How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide
Every day, billions of links are shared through email, social media, messaging apps, and search results. Most are harmless, but a small percentage lead to phishing pages, malware downloads, or scam websites designed to steal your money or identity. Knowing how to check if a link is safe before you click has become one of the most important digital safety skills of 2026.
This guide walks you through everything you need: the warning signs of a dangerous link, the best free tools to scan URLs, browser-level protections, and step-by-step methods for verifying shortened links, email links, and unfamiliar domains.
What Makes a Link Unsafe?
An unsafe link is any URL that leads to a destination designed to harm the visitor, steal information, or install unwanted software. Unsafe links generally fall into four categories:
- Phishing links — mimic real login pages (banks, Google, Microsoft, PayPal) to capture credentials.
- Malware links — trigger automatic downloads of viruses, ransomware, or spyware.
- Scam links — lead to fake stores, fake giveaways, romance scams, or investment fraud.
- Tracking/redirect links — chain through multiple servers to fingerprint your device or bypass filters.
The tricky part: most malicious links look nearly identical to legitimate ones. Attackers use lookalike domains (like paypa1.com), hidden redirects, and shortened URLs to disguise their true destination.
7 Warning Signs of a Suspicious Link
Before you use any tool, train your eye. These are the most common red flags:
- Misspelled domains — amaz0n.com, faceb00k-login.com, microsft.com.
- Excessive subdomains — secure.login.account-verify.random-domain.xyz.
- Unusual top-level domains (TLDs) — links ending in .zip, .mov, .tk, or .top are disproportionately abused.
- Urgency or fear language — "Your account will be closed in 24 hours, click here."
- Mismatched anchor text — the visible text says paypal.com but the actual URL points elsewhere.
- No HTTPS — modern legitimate sites use HTTPS; a plain http:// login page is a red flag.
- Shortened links from unknown senders — bit.ly, t.co, or other short links hide the real destination.
If a link triggers two or more of these signs, treat it as hostile until proven otherwise.
How to Check if a Link Is Safe: 6 Reliable Methods
Here are the practical, tested techniques for verifying any URL — from a quick manual inspection to deep sandbox analysis.
1. Hover Before You Click
On desktop, hover your mouse over any link without clicking. Your browser will display the true destination URL in the bottom-left corner. On mobile, press and hold the link to see a preview. This single habit prevents the majority of phishing attacks because it exposes mismatched or disguised destinations instantly.
2. Use a Free URL Scanner
Online scanners compare URLs against threat intelligence databases and, in some cases, actually visit the page in a sandbox. Paste the suspicious link into any of these free tools:
- VirusTotal (virustotal.com) — scans the URL against 90+ antivirus engines and blocklists.
- Google Safe Browsing Transparency Report — check if Google has flagged the site.
- URLVoid — aggregates reputation from 30+ blocklist services.
- PhishTank — community-driven database of known phishing URLs.
- urlscan.io — loads the page in a sandbox and shows every resource, redirect, and script it triggers.
For high-stakes links (banking emails, invoices, password resets), run the URL through at least two of these before clicking.
3. Expand Shortened Links
Shortened URLs (bit.ly, t.co, tinyurl, goo.gl legacy links) hide the real destination. Never click one from an unknown source without expanding it first. Free expanders include:
- CheckShortURL.com
- Unshorten.it
- ExpandURL.net
Reputable short-link platforms also help here. Services like Lunyb and other trusted shorteners scan destinations, block known malicious targets, and let recipients preview the final URL before visiting — which is one reason to prefer shorteners with active abuse protection. For a broader comparison, see our 2026 buyer's guide to the best URL shorteners.
4. Inspect the Domain Carefully
Read the domain from right to left. The true owner of a URL is the part immediately before the TLD (.com, .net, .org). For example:
- login.microsoft.com — owned by microsoft.com ✅
- microsoft.login-verify.com — owned by login-verify.com ❌
Attackers exploit the fact that most people read left to right and stop at the first recognizable brand name.
5. Check Domain Age and WHOIS Data
Legitimate companies rarely operate from domains registered a week ago. Use WHOIS lookup tools (whois.domaintools.com, who.is) to check:
- When the domain was registered — anything under 3 months old is suspicious for a "major brand."
- Whether the registrant info is hidden behind privacy protection (common for scams).
- The registrar's country — mismatches with the claimed business location are a red flag.
6. Use a Sandbox or Isolated Browser
If you absolutely must open a suspicious link, do it in a controlled environment:
- urlscan.io — visits the page for you and returns screenshots and network data.
- Browserling — opens URLs in a remote virtual browser you can watch.
- A separate device with no saved credentials — an old phone with no accounts logged in.
Never open questionable links on the same device you use for banking or work email.
Comparison: Free Link-Checking Tools
Not every scanner is built for the same job. This table breaks down the strengths of the most reliable free options.
| Tool | Best For | Sandbox Preview | Multi-Engine Scan | Free Limit |
|---|---|---|---|---|
| VirusTotal | Malware & blocklist checks | No | Yes (90+ engines) | Unlimited (public) |
| urlscan.io | Full page rendering & redirects | Yes | Partial | Unlimited public scans |
| Google Safe Browsing | Quick reputation check | No | Google only | Unlimited |
| PhishTank | Known phishing URLs | No | No | Unlimited |
| URLVoid | Aggregated blocklist reputation | No | Yes (30+ services) | Unlimited |
How to Check Links on Your Phone
Mobile devices are where most phishing attacks now land — smaller screens make it harder to see the full URL. Use these mobile-specific steps:
- Long-press the link (don't tap) to see a preview of the destination URL.
- Copy the link and paste it into VirusTotal or urlscan.io in your browser.
- Enable Safe Browsing in Chrome (Settings → Privacy and security → Safe Browsing → Enhanced protection).
- Turn on Fraudulent Website Warning in Safari (Settings → Safari → Fraudulent Website Warning).
- Install a security app like Bitdefender Mobile Security or Malwarebytes that scans links in real time.
How to Verify Links in Email
Email remains the number-one delivery method for malicious links. Follow this checklist before clicking anything in a message:
- Verify the sender's real email address — click the sender name to reveal the full address. "Support <support@paypa1-security.co>" is not PayPal.
- Hover over every link to see the true destination.
- Never trust the display name — anyone can send email claiming to be your bank.
- Look for DKIM/SPF pass indicators — Gmail and Outlook show warnings when authentication fails.
- When in doubt, don't click — open a new browser tab and type the company's URL manually.
If the email is about your bank, PayPal, or a delivery service, always go directly to the official app or website instead of clicking the link.
Browser Settings That Block Dangerous Links Automatically
Modern browsers include strong built-in protections that most users never activate. Turn these on today:
Chrome & Edge
- Settings → Privacy and security → Security → Enhanced Protection.
- Enable Always use secure connections to force HTTPS.
- Turn on Warn you if passwords are exposed in a data breach.
Firefox
- Settings → Privacy & Security → Enhanced Tracking Protection: Strict.
- Enable HTTPS-Only Mode.
- Turn on Block dangerous and deceptive content.
Safari
- Settings → Safari → Privacy & Security → Fraudulent Website Warning.
- Enable Prevent Cross-Site Tracking.
You can also switch your device's DNS to a filtering resolver like 1.1.1.2 (Cloudflare for Families), Quad9 (9.9.9.9), or NextDNS, which block malicious domains at the network level before your browser even loads them.
Pros and Cons of Automated Link Scanners
Pros
- Detect known malware and phishing sites in seconds.
- Free and require no software installation.
- Show full redirect chains and page content without you visiting.
- Cross-reference dozens of threat databases simultaneously.
Cons
- Cannot detect brand-new (zero-day) phishing sites not yet indexed.
- Some scanners cache old results — a recently cleaned site may still show as safe.
- Publicly submitted scans on urlscan.io may expose sensitive URLs; use the private option for internal links.
- No tool replaces critical thinking — social engineering can bypass every scanner.
Special Case: Verifying Shortened Links from Trusted Platforms
Not all shortened links are dangerous — many businesses use them for tracking and branding. The safest short links come from platforms that:
- Scan destinations for malware in real time.
- Offer branded custom domains that build trust.
- Provide analytics and let owners deactivate compromised links.
- Publish transparent abuse policies.
If you're evaluating shortening services for your own business, our honest review of Lunyb and our 2026 Rebrandly review break down how the leading options handle safety, privacy, and reliability.
What to Do If You Already Clicked a Suspicious Link
If you clicked before checking, act fast:
- Disconnect from the internet if a download started.
- Do not enter any information on the page — close the tab immediately.
- Run a full malware scan using Malwarebytes, Bitdefender, or Windows Defender.
- Change passwords for any account you may have exposed — start with email and banking.
- Enable two-factor authentication on every critical account if you haven't already.
- Monitor bank and credit card statements for the next 30 days.
- Report the link to Google Safe Browsing, PhishTank, and the impersonated company.
Frequently Asked Questions
Can I get a virus just from clicking a link?
In most cases, simply clicking a modern link won't infect a fully updated browser. However, drive-by downloads, exploit kits targeting outdated browsers, and social engineering (tricking you to download a fake update) can absolutely infect your device. Keep your browser and OS patched and never install anything a linked page prompts you to.
Is HTTPS a guarantee that a link is safe?
No. HTTPS only means the connection between you and the site is encrypted — it says nothing about whether the site itself is legitimate. Scammers can and do buy free SSL certificates for phishing pages. Always combine the HTTPS check with domain verification and a URL scanner.
What's the fastest way to check a link if I'm in a hurry?
Copy the URL and paste it into VirusTotal or urlscan.io. Both return a verdict in under 30 seconds and require no account. If either flags the URL, do not click it.
Are all shortened links dangerous?
No. Shortened links from reputable platforms with active malware scanning and abuse teams are generally safe. The risk comes from short links sent by strangers or posted in unmoderated spaces. Use a link expander to see the final destination whenever the source is unknown.
Do I need paid antivirus software to stay safe from bad links?
Not necessarily. A combination of an up-to-date browser with Enhanced Safe Browsing, a filtering DNS resolver like Quad9, and habitual use of free scanners like VirusTotal protects most users. Paid tools add convenience and real-time link scanning, but the free layer is strong on its own.
Final Thoughts
Learning how to check if a link is safe isn't about installing more software — it's about building a two-second habit: hover, inspect the domain, and scan when in doubt. Combine that habit with a well-configured browser, filtering DNS, and trusted platforms for the links you share yourself, and you'll neutralize the overwhelming majority of link-based threats before they ever reach you.
The internet will keep getting more crowded with malicious URLs, but the fundamentals of link safety haven't changed. Slow down, verify, and only click when you're confident.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Use UTM Parameters with Short Links: A Complete Guide
UTM parameters tell you exactly where your traffic comes from, but they create ugly, unwieldy URLs. Combining them with short links gives you precise campaign tracking plus clean, shareable links. This guide walks through the entire workflow with examples.
How to Password Protect a Short Link: Complete 2026 Guide
Learn how to password protect a short link with step-by-step instructions, tool comparisons, and best practices. Secure sensitive URLs, gate premium content, and control access without complex setup.
How to Report a Scam Phone Number: A Complete 2026 Guide
Scam calls and texts are relentless, but reporting them is easier than you think. This complete guide covers how to report a scam number to the FTC, FCC, mobile carriers, and international agencies, plus how to protect yourself going forward.
How to Check if Your Password Was Leaked in a Data Breach
Discover how to quickly check if your password was exposed in a data breach using free, trusted tools like Have I Been Pwned and browser password monitors. Learn what to do if your credentials are compromised and how to prevent future leaks.