facebook-pixel

How to Check if a Link Is Safe Before Clicking: The 2026 Guide

L
Lunyb Security Team
··10 min read

Every day, billions of links travel through email inboxes, text messages, chat apps, and social media feeds. Most are harmless—but a small percentage lead to phishing pages, malware downloads, credential theft, or worse. Knowing how to check if a link is safe before clicking is one of the most valuable digital skills you can develop in 2026.

This guide walks you through practical, free methods to inspect any URL in seconds, spot the warning signs that scammers rely on, and build habits that protect your accounts, your data, and your devices.

What Does It Mean for a Link to Be "Safe"?

A safe link points to a legitimate, trustworthy destination that will not attempt to steal your information, install malicious software, or manipulate you through deceptive content. An unsafe link, by contrast, typically leads to one of four dangerous outcomes: a phishing page designed to capture your login credentials, an automatic malware download, a scam page pushing fake products or investment fraud, or a drive-by exploit that targets vulnerabilities in your browser.

The tricky part is that unsafe links often look nearly identical to safe ones. Attackers deliberately register domains that mimic banks, delivery services, and social platforms. That is why manual inspection and automated scanning both matter.

10 Proven Ways to Check if a Link Is Safe

Below are ten reliable methods, ordered from fastest to most thorough. You do not need to use all of them—for most links, one or two steps are enough.

1. Hover Over the Link to Reveal the Real URL

On desktop, hover your mouse over any link without clicking. The full destination URL will appear in the bottom-left corner of your browser or email client. On mobile, press and hold the link until a preview menu appears. Compare what you see against what the link text claims. If an email says "Click here to log in to PayPal" but the hover reveals paypal-security-verify.xyz, close the message immediately.

2. Inspect the Domain Carefully

Read the domain from right to left, starting at the top-level domain. The real domain is the part immediately before the TLD (.com, .net, .org, etc.). For example:

  • login.microsoft.com → real domain is microsoft.com
  • microsoft.login-verify.com → real domain is login-verify.com
  • micros0ft.com (zero instead of "o") → typosquatting ❌

3. Use a Free Online Link Scanner

Paste any suspicious URL into a reputable scanner to get an instant safety report. Popular free options include:

  1. VirusTotal — checks the link against 70+ antivirus engines and blocklists.
  2. Google Safe Browsing Transparency Report — Google's official database of unsafe sites.
  3. URLVoid — aggregates reputation data from dozens of security services.
  4. PhishTank — a community-driven list of known phishing URLs.
  5. Sucuri SiteCheck — scans for malware, blacklisting, and outdated software.

If two or more scanners flag a URL, treat it as dangerous even if the site "looks fine."

4. Expand Shortened URLs Before Clicking

Shortened links (like bit.ly, t.co, or tinyurl.com URLs) hide the real destination. To reveal it safely, use an unshortener tool such as CheckShortURL, Unshorten.it, or ExpandURL. Paste the short link, and you will see the final URL plus a preview of the destination page.

Reputable shortening services take abuse seriously and actively remove malicious links. If you use link shorteners for your own marketing, choose providers that scan destinations and offer analytics—see our 2026 buyer's guide to URL shorteners for a full comparison.

5. Check the HTTPS Padlock (but Don't Trust It Alone)

A padlock icon in the address bar means the connection is encrypted—it does not mean the site is legitimate. Today, most phishing sites use free HTTPS certificates too. Use the padlock as a baseline, then combine it with domain inspection and reputation checks.

6. Look Up the Domain's Age with WHOIS

Legitimate businesses usually own their domains for years. Scam sites are often registered days or weeks before an attack. Use a free WHOIS lookup (like whois.domaintools.com or ICANN Lookup) to check when a domain was registered. A domain that's less than 90 days old and claims to be a major brand is almost always suspicious.

7. Read the Full URL Structure

Attackers hide malicious domains inside long, confusing URLs. Watch for these patterns:

  • Multiple subdomains stacked to look like a brand (e.g., apple.com.security-check.ru)
  • Unusual TLDs paired with famous brand names (.tk, .zip, .top, .xyz used for banking impersonation)
  • URL-encoded characters that hide the true destination (%2E, %2F)
  • "@" symbols in the middle of URLs (everything before the @ is ignored by browsers)

8. Preview the Page in a Sandbox

Tools like urlscan.io and Browserling let you "visit" a suspicious URL inside an isolated cloud browser and see a screenshot, page source, and network activity—without exposing your own device. This is one of the safest ways to inspect a link when you genuinely need to see what's on the other side.

9. Use Built-In Browser Protection

Modern browsers include real-time link scanning. Make sure these features are enabled:

  • Chrome / Edge: Enhanced Safe Browsing under Privacy and Security settings
  • Firefox: "Block dangerous and deceptive content" toggle
  • Safari: "Fraudulent Website Warning" in Security preferences

These features check every URL you visit against constantly updated blocklists and warn you before a page loads.

10. Trust Your Gut and Verify Out of Band

If a message creates urgency ("Your account will be closed in 24 hours!"), asks for sensitive information, or offers something too good to be true, verify through a separate channel. Open a new browser tab and type the official website address yourself. Call the company using a number from their real website—never the number in the suspicious message.

Red Flags That Almost Always Signal a Dangerous Link

The following table summarizes the warning signs that should stop you from clicking, along with the likely threat behind each.

Red Flag What It Usually Means Risk Level
Misspelled brand names in the domain Typosquatting / phishing High
Urgent language ("Act now!", "Account suspended") Social engineering pressure High
Requests for password, SSN, or payment info via link Credential theft Critical
Domain registered within the last 30 days Disposable scam infrastructure High
Unusual TLDs (.zip, .tk, .mov, .country) Common in malware campaigns Medium
Excessive subdomains before the real domain Brand impersonation High
Links inside unexpected attachments Malware delivery Critical
Shortened URL with no context Hidden destination Medium

How to Check Links on Mobile Devices

Mobile users are targeted more aggressively than desktop users because small screens hide URL details. Follow these mobile-specific steps.

On iPhone (iOS)

  1. Long-press the link. A preview card appears with the full URL at the top.
  2. Read the domain carefully before tapping "Open."
  3. Tap "Copy" instead, then paste into a link scanner like VirusTotal.
  4. Enable Settings → Safari → Fraudulent Website Warning.

On Android

  1. Long-press the link and choose "Preview page" (Chrome) or "Copy link address."
  2. Paste the URL into a scanner before opening.
  3. Turn on Google Play Protect for automatic app-based link warnings.

Checking Links in Email vs. Social Media vs. SMS

Different platforms carry different risks. Adapt your checking process to the channel.

Channel Most Common Threat Best First Check
Email Phishing impersonating banks, HR, or delivery services Hover to see real URL; check sender address
SMS (smishing) Fake package delivery and tax refund scams Long-press link, paste into scanner
Social media DMs Account takeover and crypto scams Verify sender identity via a second channel
QR codes Quishing (QR phishing) Use a QR scanner that shows the URL before opening
Ads and search results Malvertising and typosquat lookalikes Manually type known URLs instead of clicking ads

Building a Safer Link-Clicking Habit

Tools help, but habits are what protect you consistently. Adopt the following routine and you will avoid the vast majority of link-based attacks.

  1. Pause before every click. Two seconds of scrutiny beats hours of cleanup.
  2. Type known URLs manually. For banking, email, and government sites, never click—type.
  3. Enable multi-factor authentication everywhere. Even if a link steals your password, MFA blocks the login.
  4. Keep your browser and OS updated. Most drive-by exploits target outdated software.
  5. Use a password manager. Password managers refuse to autofill on lookalike domains—an instant phishing detector.
  6. Report suspicious links. Forward phishing emails to reportphishing@apwg.org or your national cybercrime agency.

How Link Shorteners Fit into Link Safety

Shortened links are neither inherently safe nor unsafe—they simply hide the destination. The trust equation depends on the shortening service. Reputable providers scan links, monitor for abuse, and remove malicious redirects quickly. Sketchy or abandoned services do not.

If you create short links for your own business, marketing, or social sharing, use a shortener with clear policies and active moderation. Services like Lunyb focus on clean, reliable redirects with analytics and abuse monitoring—useful whether you're sharing links in a newsletter or on social media. For a deeper look at the shortener landscape, our honest review of Lunyb and our Rebrandly review walk through the trade-offs.

What to Do If You Already Clicked a Suspicious Link

Do not panic—quick action limits the damage. Follow these steps immediately.

  1. Disconnect from the internet. Turn off Wi-Fi or unplug ethernet to stop ongoing communication with an attacker.
  2. Do not enter any information if a page loaded. Close the tab.
  3. Run a full antivirus scan. Windows Defender, Malwarebytes, or your preferred security suite.
  4. Change passwords for any account you may have entered credentials for—starting with email.
  5. Enable MFA on all critical accounts if you haven't already.
  6. Monitor bank and credit card statements for at least 30 days.
  7. Report the incident to your IT team (if at work) or a national cybercrime authority.

Frequently Asked Questions

Is it safe to click a link just to "see what it is"?

No. Some malicious pages exploit browser vulnerabilities the moment they load, without any interaction from you. If you need to inspect a link, use a sandboxed preview tool like urlscan.io rather than opening it in your normal browser.

Are shortened links always dangerous?

Not at all. Shortened links are used widely by legitimate businesses, journalists, and marketers. The safety depends entirely on the destination and the reputation of the shortening service. Use an unshortener tool to preview any short link you're unsure about.

Does HTTPS mean a link is safe?

HTTPS only guarantees that your connection to the site is encrypted—it does not verify the site's identity or legitimacy. Attackers routinely obtain free HTTPS certificates for phishing sites. Always combine the padlock check with domain inspection and reputation scanning.

What's the single fastest way to check a link?

Hover over the link (or long-press on mobile) to reveal the true URL, then read the domain from right to left. If the domain immediately before the TLD isn't the brand you expected, don't click. This one habit blocks the majority of phishing attempts.

Can antivirus software catch every dangerous link?

No security tool is 100% effective. Antivirus and browser blocklists rely on known threats, and brand-new phishing sites can slip through for hours before being flagged. That's why layered defense—manual inspection, scanners, MFA, and updated software—is essential.

The Bottom Line

Learning how to check if a link is safe is not about becoming paranoid—it's about adding a two-second pause to a reflexive action. Hover, read the domain, scan when in doubt, and verify sensitive requests through a separate channel. Combined with MFA, a password manager, and an updated browser, these habits will keep you ahead of nearly every phishing campaign you encounter. The internet is full of useful links; a little scrutiny keeps the dangerous ones from ever loading.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles