facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Every day, cybercriminals send billions of malicious links through email, social media, and text messages. A single careless click can compromise your bank account, install ransomware on your device, or hand over your login credentials to attackers. Knowing how to check if a link is safe before clicking is no longer optional—it's a fundamental digital literacy skill.

This guide walks you through 10 practical methods to verify any URL, from quick visual inspections to advanced scanning tools. Whether you received a suspicious email from your "bank" or a shortened link on social media, you'll finish this article knowing exactly how to evaluate its safety in under 60 seconds.

Why Checking Links Before Clicking Matters

Link-based attacks are the #1 delivery method for phishing, malware, and credential theft. According to industry reports, over 90% of successful cyberattacks begin with a malicious link or attachment. Attackers exploit human trust by disguising dangerous URLs as messages from familiar brands, coworkers, or delivery services.

The consequences of clicking an unsafe link range from minor annoyances to catastrophic breaches:

  • Credential theft — fake login pages capture your usernames and passwords.
  • Malware installation — drive-by downloads infect your device without any additional clicks.
  • Financial fraud — attackers drain bank accounts or make unauthorized purchases.
  • Identity theft — personal data gets sold on dark web marketplaces.
  • Ransomware — entire systems are encrypted and held hostage.

10 Ways to Check if a Link Is Safe Before Clicking

Here are ten reliable techniques you can combine to evaluate any URL. Start with the free visual checks, then escalate to scanning tools if anything looks suspicious.

1. Hover Over the Link to Preview the Real URL

On desktop, hover your mouse over any hyperlink without clicking. The true destination appears in the bottom-left corner of your browser or email client. On mobile, press and hold the link to reveal a preview menu with the full URL.

Watch for mismatches between the visible text and the actual URL. A link that says "paypal.com" but points to "paypal-secure-login.co" is a clear phishing attempt.

2. Inspect the Domain Carefully

The domain is the most important part of any URL. Read it right-to-left starting from the top-level domain (.com, .org, .net). The real domain sits immediately before that.

For example, in https://accounts.google.com.security-check.ru/login, the real domain is security-check.ru, not google.com. Attackers frequently exploit subdomain confusion to trick users.

3. Look for HTTPS and a Valid Certificate

Legitimate sites use HTTPS encryption, indicated by a padlock icon in the address bar. However, HTTPS alone doesn't mean a site is safe—many phishing sites now use free SSL certificates. HTTPS confirms the connection is encrypted, not that the destination is trustworthy.

Click the padlock to view certificate details. Legitimate businesses often have Extended Validation (EV) certificates listing the company's legal name.

4. Use a Free URL Scanner

Several online tools analyze URLs against known threat databases and behavioral indicators. Copy the suspicious link (without clicking) and paste it into one of these scanners:

  • Google Safe Browsing Transparency Report — checks Google's malware and phishing database.
  • VirusTotal — scans URLs across 70+ antivirus engines simultaneously.
  • URLVoid — aggregates reputation data from multiple blocklists.
  • PhishTank — community-driven phishing URL database.
  • Sucuri SiteCheck — detects malware, blacklisting, and defacement.

5. Expand Shortened Links Before Clicking

Shortened URLs (bit.ly, tinyurl, t.co) hide the true destination. Before clicking any shortened link from an unknown sender, use an expander service to reveal the full URL:

  1. Copy the shortened link.
  2. Paste it into an expander like CheckShortURL, Unshorten.it, or ExpandURL.
  3. Review the expanded destination.
  4. Run the expanded URL through a scanner from step 4.

Reputable link shorteners like Lunyb also offer link preview features and privacy-focused redirects, so you can share short links without exposing recipients to unnecessary tracking. For a broader comparison of trustworthy options, see our 2026 buyer's guide to URL shorteners.

6. Watch for Common Typosquatting Tricks

Typosquatting is when attackers register domains that look almost identical to legitimate ones. Common tactics include:

  • Swapped letters: arnazon.com instead of amazon.com.
  • Added characters: faceboook.com, gooogle.com.
  • Different TLDs: microsoft.co or apple.support.
  • Homoglyphs: Cyrillic "а" replacing Latin "a" (invisible to the eye).
  • Hyphens: my-bank-login.com instead of mybank.com.

7. Check the Sender's Context and Legitimacy

Even a technically valid URL can be dangerous if it arrives from an unexpected source. Ask yourself:

  • Am I expecting this message?
  • Does the sender's email address match their claimed identity?
  • Is there urgency or emotional pressure ("Your account will be closed in 24 hours!")?
  • Does the tone match previous legitimate communications?

When in doubt, navigate directly to the company's website by typing the address into your browser rather than clicking any link.

8. Use Browser Safety Features

Modern browsers include built-in phishing and malware protection. Ensure these are enabled:

  • Chrome: Settings → Privacy and Security → Safe Browsing → Enhanced Protection.
  • Firefox: Settings → Privacy & Security → Deceptive Content and Dangerous Software Protection.
  • Edge: Settings → Privacy, Search, and Services → Microsoft Defender SmartScreen.
  • Safari: Preferences → Security → Warn when visiting a fraudulent website.

9. Verify Through Official Channels

If a message claims to be from your bank, employer, or a service provider, verify through a channel you already trust. Call the phone number printed on your credit card, open the company's official app, or type their known URL directly. Never use contact information provided in the suspicious message itself.

10. Sandbox Suspicious Links

For advanced users, sandboxing tools open links in isolated environments where malware can't reach your real system. Options include:

  • urlscan.io — loads the URL in a controlled browser and shows screenshots, network requests, and behavior.
  • Browserling — opens links in a remote browser session.
  • ANY.RUN — interactive malware analysis sandbox.

Warning Signs of an Unsafe Link

Certain red flags should immediately raise your suspicion. If you spot any of these, do not click:

Warning SignWhat It Looks LikeRisk Level
Misspelled domainpaypa1.com, netfliix.comCritical
Suspicious TLD.tk, .ml, .zip, .top for a "bank"High
Excessive subdomainslogin.security.verify.example.ruHigh
IP address instead of domainhttp://192.168.4.22/loginCritical
URL shortener from unknown senderbit.ly/xyz123 in a random DMMedium
Unicode/homoglyph charactersаpple.com (Cyrillic "а")Critical
No HTTPS on a login pagehttp://bank-login.comHigh
Random character stringsxk9j2ldsmpq.websiteHigh
Urgent or threatening context"Verify now or lose access!"Medium

Free vs. Paid Link Safety Tools Compared

You don't need to spend money to check links safely, but paid tools offer deeper analysis for businesses or high-risk users.

ToolTypeBest ForCost
Google Safe BrowsingFree web checkQuick reputation lookupFree
VirusTotalFree multi-scannerCross-engine verificationFree (paid API)
urlscan.ioFree sandboxVisual + behavior analysisFree (paid tiers)
PhishTankFree databaseConfirmed phishing URLsFree
Sucuri SiteCheckFree scannerWebsite malware detectionFree
Norton Safe WebFree/paidConsumer browsingFree basic
Cisco TalosFree intelDomain reputationFree

Pros and Cons of Automated URL Scanners

Pros:

  • Fast results—usually in seconds.
  • Access to threat intelligence beyond what a human could check manually.
  • Detects known malware, phishing, and blacklisted domains reliably.
  • Most tools are free and require no installation.

Cons:

  • Brand-new phishing sites may not be in databases yet (zero-day risk).
  • Attackers use cloaking to show scanners a clean page while serving malware to real users.
  • False positives can flag legitimate sites incorrectly.
  • No single tool catches everything—layered checks are always better.

Special Cases: Shortened Links and QR Codes

Shortened links and QR codes are increasingly abused because they hide the destination URL. Treat both with extra caution when they come from unknown sources.

Handling Shortened Links Safely

  1. Never click a shortened link from an unexpected sender.
  2. Use an expander tool to reveal the full URL first.
  3. Prefer platforms that offer built-in preview pages. Trusted services like Lunyb and reputable alternatives reviewed in our Rebrandly review disclose destinations transparently.
  4. Scan the expanded URL with VirusTotal before opening.

QR Code Safety Steps

  1. Use a QR scanner app that previews the URL before opening (most modern camera apps do this).
  2. Verify the URL exactly as you would a typed link.
  3. Be extra suspicious of QR codes in public places—attackers stick fake codes over legitimate ones on parking meters, restaurant menus, and posters.

What to Do If You Already Clicked a Suspicious Link

If you clicked before checking, don't panic—take these steps immediately:

  1. Disconnect from the internet to prevent further data transmission or malware downloads.
  2. Don't enter any information on the page that opened. Close the tab immediately.
  3. Run a full antivirus scan using your installed security software.
  4. Change passwords for any accounts you may have exposed, starting with email and banking.
  5. Enable two-factor authentication on critical accounts if not already active.
  6. Monitor financial statements for unauthorized transactions over the next 30 days.
  7. Report the phishing attempt to your email provider, the impersonated brand, and anti-phishing organizations like the APWG.

Building Long-Term Link Safety Habits

Tools help, but habits are your strongest defense. Adopt these practices to reduce your risk permanently:

  • Pause before clicking. A two-second delay is enough time to notice red flags.
  • Bookmark critical sites. Use your bookmarks instead of searching or clicking links to reach your bank, email, or cloud storage.
  • Keep software updated. Browser and OS patches close vulnerabilities that malicious links exploit.
  • Use a password manager. Password managers refuse to autofill on lookalike domains—a built-in phishing detector.
  • Enable multi-factor authentication everywhere possible so stolen passwords alone can't compromise accounts.
  • Educate everyone in your household or team. A single click by any member can expose shared devices or networks.

Frequently Asked Questions

Can I get hacked just by clicking a link without entering any information?

Yes, though it's less common than credential phishing. "Drive-by downloads" can install malware simply by loading a malicious page, especially if your browser or operating system has unpatched vulnerabilities. Keeping software updated dramatically reduces this risk, but you should still avoid clicking unknown links.

Is a link with HTTPS always safe?

No. HTTPS only means the connection between your browser and the server is encrypted—it says nothing about who owns the server or what they intend to do with your data. Modern phishing sites almost always use HTTPS because free certificates are easy to obtain. Always verify the domain itself, not just the padlock icon.

How can I tell if a shortened link is safe?

Use a URL expander service (CheckShortURL, Unshorten.it, or ExpandURL) to reveal the full destination without visiting it. Then run that expanded URL through a scanner like VirusTotal or urlscan.io. Reputable shortening platforms also provide preview pages that show the destination before redirect.

Are link scanners like VirusTotal 100% accurate?

No scanner catches every threat. Brand-new phishing sites may not appear in databases for hours or days after launch, and sophisticated attackers use cloaking techniques to show scanners a clean page. Combine automated scanning with manual checks (domain inspection, sender verification, and context awareness) for the best protection.

What should I do if a link came from a friend but looks suspicious?

Assume the friend's account may be compromised. Contact them through a different channel (phone call, in person, or a different messaging app) to confirm they actually sent it. Attackers frequently hijack social media and email accounts to send malicious links to the victim's contact list, exploiting the trust relationship.

Final Thoughts

Checking whether a link is safe before clicking takes less than a minute once you develop the habit. Start with hovering to preview the URL, inspect the domain carefully, and escalate to free scanners like VirusTotal or urlscan.io when anything feels off. Combine these tools with skepticism about unexpected messages, and you'll neutralize the vast majority of link-based attacks before they reach you.

The best time to build this habit is before you need it. Bookmark two or three of the scanning tools mentioned above right now, and you'll always have them ready the next time a suspicious link lands in your inbox.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles