Privacy & Security
- Safari: Ensure "Fraudulent Website Warning" is active
- Brave: Ships with aggressive tracker and malware blocking by default
Encrypted DNS Services That Filter Threats
- Cloudflare 1.1.1.1 for Families — blocks malware and optional adult content
- Quad9 (9.9.9.9) — blocks known malicious domains at the DNS layer
- NextDNS — customizable filtering with detailed logs
- AdGuard DNS — combines ad blocking with threat protection
Configuring one of these on your router or device protects every browser and app automatically, without slowing down your connection.
Step 7: Sandbox Suspicious Links When You Must Investigate
Sometimes you genuinely need to see what's behind a link — for work, journalism, or research. In those cases, never click from your main device.
Safer Ways to Open a Suspect Link
- URLScan.io or Browserling — render the page in a remote sandbox and view a screenshot
- Any.run — interactive malware sandbox for advanced analysis
- A disposable virtual machine — spin up a VM you can discard after the visit
- A separate low-privilege browser profile with no saved passwords, cookies, or extensions
- Your phone in airplane mode is not safe — network-based malware still executes when reconnected
Quick Reference: The 10-Second Link Safety Checklist
- Hover and read the full URL — does the domain match the claimed brand?
- Is it a shortened link? Expand it first.
- Paste it into VirusTotal or Google Safe Browsing.
- Does the message create urgency or ask for credentials?
- Does the sender address match the claimed organization?
- Is the domain unusually new?
- Is HTTPS present — and does the certificate name match?
- Any misspellings, weird characters, or unfamiliar TLDs?
- If still unsure, open it in a sandbox instead of your main browser.
- When in doubt, don't click. Verify through a separate trusted channel.
Special Cases: Links in Different Places
Links in Email
Email remains the top phishing vector. Never trust the display text of a hyperlink — always hover to see the real destination. Enterprise users should also check whether the message passed SPF, DKIM, and DMARC authentication.
Links in SMS (Smishing)
Text messages carry extra risk because previews are short and the sender is easy to spoof. Delivery notifications, tax refund alerts, and bank verification messages are common smishing themes. When in doubt, open the carrier or bank app directly instead of tapping the link.
Links in Social Media and DMs
Compromised accounts often blast malicious links to friend lists. If a contact suddenly sends you a link with little context — especially with phrases like "is this you?" or "look what I found" — verify with them through another channel before clicking.
Links in QR Codes
QR codes are just URLs in visual form. Use a scanner app that previews the URL before opening it (most modern phone cameras do this). Be especially cautious with QR codes stuck on parking meters, restaurant tables, or public flyers — "quishing" is a growing attack vector.
Building Long-Term Link Safety Habits
Tools help, but habits keep you safe. The people who never fall for phishing aren't the most technical — they're the ones who pause. Bookmark the sites you visit often so you never rely on links from messages. Use a password manager, because it will refuse to auto-fill credentials on a lookalike domain, giving you a silent early warning. Turn on multi-factor authentication so a stolen password alone isn't enough. And if you share links yourself — for marketing, support, or personal use — choose a shortener with clean analytics and a good reputation, like the options compared in our Rebrandly review or shortener buyer's guide.
Frequently Asked Questions
Is a link safe if it has HTTPS and a padlock icon?
Not necessarily. HTTPS only means the connection between your browser and the server is encrypted. It says nothing about whether the site itself is legitimate. The majority of modern phishing pages now use HTTPS because free certificates are easy to obtain. Always verify the domain name in addition to the padlock.
What's the fastest free way to check if a link is safe?
Paste the URL into VirusTotal (virustotal.com). It scans the link against 90+ security engines in under 30 seconds and gives you a clear detection count. For a second opinion, run it through URLScan.io, which also shows a live screenshot of the page.
Can I get infected just by clicking a link without downloading anything?
Yes, though it's rarer than it used to be. Drive-by downloads exploit browser or plugin vulnerabilities to execute code the moment a page loads. Keeping your browser fully updated dramatically reduces this risk. Most modern attacks still require you to enter credentials or approve a download, but it's not safe to assume clicking alone is harmless.
Are shortened URLs like bit.ly links inherently dangerous?
No, shortened links are used constantly for legitimate marketing, social media, and analytics. The risk is that they hide the final destination. Treat shortened links from unknown senders with extra caution and expand them using a preview tool before clicking. Reputable shortening platforms actively police their networks for abuse.
What should I do if I already clicked a suspicious link?
Act quickly. Disconnect from the internet if you suspect a download started. Run a full antivirus scan. Change passwords for any accounts you may have entered credentials into, starting with email and banking. Enable multi-factor authentication if you haven't already. Watch bank and card statements for unusual activity, and consider a credit freeze if sensitive personal information may have been exposed.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Create Branded Short Links: The Complete 2026 Guide
Branded short links dramatically boost trust and click-through rates compared to generic shorteners. This step-by-step guide walks you through choosing a custom domain, connecting DNS, creating branded links, and tracking performance in 2026.
How to Check if Your Password Was Leaked in a Data Breach (2026 Guide)
Billions of passwords have leaked online — but checking if yours is one of them takes just two minutes with the right tools. This step-by-step guide shows you how to safely check for compromised credentials and lock down your accounts before attackers do.
How to Improve Your Phone's Security Score: A Complete 2026 Guide
Your phone holds your entire digital life, but most people never audit its security. This 10-step guide shows you exactly how to improve your phone security score in 2026—from OS updates and permissions to encrypted DNS, 2FA, and safer link handling.
How to Shorten a URL: The Complete 2026 Guide
Learn how to shorten a URL in seconds with this complete 2026 guide. Discover free tools, custom branded links, tracking, QR codes, and best practices for creating clean, professional short links.