facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Every day, billions of links travel through emails, text messages, social media posts, and chat apps. Most are harmless. But a single malicious link can drain your bank account, install ransomware, or hand your login credentials to a criminal within seconds. Learning how to check if a link is safe before clicking is no longer optional cybersecurity hygiene — it's a survival skill for anyone who uses the internet.

This guide walks you through 10 practical methods to verify any URL, from quick visual inspections to professional-grade scanning tools. Whether you received a suspicious email from your "bank," a shortened link on social media, or a QR code in a public place, you'll learn exactly how to evaluate it in under 60 seconds.

Why Link Safety Matters More Than Ever in 2026

Phishing remains the number-one delivery method for cyberattacks worldwide. According to recent industry reports, over 90% of successful data breaches begin with a malicious link clicked by an unsuspecting user. Attackers have gotten dramatically better at crafting convincing lookalikes — AI-generated phishing pages now mimic legitimate sites so accurately that even trained professionals struggle to spot the difference at a glance.

The consequences of clicking a bad link range from minor annoyances to catastrophic:

  • Credential theft — Fake login pages capture your username and password.
  • Malware installation — Drive-by downloads infect your device without any further action.
  • Financial fraud — Attackers use stolen data to drain accounts or open new lines of credit.
  • Ransomware — Your files get encrypted and held hostage.
  • Identity theft — Personal information ends up on the dark web, sold to the highest bidder.

The good news: most of these attacks are preventable with a few seconds of link verification.

10 Ways to Check if a Link Is Safe Before You Click

Below are the most reliable techniques, ordered from fastest visual checks to deeper technical scans. Use as many as the situation warrants — a link from your best friend needs less scrutiny than one from an unknown sender demanding urgent action.

1. Hover Over the Link to See the Real Destination

The simplest and fastest check: on a desktop, hover your mouse cursor over any link without clicking. The actual destination URL appears in the bottom-left corner of your browser or email client. On mobile, press and hold the link (don't tap) to reveal a preview.

Compare what you see to what the link claims to be. If the visible text says paypal.com but the hover reveals paypa1-secure-login.ru, you've caught a phishing attempt in three seconds.

2. Inspect the Domain Carefully

Attackers rely on you skimming. Slow down and read the domain letter by letter. Watch for:

  1. Character substitution — zeros for O's, ones for L's, or Cyrillic letters that look identical to Latin ones (e.g., аpple.com vs apple.com).
  2. Extra words or hyphensamazon-security-update.com is not owned by Amazon.
  3. Wrong top-level domainmicrosoft.support instead of microsoft.com.
  4. Subdomain trickspaypal.com.verification-center.net is actually on verification-center.net, not PayPal.

Remember: the true domain is always the part immediately before the first single slash, reading right-to-left from that slash.

3. Use a Free URL Scanner

Several reputable services let you paste a suspicious link and receive a detailed safety report without visiting the page yourself. Top options include:

  • VirusTotal — Scans the URL against 70+ security engines and reputation databases.
  • Google Safe Browsing Transparency Report — Google's own database of known dangerous sites.
  • URLVoid — Cross-references dozens of blocklists and provides domain reputation history.
  • Sucuri SiteCheck — Detects malware, blacklist status, and out-of-date software on the destination site.
  • PhishTank — A community-driven database of confirmed phishing URLs.

Best practice: run any unexpected link through at least two of these before clicking.

4. Expand Shortened URLs Before Clicking

Short links from services like Bitly, TinyURL, or Lunyb hide the true destination behind a compact wrapper. Legitimate uses are everywhere — cleaner social posts, easier-to-type addresses, trackable marketing campaigns — but attackers exploit the same feature to disguise malicious destinations.

Use an unshortener before clicking:

  • CheckShortURL.com — Reveals the final destination and previews the page.
  • Unshorten.It — Expands the link and rates safety.
  • ExpandURL.net — Fast, no-frills expansion.

Reputable shorteners have built-in protections too. For a deeper look at how modern link services handle security, see our honest review of Lunyb and our 2026 buyer's guide to URL shorteners.

5. Verify HTTPS and the Certificate

Look for https:// at the start of the URL and the padlock icon in your browser's address bar. HTTPS encrypts data between you and the site, which is essential — but it does not mean the site itself is trustworthy. Attackers can and do get free SSL certificates for phishing pages.

Click the padlock to inspect the certificate. A legitimate bank's certificate will be issued to the bank's registered legal entity. A phishing site's certificate is often issued to a random domain with no verifiable organization behind it.

6. Check the Domain's Age and Registration

Phishing domains are typically registered days or hours before an attack. A quick WHOIS lookup at whois.domaintools.com or who.is reveals when a domain was registered. If a site claiming to be your 20-year-old bank was registered last Tuesday, walk away.

Domain AgeTrust LevelRecommended Action
Less than 30 daysVery LowAvoid unless you know the exact source
1-6 monthsLowScan thoroughly before clicking
6 months - 2 yearsModerateVerify with additional checks
2+ years with clean historyHigherStandard caution applies

7. Look for Grammar, Spelling, and Design Red Flags

If you preview the page (via an unshortener or scanner), watch for:

  • Awkward phrasing or obvious translation errors
  • Low-resolution logos or mismatched branding
  • Urgent language: "Act now or your account will be suspended!"
  • Requests for information the real company would never ask for via link (passwords, full SSN, PIN codes)
  • Pop-ups demanding you enable notifications, install software, or grant permissions

Professional companies invest heavily in polished communications. Sloppiness is a strong signal of fraud.

8. Use Browser Built-In Protections

Modern browsers include real-time phishing and malware protection. Make sure these are enabled:

  • Chrome — Settings → Privacy and security → Safe Browsing → Enhanced protection
  • Firefox — Settings → Privacy & Security → Deceptive Content and Dangerous Software Protection (both boxes)
  • Edge — Settings → Privacy → Microsoft Defender SmartScreen (on)
  • Safari — Preferences → Security → Warn when visiting a fraudulent website

These features check every URL you visit against constantly updated blocklists and can block dangerous pages before they load.

9. Consider the Context and Sender

Technical checks matter, but context is often the fastest way to detect fraud. Ask yourself:

  1. Was I expecting this message?
  2. Does the sender normally communicate this way?
  3. Is there pressure to act quickly?
  4. Does the request make sense given my relationship with the sender?
  5. Can I verify through a separate channel (call the person, visit the company's website directly)?

When in doubt, don't click. Open a new browser tab and navigate to the site manually by typing the address you know is correct.

10. Use a Sandbox or Isolated Environment

For advanced users or high-risk situations, open suspicious links inside an isolated environment where malware can't touch your real data. Options include:

  • Browserling or Browser Sandbox — Cloud-based browsers you can use to view the page without local risk.
  • Windows Sandbox — Built into Windows Pro; spins up a disposable Windows instance.
  • A virtual machine — Full isolation using VirtualBox or VMware.

Anything the page tries to install or steal stays trapped in the sandbox and disappears when you close it.

Common Red Flags in Suspicious Links

To recap, treat any link with the following characteristics as high-risk until proven otherwise:

Red FlagWhy It's Suspicious
Misspelled brand namesTyposquatting is a top phishing tactic
Excessive subdomainsHides the true destination domain
Uncommon TLDs (.tk, .top, .zip)Cheap or free, favored by attackers
IP addresses instead of domain namesLegitimate businesses don't share raw IPs
URL contains @ symbolEverything before @ is ignored; used to disguise real destination
Extremely long or obfuscated stringsOften masks tracking or malicious redirects
Shortened link from an unknown senderDestination is hidden

What to Do If You Already Clicked a Suspicious Link

Mistakes happen. If you've clicked something you shouldn't have, act quickly:

  1. Disconnect from the internet — Turn off Wi-Fi and unplug ethernet to stop any active download or data exfiltration.
  2. Do not enter any information — If a login page appeared, close it immediately without typing anything.
  3. Run a full malware scan — Use your installed security software or a reputable free scanner like Malwarebytes.
  4. Change passwords — Start with email and banking, then any account you may have exposed. Use a different device if possible.
  5. Enable two-factor authentication — On every account that supports it, especially email and financial services.
  6. Monitor your accounts — Watch for unauthorized transactions and consider a credit freeze if sensitive data was exposed.
  7. Report the phishing attempt — Forward suspicious emails to reportphishing@apwg.org and, if you're in the US, to the FTC at reportfraud.ftc.gov.

Choosing a Trustworthy Link Shortener

If you're on the sending side — sharing links with an audience — the shortener you choose affects your recipients' trust. Reputable services scan destinations for malware, block known-bad domains, and provide preview features so recipients can verify before clicking. Lunyb, for example, includes destination scanning and a clean, professional-looking domain that recipients are more likely to trust than random-string free shorteners. If you're evaluating options, our 2026 shortener comparison and our Rebrandly review cover the major players in detail.

Frequently Asked Questions

Is a link safe if it starts with HTTPS?

Not necessarily. HTTPS only means the connection between your browser and the server is encrypted — it says nothing about who owns the site or whether the content is malicious. Many phishing sites use HTTPS today because SSL certificates are free and easy to obtain. Always combine HTTPS verification with domain inspection and a reputation check.

How can I check a shortened link without clicking it?

Use a URL expander like CheckShortURL.com or Unshorten.It. Paste the short link, and the tool reveals the final destination along with a safety rating. You can then run that destination through VirusTotal or Google Safe Browsing for a second opinion before deciding to visit.

Can hovering over a link infect my device?

No. Simply hovering your cursor over a link in an email or browser does not trigger any download, script, or connection to the destination. Hovering only asks your local software to display the link's target. Only clicking (or having malicious scripts already running) can initiate a connection.

Are QR codes safer than regular links?QR codes are simply an encoded form of a URL — they carry all the same risks as any other link, and arguably more, because you can't visually inspect the destination before scanning. Use a QR scanner app that shows the decoded URL and asks for confirmation before opening. Treat unexpected QR codes (especially in public places, on flyers, or in emails) with the same skepticism as any unknown link.

What's the fastest single check I can do on any link?

Paste the URL into VirusTotal. In under 10 seconds, you'll see whether any of 70+ major security engines flag it as malicious, along with the domain's reputation history. It's not foolproof against brand-new phishing pages, but it catches the overwhelming majority of known threats and is free with no signup required.

Final Thoughts

Learning how to check if a link is safe is a skill that pays off every single day you use the internet. The techniques in this guide take seconds to apply, and they'll protect you from the vast majority of phishing and malware attacks circulating today. Build the habit of pausing before you click, inspecting the destination, and using free scanning tools whenever anything feels off.

Cybercriminals succeed by exploiting speed and trust. Slowing down for even 30 seconds — hovering, reading the domain, running a quick scan — flips the odds decisively in your favor. Stay curious, stay skeptical, and share these techniques with the less tech-savvy people in your life. Their inbox is a target too.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles