facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··9 min read

Every day, millions of people click links without thinking twice — and cybercriminals know it. A single malicious click can install malware, steal your passwords, drain your bank account, or hand over your identity. The good news? Checking whether a link is safe takes only seconds once you know how.

This guide walks you through every reliable method to verify a link before you click, from quick visual inspections to advanced scanning tools. Whether the link came from an email, a text message, social media, or a shortened URL, you'll finish this article knowing exactly how to spot the dangerous ones.

Why Link Safety Matters More Than Ever in 2026

A malicious link is a URL designed to deceive you into visiting a harmful destination — typically a phishing page, a malware download, or a fraudulent site that harvests personal data. According to industry reports, phishing attacks now account for more than 80% of reported security incidents, and shortened or obfuscated links are among the most common delivery methods.

Attackers have grown sophisticated. Fake login pages now mirror Microsoft, Google, and banking portals pixel-for-pixel. AI-generated phishing emails read fluently and personally. That means relying on "gut feeling" is no longer enough — you need a checklist.

10 Ways to Check if a Link Is Safe Before Clicking

Here are the most effective methods, ordered from fastest to most thorough. You don't need to use all of them every time — but for any link you didn't personally request, apply at least three.

1. Hover Over the Link to Preview the Real URL

On desktop, hover your cursor over the link without clicking. The true destination appears in the bottom-left corner of your browser or email client. On mobile, press and hold the link (don't tap) to see a preview.

Red flag: the visible link text says paypal.com but the actual URL points to paypal-secure-login.ru. Legitimate companies never route logins through unrelated domains.

2. Inspect the Domain Carefully

The domain is the part right before the first single slash after "https://". Read it from right to left. In https://accounts.google.com.verify-login.co/, the real domain is verify-login.co, not Google.

Watch for:

  • Misspellings: arnazon.com, micros0ft.com, faceb00k.com
  • Extra words: apple-support-verify.com
  • Unusual TLDs on brand names: netflix.top, chase.click
  • Unicode lookalikes (homoglyph attacks) using Cyrillic letters that look like Latin ones

3. Use a Free Link-Scanning Service

Paste the suspicious URL into a trusted scanner before visiting. These tools check the link against threat databases and sandbox it in a virtual environment.

ScannerWhat It ChecksCost
VirusTotal70+ antivirus engines, URL reputationFree
URLVoid30+ blocklists, domain age, WHOISFree
Google Safe BrowsingGoogle's threat databaseFree
PhishTankCommunity-verified phishing URLsFree
Sucuri SiteCheckMalware, blacklists, injected codeFree
urlscan.ioLive sandbox, screenshots, redirectsFree

4. Expand Shortened Links Before Visiting

Shortened URLs (bit.ly, t.co, tinyurl, and others) hide the real destination. That's convenient for legitimate sharing, but also useful for attackers. Before clicking any short link, expand it using an unshortener like CheckShortURL, Unshorten.it, or ExpandURL.net.

Reputable shortening platforms — such as Lunyb — apply automated malware and phishing scans to every link created on their system, which adds an extra layer of protection for both link creators and recipients. If you want to compare privacy-friendly options, see our 2026 buyer's guide to URL shorteners.

5. Check the HTTPS Padlock — But Don't Trust It Blindly

HTTPS (the padlock icon) means the connection is encrypted, not that the site is trustworthy. Over 80% of phishing sites now use HTTPS because free certificates are trivial to obtain. Treat the padlock as necessary but not sufficient — a missing padlock is a clear warning, but the presence of one proves nothing about the site's intentions.

6. Look Up the Domain Age with WHOIS

Legitimate brands own their domains for years or decades. Phishing domains are usually registered within the last 30–90 days. Use a WHOIS lookup tool (who.is, ICANN Lookup, or DomainTools) to see:

  1. When the domain was registered
  2. Who registered it (often hidden behind privacy services on scam sites)
  3. Which registrar was used
  4. When it expires (scam domains often have very short registration periods)

A domain registered two weeks ago claiming to be your bank is a screaming red flag.

7. Read the Full URL Structure

Long, cluttered URLs with random strings, multiple subdomains, or suspicious query parameters often signal trouble. Learn to break down a URL:

  • Protocol: https://
  • Subdomain: www or mail
  • Domain: example
  • TLD: .com
  • Path: /login
  • Parameters: ?redirect=...

Be especially cautious of open redirects like https://legit.com/redirect?url=https://malicious.com. The link starts on a real domain but bounces you to a hostile one.

8. Verify the Source and Context

Ask yourself:

  1. Was I expecting this message?
  2. Does the sender's email address match the organization exactly?
  3. Is there urgency, threats, or unusually good offers designed to rush me?
  4. Does the greeting feel generic ("Dear Customer") when it should be personalized?
  5. Are there spelling or grammar errors uncharacteristic of the supposed sender?

When in doubt, contact the company directly using a phone number or URL you look up independently — never one provided in the message itself.

9. Use Browser and Endpoint Protection

Modern browsers (Chrome, Firefox, Edge, Safari, Brave) include built-in phishing and malware protection powered by continuously updated threat feeds. Make sure these features are enabled:

  • Chrome: Enhanced Safe Browsing under Privacy and security
  • Firefox: Deceptive Content protection under Privacy & Security
  • Edge: Microsoft Defender SmartScreen
  • Safari: Fraudulent Website Warning

Pair browser protection with reputable endpoint security software and encrypted DNS (like Cloudflare 1.1.1.1 or Quad9), which blocks known malicious domains at the network level before your browser even loads them.

10. Open Suspicious Links in a Sandbox

If you absolutely must visit a questionable link, use an isolated environment:

  • urlscan.io — renders the page in a remote sandbox and shows you a screenshot without ever loading it on your device
  • Browserling or Browser Sandbox — cloud-based browsers
  • A virtual machine (VirtualBox, VMware) — for deeper investigation

Warning Signs of a Malicious Link Checklist

Use this quick checklist any time a link makes you hesitate. Two or more matches means don't click.

  • ☐ Misspelled or lookalike domain
  • ☐ Unusual TLD (.top, .click, .zip, .xyz) attached to a well-known brand
  • ☐ Excessive subdomains or hyphens
  • ☐ Shortened URL from an unknown sender
  • ☐ Urgent, threatening, or too-good-to-be-true language
  • ☐ Domain registered within the last 90 days
  • ☐ Mismatch between visible link text and actual URL
  • ☐ Requests login credentials, payment info, or downloads on arrival
  • ☐ Sent from a public email domain claiming to be a corporation
  • ☐ Grammatical errors or awkward phrasing

Special Cases: Where Malicious Links Hide

Emails and Text Messages (Phishing and Smishing)

Email remains the top delivery vector, but SMS phishing ("smishing") is growing fast. Fake delivery notifications from UPS, FedEx, USPS, and DHL are especially common. If a text asks you to "reschedule delivery" or "pay a small customs fee," go directly to the courier's official app or website instead.

Social Media DMs

Compromised accounts frequently send "Is this you in this video?" links or fake giveaway announcements. Even messages from real friends can be malicious if their account was hacked. Verify through another channel before clicking.

QR Codes

QR codes are just links in visual form — and "quishing" (QR phishing) is on the rise. Before scanning, cover the code with your hand and check for a physical sticker placed over a legitimate one. After scanning, review the URL preview your phone displays before opening it.

Search Engine Ads

Attackers buy sponsored ads impersonating brands like Amazon, banking apps, and popular software downloads. Always scroll past ads to organic results, or type the known URL directly into your address bar.

What to Do If You Already Clicked a Suspicious Link

Don't panic — quick action limits the damage. Follow these steps in order:

  1. Disconnect from the internet to prevent data exfiltration and stop any active download.
  2. Do not enter any information if a login or payment form appeared. Close the tab immediately.
  3. Run a full antivirus and anti-malware scan using tools like Malwarebytes, Windows Defender, or Bitdefender.
  4. Change passwords for any account you may have entered credentials into, starting with email and banking. Use unique passwords per site.
  5. Enable two-factor authentication everywhere it's supported.
  6. Monitor financial statements for unusual activity over the following weeks.
  7. Report the link to Google Safe Browsing, PhishTank, and the impersonated organization so others are protected.
  8. Consider a credit freeze if sensitive personal data (SSN, ID numbers) may have been exposed.

Building Long-Term Habits

The best defense is a slower click. Train yourself to pause for two seconds before every unfamiliar link and ask: "Do I actually know where this goes?" Combine that habit with:

  • A password manager that autofills only on legitimate domains — a subtle but powerful phishing detector
  • Regular software and browser updates
  • Encrypted DNS at the router or device level
  • Separate email accounts for banking, shopping, and newsletters
  • Periodic security check-ins on your Google and Apple accounts

If you frequently share or receive shortened links, choose platforms that publish transparent security practices and scan every URL at creation. Our 2026 shortener comparison and Rebrandly review break down which providers do this well.

Frequently Asked Questions

Is it dangerous to just click a link without entering anything?

Yes, it can be. Some malicious pages exploit browser vulnerabilities to install malware simply by loading ("drive-by downloads"). Others fingerprint your device, expose your IP address, or auto-download files. Not entering data reduces the risk dramatically but doesn't eliminate it, which is why scanning links first is safer than clicking and hoping.

Are all shortened URLs unsafe?

No. Shortened links are a legitimate tool used by marketers, journalists, and businesses worldwide. The risk comes from the fact that the destination is hidden. Use an unshortener when the sender is unknown, and prefer shortening services that scan URLs for malware — like Lunyb — over anonymous, unmoderated shorteners.

What's the single most reliable way to check a link?

Combine two methods: inspect the domain manually (reading right-to-left before the first single slash), then paste it into VirusTotal or urlscan.io for a second opinion. This two-step check catches the vast majority of phishing attempts in under 30 seconds.

Can antivirus software catch every malicious link?

No security tool catches everything. Zero-day phishing pages can slip past antivirus and browser filters for hours or days before being blacklisted. Layered defense — cautious habits, browser protection, encrypted DNS, endpoint security, and link scanners — is far more effective than relying on any single tool.

How do I report a phishing link once I've identified one?

Report to Google Safe Browsing (safebrowsing.google.com/safebrowsing/report_phish/), PhishTank (phishtank.org), the Anti-Phishing Working Group (reportphishing@apwg.org), and the impersonated brand's abuse address (usually abuse@companyname.com). If you're in the US, also file a report with the FTC at reportfraud.ftc.gov. Reporting helps blocklists update faster and protects thousands of other users.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles