facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··9 min read

Every day, more than 3.4 billion phishing emails are sent worldwide, and a single misplaced click on a malicious link can compromise your passwords, drain your bank account, or install ransomware on your device. Learning how to check if a link is safe before clicking is no longer optional—it's a core digital survival skill in 2026.

This guide walks you through practical, tested methods to verify any URL in seconds, whether it arrives by email, text message, social media DM, or a shortened link from an unknown source.

What Does It Mean for a Link to Be "Safe"?

A safe link leads to a legitimate destination that will not attempt to steal your data, install malware, redirect you through malicious infrastructure, or impersonate a trusted brand. Verifying safety involves checking the URL's structure, its reputation, its destination, and the behavior of the page it loads.

Unsafe links generally fall into four categories:

  • Phishing links that impersonate real brands to harvest credentials.
  • Malware links that trigger automatic downloads or drive-by installs.
  • Scam/redirect links that funnel you through affiliate fraud or fake giveaways.
  • Tracker-heavy links that quietly build a profile of your behavior.

12 Proven Ways to Check if a Link Is Safe

Below is a layered approach. You don't need to run all 12 checks for every URL—start with the quick visual inspection and escalate to scanners only when something feels off.

1. Hover Before You Click

On desktop, hover your mouse over the link without clicking. The true destination URL appears in the bottom-left corner of your browser or email client. On mobile, long-press the link (don't tap) to preview the full URL. If the visible text says paypal.com but the hover preview shows paypa1-secure-login.ru, that's a phishing attempt.

2. Inspect the Domain Carefully

Read the domain from right to left. The most important part is the section immediately before the first single forward slash. For example, in https://accounts.google.com.verify-login.xyz/signin, the real domain is verify-login.xyz, not google.com. Attackers exploit the fact that most users scan left to right and stop reading too early.

3. Look for HTTPS — But Don't Trust It Blindly

HTTPS (the padlock icon) means the connection is encrypted, but it does not mean the site is legitimate. Since free certificates became universal, more than 80% of phishing sites now use HTTPS. Treat the padlock as a bare minimum, not a stamp of approval.

4. Watch for Typosquatting and Homoglyphs

Attackers register domains that look almost identical to real ones by substituting characters:

  • rn instead of m (e.g., arnazon.com)
  • 0 instead of o (e.g., micr0soft.com)
  • Cyrillic "а" instead of Latin "a" (visually identical)
  • Extra hyphens (e.g., apple-support-id.com)

If a domain looks slightly "off," open a new tab and type the brand's name directly into your browser instead.

5. Expand Shortened URLs Before Clicking

Shortened links (bit.ly, t.co, tinyurl, and others) hide the destination. Before clicking one from an unknown sender, expand it using a URL unshortener such as CheckShortURL, Unshorten.It, or ExpandURL. Reputable shortening platforms—like Lunyb—also include built-in malware scanning and destination previews, which reduces the risk of blindly following a shortened link.

6. Use Google Safe Browsing

Google maintains one of the world's largest databases of unsafe sites. Paste any URL into https://transparencyreport.google.com/safe-browsing/search to get an instant reputation check. Chrome, Firefox, and Safari all use this database in the background, but the transparency report lets you check proactively.

7. Scan With VirusTotal

VirusTotal (virustotal.com) checks a URL against 70+ security engines including Kaspersky, BitDefender, ESET, and Fortinet. Paste the link into the URL tab and within seconds you'll see how many engines flag it as malicious, suspicious, or clean. A single detection may be a false positive; three or more is a strong warning sign.

8. Try URLVoid or Sucuri SiteCheck

Both tools aggregate reputation data from dozens of blacklists and provide domain age, geolocation, and hosting details. New domains (less than 30 days old) sending you "urgent" messages are a classic phishing indicator.

9. Check WHOIS Data

WHOIS lookup tools (like who.is) reveal when a domain was registered and by whom. A supposedly established bank whose domain was registered three weeks ago through a privacy proxy in a jurisdiction unrelated to the brand is almost certainly fraudulent.

10. Open Suspicious Links in a Sandbox

If you truly need to see what a link loads without risking your device, use a browser sandbox such as Browserling, urlscan.io, or Any.Run. These services open the URL in an isolated remote browser and show you screenshots, redirect chains, and any files the page tries to download.

11. Enable DNS-Level Filtering

Services like Quad9 (9.9.9.9), Cloudflare Family (1.1.1.3), or NextDNS block known malicious domains at the network layer—before your browser ever tries to load them. Set them as your DNS resolver on your router or device and you'll get automatic protection on every click, across every app.

12. Trust Your Gut — and the Context

Was the link unexpected? Does the message create urgency ("Your account will be closed in 24 hours")? Does it ask you to log in, pay, or download something? Is the sender's writing style unusual? Context is often a stronger signal than any technical check. When in doubt, contact the sender through a different channel.

Red Flags That a Link Is Probably Malicious

Even without scanning tools, you can spot most dangerous URLs by looking for these warning signs:

Red Flag Why It's Suspicious
Misspelled brand name in domainTyposquatting is the #1 phishing tactic
Long string of random charactersOften used to disguise destination or evade filters
Unusual TLDs (.zip, .top, .xyz, .click)Cheap and disproportionately abused by attackers
IP address instead of a domainLegitimate services almost never link via raw IPs
@ symbol in the URLEverything before @ is ignored; hides real destination
Excessive subdomainse.g., login.secure.verify.bank.evil.com
Shortened link from a strangerDestination is hidden until you click
Punycode (xn--) domainsUsed to disguise foreign character lookalikes

Comparing the Best Free Link-Checking Tools

Not every scanner is equal. Here's how the most reliable free tools stack up in 2026:

Tool Best For Speed Shows Redirect Chain Sandbox Preview
Google Safe BrowsingQuick reputation checkInstantNoNo
VirusTotalMulti-engine consensus5–15 secYesPartial
urlscan.ioDeep behavioral analysis15–30 secYesYes
Sucuri SiteCheckWebsite malware & blacklists10–20 secPartialNo
URLVoidDomain reputation historyInstantNoNo
PhishTankCommunity-reported phishingInstantNoNo

How to Safely Handle Shortened Links

Shortened URLs are convenient but inherently opaque. Follow this 4-step protocol whenever you receive one from a source you don't fully trust:

  1. Copy, don't click. Right-click and copy the link address.
  2. Expand it. Paste into an unshortener to reveal the final destination.
  3. Scan the destination. Run the expanded URL through VirusTotal or urlscan.io.
  4. Evaluate the domain. Apply the red-flag checklist above.

Some shortening services provide safer defaults than others. If you're choosing a shortener for your own links, our 2026 buyer's guide to URL shorteners and our Rebrandly review both dig into which platforms include malware scanning, link previews, and abuse monitoring.

Mobile-Specific Link Safety Tips

Mobile devices make link inspection harder because URLs are truncated and hover previews don't exist by default. Adapt with these habits:

  • Long-press to preview. Both iOS and Android show the full URL when you press and hold.
  • Disable link previews from unknown senders. In Messages and email apps, this prevents remote content from loading automatically.
  • Use a mobile browser with built-in protection. Brave, Firefox Focus, and DuckDuckGo browser flag known malicious sites.
  • Watch for app-based redirects. Some malicious links deep-link into apps to trigger permissions abuse.
  • Keep your OS patched. Many phishing kits exploit known browser vulnerabilities that are fixed in the latest updates.

What to Do if You Already Clicked a Suspicious Link

Don't panic—most malicious pages need you to enter data or download a file to cause real damage. Take these steps in order:

  1. Disconnect from the internet if a download started. This stops the payload mid-transfer.
  2. Do not enter any credentials. Close the tab immediately.
  3. Run a full antivirus scan using Windows Defender, Malwarebytes, or your preferred tool.
  4. Change passwords for any account you might have exposed—starting with email, then banking.
  5. Enable two-factor authentication everywhere you haven't already.
  6. Monitor bank and card statements for the next 60 days.
  7. Report the link to Google Safe Browsing, PhishTank, and the impersonated brand.

Building Long-Term Habits for Link Safety

Tools help, but consistent habits are what actually keep you safe over time. The most secure users share four traits:

  • They never log in from a link. Instead, they open a new tab and navigate to the site directly.
  • They use a password manager, which refuses to autofill on lookalike domains—an early phishing warning.
  • They enable hardware or app-based two-factor authentication on every sensitive account.
  • They slow down. Phishing succeeds because it exploits urgency. Pausing for 10 seconds defuses most attacks.

Frequently Asked Questions

Can I get a virus just from clicking a link?

In most cases, simply visiting a page won't infect you if your browser and operating system are fully patched. However, "drive-by" attacks that exploit unpatched vulnerabilities do still exist, and some pages trigger automatic downloads. The safest approach is to inspect links before clicking, keep your software updated, and use a browser with active phishing and malware protection.

Is HTTPS enough to know a link is safe?

No. HTTPS only means the connection between you and the site is encrypted—not that the site itself is trustworthy. The majority of phishing sites now use HTTPS certificates because they're free and easy to obtain. Always combine the padlock check with domain inspection and a reputation scan.

What's the fastest way to check a link on my phone?

Long-press the link to preview the full URL, then copy it and paste into VirusTotal or Google Safe Browsing. Both work in a mobile browser without needing an app. If the link is shortened, expand it first using a service like CheckShortURL.

Are shortened links always dangerous?

No—shortened links are widely used for legitimate marketing, analytics, and sharing on character-limited platforms. The risk comes from the opacity: you can't see the destination until you click. Reputable shorteners scan destinations for malware and offer preview features. When you receive a shortened link from an unknown source, expand it before clicking regardless of the platform.

Which free tool should I use if I only pick one?

VirusTotal is the best single choice. It aggregates results from 70+ security engines, works on both URLs and files, shows redirect chains, and is completely free with no account required. Bookmark it and paste any suspicious link into it before clicking.

How do I report a phishing link I received?

Forward phishing emails to reportphishing@apwg.org and to the impersonated company (most have a dedicated address like phishing@paypal.com). Submit the URL to Google Safe Browsing, PhishTank, and Microsoft's SmartScreen so it gets blocked for everyone.

Final Thoughts

Learning how to check if a link is safe is one of the highest-leverage security skills you can build. A 30-second inspection habit prevents the overwhelming majority of phishing attacks, malware infections, and account takeovers—without slowing down your day. Combine the visual checks in this guide with a trusted scanner like VirusTotal, and you'll click with confidence in 2026 and beyond.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles