facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Every day, billions of links are shared through emails, text messages, social media, and chat apps. Most are harmless — but a growing number lead to phishing pages, malware downloads, or scams designed to steal your money and identity. Knowing how to check if a link is safe before clicking is one of the most valuable digital skills you can develop in 2026.

This guide walks you through practical, step-by-step methods to verify any URL — whether it arrived in your inbox, appeared in a social media post, or was shared by a friend. You'll learn free tools, manual inspection techniques, and warning signs that separate legitimate links from dangerous ones.

Why Checking Links Before Clicking Matters

A single click on a malicious link can install ransomware, expose passwords, drain bank accounts, or hand over your identity to criminals. According to industry reports, more than 80% of reported cyberattacks begin with a phishing link. Attackers have become skilled at disguising harmful URLs to look like trusted brands — banks, delivery services, streaming platforms, and government agencies.

The good news: with a few seconds of caution, most dangerous links can be identified before they cause damage. Prevention is always cheaper than recovery.

Common Threats Hidden Behind Links

  • Phishing pages — fake login screens that steal your credentials
  • Drive-by malware downloads — files that install silently when the page loads
  • Fake shopping sites — designed to collect card details
  • Cryptocurrency scams — fraudulent wallets and investment platforms
  • Tech support scams — pages that lock your browser and demand a call
  • Session hijacking — links that steal your logged-in browser cookies

10 Ways to Check if a Link Is Safe Before Clicking

Below are the most reliable methods to verify a link's safety. You don't need all of them for every URL — start with the quickest checks and escalate to deeper scans when something feels off.

1. Hover Over the Link to Preview the Real URL

On desktop, hover your mouse cursor over any hyperlink without clicking. The full destination URL will appear in the bottom-left corner of your browser or email client. Compare it against the visible text. If the link says "paypal.com" but the preview shows "paypa1-security-verify.ru", it's a phishing attempt.

On mobile, press and hold the link (don't tap) until a preview menu appears showing the actual URL.

2. Inspect the Domain Carefully

Attackers rely on lookalike domains. Read the domain from right to left, focusing on the part just before the top-level domain (.com, .net, .org):

  1. Identify the root domain (e.g., in login.mybank.support-verify.com, the real domain is support-verify.com, not mybank).
  2. Look for character swaps: rn instead of m, 0 instead of o, or Cyrillic letters that look identical to Latin ones.
  3. Check for extra hyphens or added words like -secure, -login, or -verify.
  4. Be suspicious of unusual TLDs (.tk, .xyz, .top) claiming to represent major brands.

3. Use a Free Online URL Scanner

Several trusted services let you paste a URL and receive an instant safety report. They scan the link against known threat databases and often render the page in a sandbox.

ScannerBest ForCost
VirusTotalCross-checking 70+ antivirus enginesFree
Google Safe Browsing Transparency ReportConfirming Google's threat classificationFree
URLScan.ioSeeing what a page loads and connects toFree
PhishTankCommunity-verified phishing reportsFree
Sucuri SiteCheckDetecting malware on websitesFree

4. Expand Shortened URLs Before Clicking

Shortened links (bit.ly, t.co, tinyurl, and others) hide their true destination. This is convenient — but also useful to attackers. Before opening any short link from an untrusted source, expand it using a service like CheckShortURL, Unshorten.It, or Unshorten.me. These tools reveal the final destination without loading it in your browser.

Reputable shortener platforms like Lunyb and enterprise services covered in our 2026 URL shortener buyer's guide include built-in malware scanning and preview features — so links created through them are less likely to hide malicious destinations.

5. Check for HTTPS — But Don't Rely on It Alone

A padlock icon and https:// mean the connection is encrypted, not that the site is trustworthy. Modern phishing pages almost always use HTTPS because free SSL certificates are easy to obtain. Treat the padlock as the bare minimum, not proof of legitimacy.

6. Look Up the Domain's Age and Registration

Legitimate brands own their domains for years. Phishing domains are often registered days or hours before an attack. Use a WHOIS lookup tool (like whois.domaintools.com) to check when the domain was created. A domain registered last week claiming to be a 30-year-old bank is a major red flag.

7. Search the URL or Domain on Google

Copy the domain and search for it along with terms like "scam," "phishing," "review," or "legit." If others have reported it, you'll usually see complaints on forums like Reddit, Trustpilot, or scam-tracking sites. No results at all for a supposedly major service is also suspicious.

8. Use Your Browser's Built-In Protection

Chrome, Edge, Firefox, Safari, and Brave all include Safe Browsing or SmartScreen features that warn you when a site is known to be malicious. Make sure these protections are enabled in your browser's privacy settings. If a red warning page appears — do not bypass it.

9. Verify Through an Independent Channel

If a link claims to be from your bank, delivery service, or employer, don't click it. Instead:

  1. Open a new browser tab
  2. Type the official website address manually (or use a saved bookmark)
  3. Log in and check your account for the alleged notification
  4. If it's real, the message will be waiting inside your account

This single habit blocks nearly every phishing attempt.

10. Open Suspicious Links in a Sandbox

If you must see what a link leads to, use a sandboxed environment. Services like URLScan.io, Browserling, or any-run render the page inside an isolated system — so even if it's malicious, your device stays safe. Advanced users can also use a virtual machine or a disposable browser profile.

Red Flags That Should Stop You Immediately

Even without tools, certain signals should trigger caution. Treat any link with these traits as guilty until proven innocent:

  • Urgency language: "Your account will be closed in 24 hours"
  • Threats or emotional manipulation
  • Prizes, refunds, or unexpected package notifications
  • Requests for passwords, one-time codes, or card details
  • Misspellings in the sender's name, domain, or message body
  • Attachments combined with links (double threat)
  • Links inside unsolicited messages from unknown numbers
  • Cryptocurrency "opportunities" or investment giveaways
  • Requests to install software or browser extensions
  • Odd formatting: mixed languages, broken graphics, or generic greetings

Mobile vs. Desktop: Special Considerations

Mobile devices make it harder to inspect links because previews are shorter and hovering isn't possible. Attackers know this and increasingly target smartphone users through SMS ("smishing") and messaging apps.

Extra Tips for Mobile Users

  • Long-press links to reveal the full URL before opening
  • Never install apps from links sent via SMS or DMs
  • Disable auto-preview features in messaging apps if possible
  • Keep your OS and browser updated — many threats are patched quickly
  • Use a mobile browser with built-in phishing protection

How to Check Links in Emails Safely

Email remains the number one delivery channel for phishing. Follow this workflow before clicking any link inside an email:

  1. Check the sender's full email address, not just the display name. "Amazon Support <support@amaz0n-billing.co>" is fake.
  2. Hover over every link to preview its destination.
  3. Look at the email headers if you're technical — mismatched SPF, DKIM, or DMARC results indicate spoofing.
  4. Never trust logos or branding alone. These are trivially copied.
  5. When in doubt, delete and go direct.

Tools and Extensions That Help Automatically

Browser extensions and utilities can add a layer of automated protection so you don't have to check every single link manually.

ToolWhat It DoesPlatform
Bitdefender TrafficLightReal-time link scanning in search results and social feedsChrome, Firefox, Edge
Malwarebytes Browser GuardBlocks phishing, scam, and malware pagesAll major browsers
uBlock OriginBlocks known malicious domains via filter listsFirefox, Chromium
Encrypted DNS (Cloudflare 1.1.1.1, Quad9)Blocks known malicious domains at the network levelSystem-wide
Password managersWon't autofill on lookalike domains — a silent phishing detectorAll platforms

Encrypted DNS resolvers like Quad9 are especially powerful — they refuse to resolve known malicious domains before your browser ever loads them.

What to Do if You Already Clicked a Suspicious Link

If you've clicked a link that turned out to be malicious, act quickly. The first hour matters most.

  1. Disconnect from the internet to stop any download or data transfer in progress.
  2. Do not enter any information if a login form appeared.
  3. Run a full antivirus scan using a reputable tool.
  4. Change passwords for any account that could have been exposed — starting with your email.
  5. Enable two-factor authentication on all critical accounts.
  6. Monitor bank and card statements for at least 30 days.
  7. Report the link to Google Safe Browsing, PhishTank, or the impersonated brand's abuse team.
  8. Freeze your credit if financial information may have leaked.

Building Long-Term Link Safety Habits

The best defense isn't a single tool — it's a set of habits. Assume every unsolicited link is dangerous until you verify otherwise. Bookmark the official sites you visit often so you never have to search for them. Use unique passwords with a password manager, so even a successful phish only exposes one account. And share what you learn — most phishing victims are people who simply weren't aware of the warning signs.

For businesses and creators sharing links publicly, using a reputable shortener with built-in security scanning — such as Lunyb or the top platforms compared in our Rebrandly 2026 review — helps protect your audience from being caught in someone else's spoofing attempt.

FAQ: Checking if a Link Is Safe

Can just clicking a link infect my device?

Yes, in some cases. Drive-by downloads and browser exploit kits can install malware without any further action from you, especially if your browser or operating system is out of date. Keeping everything updated dramatically reduces this risk, but the safest habit is still to verify links before clicking.

Is HTTPS enough to know a link is safe?

No. HTTPS only guarantees that your connection to the website is encrypted — it does not verify the site's identity or intentions. The vast majority of phishing sites now use HTTPS because SSL certificates are free and easy to obtain. Always combine HTTPS with domain inspection and a URL scanner.

What's the fastest way to check a suspicious link?

Copy the URL and paste it into VirusTotal or Google's Safe Browsing checker. Both take under 10 seconds and cross-reference the link against dozens of threat databases. For shortened URLs, run them through an unshortening tool first to see the real destination.

Are shortened links always dangerous?

Not at all. Shortened links are widely used by legitimate businesses, marketers, and news outlets to create clean, trackable URLs. The risk comes from not knowing where a shortener points. Use a URL expander when in doubt, and prefer shorteners that offer preview pages and malware scanning.

How do I report a malicious link?

You can report phishing and malware links to Google Safe Browsing, PhishTank, the Anti-Phishing Working Group (reportphishing@apwg.org), and the abuse team of the impersonated brand. If you received the link by email, most providers (Gmail, Outlook, Yahoo) also offer a one-click "Report phishing" option.

Final Thoughts

Learning how to check if a link is safe is a small habit with an enormous payoff. A ten-second pause — to hover, read the domain, or paste it into a scanner — can prevent identity theft, financial loss, and hours of recovery work. Combine manual inspection with automated protections like browser safe browsing, encrypted DNS, and a password manager, and you'll block the overwhelming majority of link-based attacks before they ever reach you.

Stay curious, stay skeptical, and when in doubt — don't click. Verify.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles