How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide
Every day, more than 3.4 billion phishing emails are sent worldwide, and a single misplaced click on a malicious link can compromise your passwords, drain your bank account, or install ransomware on your device. Learning how to check if a link is safe before clicking is no longer optional—it's a core digital survival skill in 2026.
This guide walks you through practical, tested methods to verify any URL in seconds, whether it arrives by email, text message, social media DM, or a shortened link from an unknown source.
What Does It Mean for a Link to Be "Safe"?
A safe link leads to a legitimate destination that will not attempt to steal your data, install malware, redirect you through malicious infrastructure, or impersonate a trusted brand. Verifying safety involves checking the URL's structure, its reputation, its destination, and the behavior of the page it loads.
Unsafe links generally fall into four categories:
- Phishing links that impersonate real brands to harvest credentials.
- Malware links that trigger automatic downloads or drive-by installs.
- Scam/redirect links that funnel you through affiliate fraud or fake giveaways.
- Tracker-heavy links that quietly build a profile of your behavior.
12 Proven Ways to Check if a Link Is Safe
Below is a layered approach. You don't need to run all 12 checks for every URL—start with the quick visual inspection and escalate to scanners only when something feels off.
1. Hover Before You Click
On desktop, hover your mouse over the link without clicking. The true destination URL appears in the bottom-left corner of your browser or email client. On mobile, long-press the link (don't tap) to preview the full URL. If the visible text says paypal.com but the hover preview shows paypa1-secure-login.ru, that's a phishing attempt.
2. Inspect the Domain Carefully
Read the domain from right to left. The most important part is the section immediately before the first single forward slash. For example, in https://accounts.google.com.verify-login.xyz/signin, the real domain is verify-login.xyz, not google.com. Attackers exploit the fact that most users scan left to right and stop reading too early.
3. Look for HTTPS — But Don't Trust It Blindly
HTTPS (the padlock icon) means the connection is encrypted, but it does not mean the site is legitimate. Since free certificates became universal, more than 80% of phishing sites now use HTTPS. Treat the padlock as a bare minimum, not a stamp of approval.
4. Watch for Typosquatting and Homoglyphs
Attackers register domains that look almost identical to real ones by substituting characters:
rninstead ofm(e.g., arnazon.com)0instead ofo(e.g., micr0soft.com)- Cyrillic "а" instead of Latin "a" (visually identical)
- Extra hyphens (e.g., apple-support-id.com)
If a domain looks slightly "off," open a new tab and type the brand's name directly into your browser instead.
5. Expand Shortened URLs Before Clicking
Shortened links (bit.ly, t.co, tinyurl, and others) hide the destination. Before clicking one from an unknown sender, expand it using a URL unshortener such as CheckShortURL, Unshorten.It, or ExpandURL. Reputable shortening platforms—like Lunyb—also include built-in malware scanning and destination previews, which reduces the risk of blindly following a shortened link.
6. Use Google Safe Browsing
Google maintains one of the world's largest databases of unsafe sites. Paste any URL into https://transparencyreport.google.com/safe-browsing/search to get an instant reputation check. Chrome, Firefox, and Safari all use this database in the background, but the transparency report lets you check proactively.
7. Scan With VirusTotal
VirusTotal (virustotal.com) checks a URL against 70+ security engines including Kaspersky, BitDefender, ESET, and Fortinet. Paste the link into the URL tab and within seconds you'll see how many engines flag it as malicious, suspicious, or clean. A single detection may be a false positive; three or more is a strong warning sign.
8. Try URLVoid or Sucuri SiteCheck
Both tools aggregate reputation data from dozens of blacklists and provide domain age, geolocation, and hosting details. New domains (less than 30 days old) sending you "urgent" messages are a classic phishing indicator.
9. Check WHOIS Data
WHOIS lookup tools (like who.is) reveal when a domain was registered and by whom. A supposedly established bank whose domain was registered three weeks ago through a privacy proxy in a jurisdiction unrelated to the brand is almost certainly fraudulent.
10. Open Suspicious Links in a Sandbox
If you truly need to see what a link loads without risking your device, use a browser sandbox such as Browserling, urlscan.io, or Any.Run. These services open the URL in an isolated remote browser and show you screenshots, redirect chains, and any files the page tries to download.
11. Enable DNS-Level Filtering
Services like Quad9 (9.9.9.9), Cloudflare Family (1.1.1.3), or NextDNS block known malicious domains at the network layer—before your browser ever tries to load them. Set them as your DNS resolver on your router or device and you'll get automatic protection on every click, across every app.
12. Trust Your Gut — and the Context
Was the link unexpected? Does the message create urgency ("Your account will be closed in 24 hours")? Does it ask you to log in, pay, or download something? Is the sender's writing style unusual? Context is often a stronger signal than any technical check. When in doubt, contact the sender through a different channel.
Red Flags That a Link Is Probably Malicious
Even without scanning tools, you can spot most dangerous URLs by looking for these warning signs:
| Red Flag | Why It's Suspicious |
|---|---|
| Misspelled brand name in domain | Typosquatting is the #1 phishing tactic |
| Long string of random characters | Often used to disguise destination or evade filters |
| Unusual TLDs (.zip, .top, .xyz, .click) | Cheap and disproportionately abused by attackers |
| IP address instead of a domain | Legitimate services almost never link via raw IPs |
| @ symbol in the URL | Everything before @ is ignored; hides real destination |
| Excessive subdomains | e.g., login.secure.verify.bank.evil.com |
| Shortened link from a stranger | Destination is hidden until you click |
| Punycode (xn--) domains | Used to disguise foreign character lookalikes |
Comparing the Best Free Link-Checking Tools
Not every scanner is equal. Here's how the most reliable free tools stack up in 2026:
| Tool | Best For | Speed | Shows Redirect Chain | Sandbox Preview |
|---|---|---|---|---|
| Google Safe Browsing | Quick reputation check | Instant | No | No |
| VirusTotal | Multi-engine consensus | 5–15 sec | Yes | Partial |
| urlscan.io | Deep behavioral analysis | 15–30 sec | Yes | Yes |
| Sucuri SiteCheck | Website malware & blacklists | 10–20 sec | Partial | No |
| URLVoid | Domain reputation history | Instant | No | No |
| PhishTank | Community-reported phishing | Instant | No | No |
How to Safely Handle Shortened Links
Shortened URLs are convenient but inherently opaque. Follow this 4-step protocol whenever you receive one from a source you don't fully trust:
- Copy, don't click. Right-click and copy the link address.
- Expand it. Paste into an unshortener to reveal the final destination.
- Scan the destination. Run the expanded URL through VirusTotal or urlscan.io.
- Evaluate the domain. Apply the red-flag checklist above.
Some shortening services provide safer defaults than others. If you're choosing a shortener for your own links, our 2026 buyer's guide to URL shorteners and our Rebrandly review both dig into which platforms include malware scanning, link previews, and abuse monitoring.
Mobile-Specific Link Safety Tips
Mobile devices make link inspection harder because URLs are truncated and hover previews don't exist by default. Adapt with these habits:
- Long-press to preview. Both iOS and Android show the full URL when you press and hold.
- Disable link previews from unknown senders. In Messages and email apps, this prevents remote content from loading automatically.
- Use a mobile browser with built-in protection. Brave, Firefox Focus, and DuckDuckGo browser flag known malicious sites.
- Watch for app-based redirects. Some malicious links deep-link into apps to trigger permissions abuse.
- Keep your OS patched. Many phishing kits exploit known browser vulnerabilities that are fixed in the latest updates.
What to Do if You Already Clicked a Suspicious Link
Don't panic—most malicious pages need you to enter data or download a file to cause real damage. Take these steps in order:
- Disconnect from the internet if a download started. This stops the payload mid-transfer.
- Do not enter any credentials. Close the tab immediately.
- Run a full antivirus scan using Windows Defender, Malwarebytes, or your preferred tool.
- Change passwords for any account you might have exposed—starting with email, then banking.
- Enable two-factor authentication everywhere you haven't already.
- Monitor bank and card statements for the next 60 days.
- Report the link to Google Safe Browsing, PhishTank, and the impersonated brand.
Building Long-Term Habits for Link Safety
Tools help, but consistent habits are what actually keep you safe over time. The most secure users share four traits:
- They never log in from a link. Instead, they open a new tab and navigate to the site directly.
- They use a password manager, which refuses to autofill on lookalike domains—an early phishing warning.
- They enable hardware or app-based two-factor authentication on every sensitive account.
- They slow down. Phishing succeeds because it exploits urgency. Pausing for 10 seconds defuses most attacks.
Frequently Asked Questions
Can I get a virus just from clicking a link?
In most cases, simply visiting a page won't infect you if your browser and operating system are fully patched. However, "drive-by" attacks that exploit unpatched vulnerabilities do still exist, and some pages trigger automatic downloads. The safest approach is to inspect links before clicking, keep your software updated, and use a browser with active phishing and malware protection.
Is HTTPS enough to know a link is safe?
No. HTTPS only means the connection between you and the site is encrypted—not that the site itself is trustworthy. The majority of phishing sites now use HTTPS certificates because they're free and easy to obtain. Always combine the padlock check with domain inspection and a reputation scan.
What's the fastest way to check a link on my phone?
Long-press the link to preview the full URL, then copy it and paste into VirusTotal or Google Safe Browsing. Both work in a mobile browser without needing an app. If the link is shortened, expand it first using a service like CheckShortURL.
Are shortened links always dangerous?
No—shortened links are widely used for legitimate marketing, analytics, and sharing on character-limited platforms. The risk comes from the opacity: you can't see the destination until you click. Reputable shorteners scan destinations for malware and offer preview features. When you receive a shortened link from an unknown source, expand it before clicking regardless of the platform.
Which free tool should I use if I only pick one?
VirusTotal is the best single choice. It aggregates results from 70+ security engines, works on both URLs and files, shows redirect chains, and is completely free with no account required. Bookmark it and paste any suspicious link into it before clicking.
How do I report a phishing link I received?
Forward phishing emails to reportphishing@apwg.org and to the impersonated company (most have a dedicated address like phishing@paypal.com). Submit the URL to Google Safe Browsing, PhishTank, and Microsoft's SmartScreen so it gets blocked for everyone.
Final Thoughts
Learning how to check if a link is safe is one of the highest-leverage security skills you can build. A 30-second inspection habit prevents the overwhelming majority of phishing attacks, malware infections, and account takeovers—without slowing down your day. Combine the visual checks in this guide with a trusted scanner like VirusTotal, and you'll click with confidence in 2026 and beyond.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Set Up Link Retargeting: A Complete Step-by-Step Guide
Link retargeting lets you build advertising audiences from every click on a shortened URL — even links pointing to third-party sites. This step-by-step guide shows you how to set up pixels, choose the right tool, and launch your first retargeting campaign in under an hour.
How to Lock Apps and Photos with Face ID: The Complete 2026 Guide
Learn how to lock apps and photos with Face ID on your iPhone using built-in iOS tools and trusted third-party options. This complete 2026 guide covers step-by-step instructions, hidden albums, notes, troubleshooting, and privacy best practices.
Who Called Me? How to Identify an Unknown Number in 2026
Getting calls from unknown numbers can be unnerving—and sometimes dangerous. This guide covers 8 proven methods to identify unknown callers, spot scams instantly, and protect your phone from unwanted contact in 2026.
How to Shorten a URL: The Complete 2026 Guide
Learn how to shorten a URL with this complete 2026 guide. Discover free tools, custom branded links, mobile methods, API integration, and best practices for safe, effective link sharing.