facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··9 min read

Every day, billions of links are shared through emails, text messages, social media posts, and instant messengers. Some lead to helpful resources, while others hide phishing traps, malware downloads, or scam pages designed to steal your credentials. Knowing how to check if a link is safe before clicking has become one of the most important digital literacy skills of the modern era.

This guide walks you through practical, step-by-step methods to verify any URL, spot warning signs, and use free tools to scan suspicious links. Whether you received a shortened link from a friend or a suspicious email from your "bank," these techniques will help you stay safe.

Why Link Safety Matters More Than Ever

A malicious link is a hyperlink that leads to a website designed to harm the visitor, either by installing malware, harvesting personal information, or executing fraudulent transactions. According to industry threat reports, phishing attacks powered by deceptive links account for more than 80% of reported security incidents worldwide.

Attackers rely on urgency, curiosity, and trust to make you click. A single wrong tap can compromise your email account, drain your bank balance, or infect your device with ransomware. Fortunately, most malicious links leave clues that anyone can learn to spot.

10 Ways to Check if a Link Is Safe Before Clicking

Below is a layered approach. You do not need to use all ten methods for every link, but combining two or three dramatically reduces your risk.

1. Hover Over the Link to Preview the Real URL

On a desktop computer, place your mouse cursor over the link without clicking. The full destination URL will appear at the bottom of your browser or email client. On mobile devices, press and hold the link until a preview appears, then tap "Copy" instead of "Open."

Compare what the link says with where it actually goes. A link that reads "paypal.com" but points to "paypal-secure-login.xyz" is a red flag.

2. Inspect the Domain Carefully

Attackers love lookalike domains. Read the domain from right to left, starting at the top-level domain (.com, .org, .net) and moving backwards.

  • Legitimate: accounts.google.com
  • Suspicious: google.accounts-verify.com (the real domain is "accounts-verify.com," not Google)
  • Typosquatting: arnazon.com, faceb00k.com, netfl1x.com

3. Use a Free URL Scanner

Several online tools analyze links in seconds without you having to visit the page yourself. Paste the suspicious URL into any of these:

  • VirusTotal (virustotal.com) — checks the URL against 70+ security engines
  • Google Safe Browsing (transparencyreport.google.com/safe-browsing/search)
  • URLVoid (urlvoid.com) — aggregates reputation data from multiple blacklists
  • PhishTank (phishtank.org) — community-driven phishing database

4. Expand Shortened Links Before Clicking

Short links from services like bit.ly, t.co, or tinyurl hide the real destination. Use an unshortener before clicking:

  1. Copy the shortened URL
  2. Paste it into a tool like CheckShortURL.com or Unshorten.it
  3. Review the expanded destination before deciding whether to visit

Reputable shortening platforms take security seriously. For example, Lunyb automatically scans destination URLs and blocks known malicious targets, which is one of many reasons trustworthy shorteners matter. You can also compare options in our 2026 buyer's guide to URL shorteners.

5. Check for HTTPS and a Valid Certificate

Legitimate websites, especially those handling logins or payments, use HTTPS (indicated by a padlock icon). However, HTTPS alone is no longer a guarantee of safety — attackers routinely obtain free SSL certificates for phishing pages. Treat HTTPS as a minimum requirement, not proof of legitimacy.

Click the padlock to view certificate details. If the certificate is issued to a company name that doesn't match the site you expect, be cautious.

6. Look Up the Domain's Age and Registration

Phishing domains are often created days or hours before an attack. Use a WHOIS lookup tool (whois.domaintools.com or who.is) to check when a domain was registered.

  • Domain created less than 30 days ago = high risk
  • Privacy-protected registration + urgent request = suspicious
  • Domain older than several years with matching business info = generally safer

7. Watch for Red-Flag Characters in the URL

Attackers use Unicode tricks to disguise domains. Look for:

  • Cyrillic or Greek letters that look like Latin ones (e.g., "аpple.com" using a Cyrillic "а")
  • Excessive subdomains: login.secure.account.verify.badsite.com
  • Unusual top-level domains for well-known brands (.tk, .ml, .cf, .zip)
  • Random strings of numbers and letters
  • @ symbols in the URL, which browsers interpret in unexpected ways

8. Verify Through an Independent Channel

If a link claims to be from your bank, employer, or a service you use, don't click it. Instead:

  1. Open a new browser tab
  2. Type the official website address manually
  3. Log in and check for the notification directly
  4. Or call the organization using the number on their official site — never the number in the message

9. Enable Browser and DNS-Level Protection

Modern browsers include built-in safe browsing features. Make sure they're enabled:

  • Chrome: Settings → Privacy and security → Safe Browsing → Enhanced protection
  • Firefox: Settings → Privacy & Security → Deceptive Content and Dangerous Software Protection
  • Edge: Settings → Privacy → Microsoft Defender SmartScreen

You can also add an extra layer with an encrypted DNS resolver like Cloudflare 1.1.1.1 for Families or Quad9, which block known malicious domains at the network level.

10. Trust Your Instincts and the Context

If a message feels off — unexpected attachment, unusual sender, urgent tone, offer that's too good to be true — trust that feeling. Social engineering succeeds by rushing you past your natural skepticism. Take a breath and verify.

Comparison of Free Link-Checking Tools

Here's a side-by-side look at the most popular scanners so you can pick the right one:

Tool What It Checks Best For Cost
VirusTotal 70+ antivirus engines, blacklists, community reports Comprehensive analysis Free
Google Safe Browsing Google's malware and phishing database Quick reputation check Free
URLVoid 30+ reputation and blacklist services Domain reputation overview Free
PhishTank Verified phishing URL database Confirming phishing attempts Free
urlscan.io Live sandbox scan, screenshots, network requests Technical investigation Free tier
CheckShortURL Expands shortened URLs safely Short link previews Free

Common Types of Malicious Links to Recognize

Understanding what you're up against helps you spot threats faster.

Phishing Links

These lead to fake login pages that mimic banks, email providers, or workplace tools. Once you enter your credentials, attackers capture them. Warning signs include misspelled domains, urgent language, and generic greetings like "Dear Customer."

Malware Delivery Links

Clicking triggers a download or exploits a browser vulnerability to install spyware, ransomware, or a keylogger. Watch for links promising free software, cracked games, or unexpected file downloads (.exe, .scr, .zip from unknown senders).

Drive-By Download Sites

Simply visiting the page infects your device by exploiting unpatched browser or plugin flaws. Keeping your browser and operating system up to date is your best defense.

Scam and Fraud Pages

Fake shopping sites, cryptocurrency scams, romance scams, and "you've won a prize" pages designed to extract payment information. Reverse-image search product photos and check reviews on independent platforms.

Malicious Redirects and Ad Scripts

Some links pass through several redirects before reaching the final page, which can hide the true destination or serve different content depending on your device. Use urlscan.io to trace the full redirect chain.

Special Cases: Shortened Links, QR Codes, and Attachments

Shortened Links

Not every short link is dangerous — many marketers, journalists, and content creators use them legitimately. The issue is that you can't see the destination. Always expand short links from unfamiliar sources, and prefer platforms that publish transparent safety policies. If you're evaluating shortening services for your own use, our Rebrandly review and comparison guides examine which providers prioritize security features.

QR Codes

QR codes are just visual links. "Quishing" (QR-code phishing) is a fast-growing threat because people scan codes on posters, menus, and parking meters without inspecting them. Use a QR scanner app that shows the URL before opening it, and never scan codes stuck on top of other codes in public places.

Links Inside Attachments

PDFs and Word documents can hide clickable links that behave the same way as web links. Hover before clicking, or open the file in a preview mode that disables active content.

What to Do If You Already Clicked a Suspicious Link

Mistakes happen. If you clicked and now suspect the link was malicious, act fast:

  1. Disconnect from the internet to stop ongoing data theft or downloads
  2. Do not enter any credentials if a login page appeared
  3. Run a full antivirus scan using a reputable tool like Malwarebytes or Windows Defender
  4. Change passwords for any accounts you may have exposed, starting with email and banking
  5. Enable two-factor authentication on every important account
  6. Monitor bank and credit card statements for the next several weeks
  7. Report the link to Google Safe Browsing, PhishTank, or your workplace IT team so others are protected

Building Long-Term Habits for Link Safety

Individual checks are useful, but consistent habits protect you over the long haul:

  • Keep your browser, operating system, and apps updated automatically
  • Use a password manager so you're not tempted to reuse credentials across sites
  • Enable two-factor authentication everywhere — this alone stops most credential theft
  • Bookmark the login pages of your important accounts and use those bookmarks instead of clicking email links
  • Educate family members, especially those less familiar with technology, about common scam patterns
  • Back up important data so ransomware doesn't hold you hostage

Frequently Asked Questions

Can I get hacked just by clicking a link?

In most cases, clicking a link alone won't compromise you — you typically need to enter credentials, download a file, or have an unpatched browser vulnerability. However, drive-by exploits do exist, so keeping software updated and avoiding suspicious links entirely is the safest approach.

Are HTTPS links always safe?

No. HTTPS only means the connection between you and the site is encrypted. It doesn't say anything about whether the site itself is trustworthy. Phishing sites regularly use HTTPS certificates because they're free and easy to obtain.

How can I check a link on my phone?

Press and hold the link to see a preview of the URL and copy it without opening. Then paste it into a scanner like VirusTotal or Google Safe Browsing in your browser. Many mobile security apps also include real-time link scanning features.

Are all shortened links dangerous?

No. Shortened links are widely used by legitimate businesses, media outlets, and creators to save space and track clicks. The concern is that you can't see where they lead. Use an unshortener tool for links from unknown sources, and stick with reputable shortening platforms that scan destinations for threats.

What's the single best tool for checking a link?

VirusTotal is the most comprehensive free option because it checks a URL against dozens of security engines and shows community feedback. For deeper technical analysis, urlscan.io provides screenshots and full network traces of what a page actually does when loaded.

Final Thoughts

Learning how to check if a link is safe isn't about paranoia — it's about developing a small set of reflexes that take seconds but save you from serious harm. Hover before you click. Expand before you visit. Scan when in doubt. And when a message feels urgent, slow down instead of speeding up: urgency is the attacker's favorite weapon.

Combine the tools and habits in this guide and you'll neutralize the vast majority of link-based threats before they ever reach you. Stay curious, stay skeptical, and share this knowledge with people who might not know the warning signs yet.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles