facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Every day, billions of links are shared across email, social media, and messaging apps — and a surprising number of them lead somewhere they shouldn't. Phishing pages, malware downloads, credential harvesters, and scam sites all rely on one thing: you clicking without checking. The good news is that verifying a link's safety takes less than 30 seconds once you know what to look for.

This guide walks you through exactly how to check if a link is safe before clicking, from quick visual inspections to professional-grade scanning tools. Whether you received a suspicious email, a shortened URL from a stranger, or just want to build safer browsing habits, these methods work on any device.

Why Checking Links Before Clicking Matters

A single malicious click can compromise your passwords, drain a bank account, or install ransomware on your device. According to industry reports, phishing remains the number one attack vector globally, and shortened or disguised URLs are involved in the majority of successful campaigns.

The threats hiding behind a bad link typically fall into four categories:

  • Phishing pages that mimic real login screens to steal credentials.
  • Drive-by malware that installs automatically when the page loads.
  • Scam and fraud sites designed to trick you into sending money or personal data.
  • Tracking and fingerprinting pages that profile you without consent.

Checking a link is your last line of defense before any of these can reach you.

Quick Visual Checks You Can Do in 10 Seconds

Before pulling out any tools, most dangerous links reveal themselves through obvious visual clues. Train your eye to spot these red flags first.

1. Read the Domain Carefully

The domain is the part between https:// and the first single slash — for example, lunyb.com in https://lunyb.com/dashboard. Attackers love to register lookalike domains such as paypa1.com, arnazon-support.net, or micros0ft-login.co. Read the domain letter by letter and check for:

  • Numbers substituted for letters (0 for o, 1 for l, 5 for s).
  • Extra hyphens or words (like -secure, -login, -verify).
  • Unusual top-level domains (.zip, .top, .xyz on a supposedly big brand).
  • Subdomains that hide the real destination, like paypal.com.secure-login.ru — the real domain here is secure-login.ru.

2. Hover Before You Click

On desktop, hover your mouse over any link without clicking. The real destination appears in the bottom-left corner of your browser or email client. On mobile, press and hold the link to see a preview. If the visible text says one thing but the URL points somewhere else entirely, that's a major warning sign.

3. Check for HTTPS — but Don't Trust It Alone

A padlock icon and https:// mean the connection is encrypted, not that the site is legitimate. Modern phishing sites almost always use HTTPS because free certificates are trivial to get. Treat HTTPS as a baseline, not proof of safety.

How to Check if a Link Is Safe Using Free Online Scanners

Link scanners are websites that analyze a URL against threat databases, sandbox it in a virtual browser, and report back what they find. They're the most reliable way to check a link without visiting it yourself.

Here's the process:

  1. Copy the link without clicking it — right-click and select "Copy link address" on desktop, or long-press and choose "Copy link" on mobile.
  2. Open a scanner in a new tab (see comparison below).
  3. Paste the URL into the scanner's input field.
  4. Wait for the report — most scanners return results in 5 to 30 seconds.
  5. Review the verdict — look for detection counts, categorization, and any linked malware families.

Comparison of Popular Free Link Scanners

Scanner Best For Engines Used Shows Screenshot Free Tier
VirusTotal Multi-engine reputation check 70+ security vendors No Unlimited
urlscan.io Deep behavioral analysis Sandbox + threat intel Yes Unlimited public scans
Google Safe Browsing Fast phishing/malware check Google's own database No Unlimited
PhishTank Confirmed phishing URLs Community reports No Unlimited
Sucuri SiteCheck Website malware & blacklists Sucuri scanners No Unlimited

For everyday use, VirusTotal and urlscan.io are the strongest combination: one gives you consensus across dozens of engines, the other shows you exactly what the page does when loaded.

How to Handle Shortened URLs Safely

Shortened links (from services like bit.ly, tinyurl, or Lunyb) hide the true destination behind a short code. That's convenient for sharing, but it also means you can't visually inspect the domain. Attackers exploit this to disguise malicious URLs.

The safe workflow for any shortened link is:

  1. Expand the URL first using an unshortener tool such as CheckShortURL, Unshorten.it, or Where Goes.
  2. Read the revealed destination using the visual checks from earlier.
  3. Run it through a scanner if anything looks off.

Reputable shortener platforms actively fight abuse. For example, we cover how one of the more security-focused providers handles this in our honest review of Lunyb, and compare the wider market in our 2026 buyer's guide to URL shorteners. Choosing a shortener that scans destinations, blocks known bad domains, and offers link previews significantly reduces the risk on the sender's side too.

Advanced Techniques for Checking Suspicious Links

Inspect the WHOIS Record

A WHOIS lookup tells you when a domain was registered and by whom. Legitimate brands own their domains for years; phishing domains are often registered within the last 30 days. Free tools like whois.domaintools.com or who.is give you this data instantly. A domain created three days ago that claims to be your bank is almost certainly fake.

Check the SSL Certificate Details

Click the padlock in your browser (only after opening a scanner's cached preview, not the live site) to see who issued the certificate and to which organization. Big brands use Extended Validation (EV) or Organization Validated (OV) certs listing their legal entity. A free Let's Encrypt cert on a page pretending to be a Fortune 500 bank is suspicious.

Use a Sandbox or Isolated Browser

If you absolutely must visit an unknown link, do it in an isolated environment:

  • Browser sandbox services like urlscan.io or Browserling load the page in a remote virtual machine and let you see it safely.
  • Virtual machines on your own computer (VirtualBox, VMware) let you visit anything without affecting your real system.
  • Guest accounts or a separate device with no saved credentials add a layer of protection.

Turn On Encrypted DNS and Safe Browsing

Encrypted DNS providers such as Cloudflare's 1.1.1.1 for Families, Quad9, or NextDNS block known malicious domains at the network level before your browser even connects. Combine this with your browser's built-in Safe Browsing or SmartScreen feature and many bad links will simply refuse to load — a free extra layer of defense.

Red Flags That Should Stop You From Clicking

Beyond the URL itself, the context around a link is often the biggest tell. Treat any of the following as a hard stop:

  • Urgency and threats: "Your account will be closed in 24 hours," "Unusual login detected," or "Package undeliverable — pay fee now."
  • Unexpected attachments or invoices from senders you don't recognize.
  • Requests for credentials, 2FA codes, or payment info delivered via link.
  • Grammar and spelling errors in supposedly professional messages.
  • Mismatched sender addresses — a "support@apple.com" display name with a real address ending in @supportapple-help.co.
  • Links inside SMS from unknown numbers, especially about parcels, taxes, or bank alerts.
  • Rewards, prizes, or giveaways you never entered.

When any of these appear, do not click. Instead, navigate to the supposed sender's official website manually and log in there to check.

Pros and Cons of the Main Link-Checking Approaches

Visual Inspection

Pros: Instant, free, works offline, builds long-term instincts.
Cons: Misses well-crafted lookalikes; useless for shortened URLs.

Online Scanners

Pros: Extremely accurate; checks multiple threat feeds; shows page behavior.
Cons: Requires copying the URL and switching tabs; may not catch brand-new threats (zero-day phishing).

Browser Extensions

Pros: Automatic, real-time warnings as you browse.
Cons: Some request excessive permissions; quality varies wildly. Stick to well-known names from reputable security vendors.

Sandboxed Browsing

Pros: Safest possible way to open an unknown link.
Cons: Slower, requires a bit of setup or a paid service for regular use.

A Simple Everyday Workflow

You don't need to run every single link through five tools. Here's a practical routine that balances safety and speed:

  1. Trusted sender + expected message: hover to confirm the domain, then click.
  2. Trusted sender + unexpected link: verify through another channel (call, chat) before clicking.
  3. Unknown sender or shortened URL: unshorten if needed, then scan with VirusTotal or urlscan.io.
  4. High-value action (banking, taxes, work login): never use the link at all — type the address into your browser manually.

Following this workflow blocks the vast majority of real-world attacks with only a few seconds of extra effort.

What to Do If You Already Clicked a Suspicious Link

Even careful people slip up. If you clicked something you shouldn't have, act quickly:

  1. Disconnect from the internet if you suspect a download started.
  2. Do not enter any credentials if a login page loaded.
  3. Close the tab and clear browser cache and cookies.
  4. Run a full antivirus scan using your OS's built-in tool or a reputable third-party scanner.
  5. Change passwords for any account whose credentials you typed, starting with email and banking. Enable two-factor authentication everywhere.
  6. Monitor bank and card statements for the next 30–60 days and set up transaction alerts.
  7. Report the phishing link to Google Safe Browsing, PhishTank, or the impersonated brand.

Building Safer Habits Over Time

Tools help, but habits protect you long-term. A few worth developing:

  • Bookmark the sites you use most so you never rely on search or email links to reach them.
  • Use a password manager — it will refuse to autofill credentials on lookalike domains, which is a fantastic passive warning.
  • Keep your operating system, browser, and extensions updated. Most drive-by attacks target known, already-patched vulnerabilities.
  • When in doubt, don't click. There is almost no message urgent enough to justify skipping the check.

For creators and businesses sharing links, the responsibility flows the other way too: using a reputable shortener that blocks malware destinations protects your audience. If you're evaluating providers, our reviews of Rebrandly and other services cover the security features that matter.

Frequently Asked Questions

Is it dangerous to just click a link without entering any information?

Yes, it can be. Some malicious pages exploit browser or plugin vulnerabilities to run code the moment they load — this is called a drive-by download. Keeping your browser fully updated dramatically lowers the risk, but the safest approach is still to scan unfamiliar links before opening them.

How can I check if a link is safe on my phone?

Long-press the link to reveal a preview and the full URL, then copy it. Open a mobile browser and paste it into VirusTotal or urlscan.io. Both work perfectly on phones. Enable your device's built-in safe browsing (Chrome's Safe Browsing on Android, Fraudulent Website Warning on iOS Safari) for automatic protection.

Does HTTPS mean a link is safe?

No. HTTPS only means the connection between you and the site is encrypted. It does not verify that the site itself is trustworthy. Free certificates are easy to obtain, so most phishing sites now use HTTPS too. Always combine the padlock with a domain check and, when unsure, a scanner report.

Are shortened links inherently unsafe?

Not at all — they simply hide the destination, which is why extra caution helps. Reputable shortener services actively block malicious destinations and provide analytics that let owners spot abuse. The safe habit is to expand any shortened URL from a source you don't fully trust before opening it.

Which is the single best free tool to check a link?

If you can only use one, choose urlscan.io. It renders the page in a remote sandbox, shows you a screenshot, lists every domain contacted, and cross-checks against major threat databases — all without you ever touching the site yourself. Pair it with VirusTotal for a second opinion on anything borderline.

Checking links before you click is one of the highest-value security habits you can build. It takes seconds, costs nothing, and blocks the majority of attacks aimed at everyday users. Bookmark a scanner, train your eye on domains, and treat urgent messages with healthy skepticism — those three steps alone will keep you ahead of almost every phishing campaign out there.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles