facebook-pixel

How to Check if a Link Is Safe Before Clicking: The 2026 Guide

L
Lunyb Security Team
··9 min read

Every day, billions of links are shared through email, social media, and messaging apps — and a significant percentage of them lead to phishing pages, malware downloads, or scam sites. Knowing how to check if a link is safe before clicking has become one of the most essential digital literacy skills of 2026. This guide walks you through the exact steps, tools, and warning signs security professionals use to verify URLs in seconds.

Why Checking Links Before Clicking Matters

A single click on a malicious link can compromise your passwords, drain your bank account, or install ransomware on your device. Attackers rely on urgency, curiosity, and trust to trick users into clicking without thinking. According to recent industry reports, phishing remains the number one cause of data breaches worldwide, with over 90% of successful cyberattacks starting with a suspicious link.

The good news: nearly all of these attacks can be avoided with a few seconds of verification. You don't need to be a cybersecurity expert — you just need to know what to look for and which free tools to use.

What Makes a Link Dangerous?

A dangerous link is any URL that leads to a website designed to harm you, steal your information, or manipulate your device. Common categories include:

  • Phishing links — fake login pages that mimic banks, social networks, or workplaces.
  • Malware droppers — pages that automatically download infected files.
  • Drive-by exploits — sites that abuse browser vulnerabilities on visit.
  • Scam and fraud sites — fake shops, crypto giveaways, or investment traps.
  • Tracking and data-harvesting links — URLs designed to fingerprint you or leak personal data.

10 Warning Signs That a Link Might Be Unsafe

Before running any tool, scan the link with your own eyes. Most malicious URLs give themselves away if you know what to spot.

  1. Misspelled domain names — like paypa1.com, arnaz0n-support.net, or microsofft.com.
  2. Suspicious subdomains — such as paypal.com.login-security.xyz (the real domain is login-security.xyz).
  3. Unusual top-level domains — TLDs like .zip, .mov, .click, or .tk are heavily abused.
  4. Excessive hyphens or numbers — e.g., secure-login-bank-verify-2026.com.
  5. Urgency or fear language — "Your account will be closed in 24 hours!"
  6. Unexpected shortened URLs from unknown senders.
  7. Mismatched anchor text — the visible text says one thing, but hovering reveals another destination.
  8. No HTTPS padlock — though HTTPS alone doesn't guarantee safety, its absence is a red flag on any login page.
  9. Requests for sensitive data immediately after clicking (passwords, SSN, card numbers).
  10. Attachments disguised as links ending in .exe, .scr, .iso, or .js.

How to Check if a Link Is Safe: 7 Reliable Methods

1. Hover Before You Click

On desktop, hover your mouse over any link without clicking. The real destination appears at the bottom of your browser or in a tooltip. On mobile, press and hold the link to preview the full URL. If the visible text says "amazon.com" but the actual URL points to bit.ly/xY7z or a random domain, don't click.

2. Inspect the Domain Carefully

Read the domain from right to left. The most important part is the last section before the first single slash. For example, in https://secure.paypal.com.login-fix.ru/verify, the actual domain is login-fix.ru, not PayPal. Attackers routinely add trusted brand names as subdomains to fool casual readers.

3. Use a Free URL Scanner

Copy the link (right-click → Copy link address) and paste it into a trusted online scanner. These services check the URL against dozens of threat intelligence databases without you having to visit it.

  • VirusTotal (virustotal.com) — scans against 70+ antivirus engines.
  • Google Safe Browsing Transparency Report — checks Google's malware and phishing database.
  • URLVoid — aggregates reputation data from multiple blacklists.
  • PhishTank — community-driven phishing URL database.
  • Sucuri SiteCheck — scans for malware, defacements, and blacklist status.

4. Expand Shortened URLs Before Visiting

Short links from services like bit.ly, t.co, tinyurl, or custom shorteners hide the true destination. Use an expander to preview where they lead:

  • CheckShortURL.com
  • Unshorten.it
  • ExpandURL.net

Reputable shortener platforms — including Lunyb — publish transparent redirection information and don't cloak destinations, which is why many privacy-conscious teams prefer them. For a broader comparison of trustworthy providers, see our 2026 buyer's guide to URL shorteners.

5. Check Domain Age and WHOIS Data

Legitimate businesses usually own domains for years. Phishing sites are often days or hours old. Look up a domain using WHOIS lookups on:

  • whois.domaintools.com
  • who.is
  • ICANN Lookup

If a "bank" domain was registered three days ago through a privacy-shielded registrar in an unrelated country, walk away.

6. Preview the Page in a Sandbox

If you absolutely must see what a link contains, open it in a sandboxed environment where nothing can be installed on your real device. Free tools include:

  • urlscan.io — takes a screenshot, records requests, and flags suspicious behavior.
  • Browserling — remote browser preview.
  • Any.Run — interactive malware sandbox.

7. Rely on Browser and OS Protections

Modern browsers (Chrome, Firefox, Edge, Safari) include built-in Safe Browsing warnings. Keep them enabled. Combine this with:

  • Encrypted DNS providers like Cloudflare 1.1.1.1 or Quad9, which block known malicious domains at the network level.
  • An updated operating system and browser.
  • A reputable endpoint security suite with web protection.

Comparison: Free Link Safety Tools

ToolBest ForSpeedDepth of AnalysisCost
VirusTotalMulti-engine malware checkFastHighFree
urlscan.ioVisual sandbox previewMediumVery HighFree
Google Safe BrowsingQuick reputation checkInstantMediumFree
URLVoidBlacklist aggregationFastMediumFree
PhishTankKnown phishing URLsInstantFocusedFree
Sucuri SiteCheckWebsite malware/injection scansMediumHighFree tier

Special Cases: Emails, SMS, QR Codes, and Social Media

Email Links

Email is still the #1 phishing channel. Before clicking any link in an email:

  1. Verify the sender's full email address, not just the display name.
  2. Check whether the message tone matches previous legitimate communication.
  3. Never click "unsubscribe" links in obvious spam — they often confirm your address to attackers.
  4. When in doubt, open a new browser tab and navigate to the site manually.

SMS and Messaging Apps ("Smishing")

Text-message scams surged sharply between 2023 and 2026. Common lures include fake delivery notifications, toll-road fines, and bank alerts. Rules of thumb:

  • Legitimate couriers and banks rarely send clickable links via SMS.
  • Never enter payment info on a page reached from a text message.
  • Forward suspicious SMS to 7726 (SPAM) in most countries.

QR Codes ("Quishing")

Attackers place malicious QR codes on parking meters, restaurant tables, and posters. Before scanning:

  • Use a QR scanner that shows the URL before opening it.
  • Be extra cautious with QR stickers that appear placed over an original code.

Social Media Links

Compromised accounts frequently DM shortened links to contacts. If a friend sends an out-of-character message with only a link, verify through another channel before clicking.

What to Do If You Already Clicked a Suspicious Link

If you clicked before checking, don't panic — but act quickly:

  1. Disconnect from Wi-Fi or mobile data if you suspect a download started.
  2. Do not enter credentials or personal data on the loaded page.
  3. Close the tab and clear browser cache and cookies for that session.
  4. Run a full antivirus/anti-malware scan.
  5. Change passwords for any account you may have entered credentials into, starting with email and banking.
  6. Enable two-factor authentication everywhere possible.
  7. Monitor your bank and credit accounts for the next 30–90 days.
  8. Report the URL to Google Safe Browsing, PhishTank, and your country's cybercrime authority.

Best Practices for Long-Term Link Safety

Building safe habits reduces risk far more than any single tool. Adopt these practices:

  • Use a password manager — it won't auto-fill credentials on look-alike domains.
  • Enable two-factor authentication (preferably via an authenticator app or hardware key).
  • Keep your browser and OS updated automatically.
  • Use encrypted DNS (DNS-over-HTTPS) to filter known malicious domains at the network layer.
  • Train family members and colleagues — phishing awareness is a team sport.
  • When creating your own short links for marketing or sharing, choose reputable platforms that offer link scanning, custom branded domains, and analytics. Our reviews of Rebrandly and Lunyb compare the safety features of leading options.

Quick Checklist: 30-Second Link Verification

Print or bookmark this checklist for a rapid daily routine:

  1. Hover to reveal the true destination.
  2. Read the domain right-to-left — is it really who it claims to be?
  3. Expand shortened URLs.
  4. Paste into VirusTotal or urlscan.io if uncertain.
  5. Check for urgency, fear, or reward language in the message.
  6. When in doubt, navigate to the official site manually.

Frequently Asked Questions

Is a link with HTTPS always safe?

No. HTTPS only means the connection is encrypted between your browser and the server — it does not guarantee the site itself is legitimate. Attackers routinely obtain free SSL certificates for phishing domains. Always verify the domain name, not just the padlock icon.

Can I get hacked just by clicking a link without entering anything?

In most cases, simply visiting a page is not enough to compromise a fully patched device. However, drive-by exploits targeting outdated browsers, plugins, or operating systems do exist. Keeping software updated dramatically reduces this risk. Downloads that start automatically should always be canceled and deleted.

Are shortened URLs always dangerous?

No — link shorteners are widely used by legitimate businesses, publishers, and marketers for tracking and cleaner sharing. The risk depends on the sender, not the shortener. Reputable services publish transparent redirect chains and scan destinations. Always expand a short URL before clicking if you don't fully trust the source.

What's the fastest way to check a link on mobile?

Press and hold the link to preview the full URL. If it looks suspicious, copy it (don't open it) and paste it into VirusTotal or urlscan.io in your browser. Many mobile security apps also include a built-in link checker.

Should I report suspicious links I receive?

Yes. Reporting helps protect others. Forward phishing emails to reportphishing@apwg.org, SMS to 7726, and submit URLs to Google Safe Browsing and PhishTank. If you were targeted at work, notify your IT or security team immediately.

Final Thoughts

Learning how to check if a link is safe takes only a few minutes to master, but it can save you from years of financial and emotional damage. Combine visual inspection, free scanning tools, and strong browser hygiene, and you'll neutralize the vast majority of link-based attacks before they ever reach you. Bookmark the tools above, share this checklist with your team, and make link verification a reflex — not an afterthought.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles