How to Check if a Link Is Safe Before Clicking: 2026 Guide
Every day, billions of links are shared through email, social media, messaging apps, and search results. Most are harmless, but a small percentage lead to phishing pages, malware downloads, or scam websites designed to steal your money or identity. Knowing how to check if a link is safe before you click is one of the most valuable digital skills you can develop in 2026.
This guide walks you through practical, free methods to verify any URL, from quick visual checks to professional-grade scanning tools. Whether you received a suspicious email, a shortened link on social media, or an unexpected text message, these techniques will help you stay safe.
Why Link Safety Matters More Than Ever
Malicious links are the number one delivery method for cyberattacks. According to industry reports, over 90% of successful cyberattacks begin with a phishing link. Attackers have grown sophisticated, using URL shorteners, look-alike domains, and AI-generated content to disguise dangerous destinations.
A single click can lead to:
- Credential theft on fake login pages
- Automatic malware downloads (drive-by attacks)
- Financial fraud through fake payment portals
- Ransomware infections that lock your files
- Identity theft using harvested personal data
The good news: with a few habits and free tools, you can identify most threats in under a minute.
Quick Visual Checks You Can Do in Seconds
Before using any tool, train your eyes to spot the most common warning signs. These visual checks catch the majority of low-effort phishing attempts.
1. Hover Before You Click
On desktop, hover your mouse over any hyperlink without clicking. The real destination URL appears in the bottom-left corner of your browser or email client. If the visible text says "paypal.com" but the hover reveals "paypa1-secure.ru", you have your answer.
On mobile, press and hold the link (don't tap) to preview the full URL in a popup.
2. Examine the Domain Carefully
Attackers rely on you glancing quickly. Look at the domain right before the first single slash — that is the true owner of the page.
- Legitimate: https://accounts.google.com/signin
- Fake: https://accounts.google.com.verify-login.co/signin
In the fake example, the real domain is verify-login.co, not Google.
3. Watch for Typosquatting
Common tricks include swapping letters, adding hyphens, or using look-alike characters:
- amaz0n.com (zero instead of "o")
- micros0ft-support.com
- faceb00k-login.net
- rn instead of m (rnicrosoft.com)
4. Check for HTTPS — But Don't Trust It Alone
The padlock icon and "https://" prefix mean the connection is encrypted, but they do not guarantee the site is legitimate. Over 80% of phishing sites now use HTTPS. Treat the padlock as necessary but not sufficient.
Free Online Tools to Scan Any URL
When visual inspection isn't enough, these free scanners analyze links against threat databases and behavioral signals. Copy the suspicious link (right-click → Copy Link Address) and paste it into any of these services — never click first.
Top Link Scanners Compared
| Tool | What It Checks | Best For | Cost |
|---|---|---|---|
| VirusTotal | Scans URL against 70+ antivirus and blocklist engines | Comprehensive multi-engine verdict | Free |
| URLVoid | Reputation across 30+ blocklists, domain age, location | Domain reputation history | Free |
| Google Safe Browsing | Google's own phishing and malware database | Quick single-source check | Free |
| PhishTank | Community-verified phishing URL database | Confirming known phishing sites | Free |
| urlscan.io | Loads URL in sandbox, shows screenshots and behavior | Seeing the page without visiting it | Free tier available |
Step-by-Step: Using VirusTotal
- Go to virustotal.com in your browser
- Click the "URL" tab
- Paste the suspicious link into the search box
- Press Enter and wait for the scan (usually 5–15 seconds)
- Review the results: any red flags from major vendors (Google, Kaspersky, Fortinet, Sophos) should be taken seriously
A clean result across all 70+ engines is a strong safety signal. Even one or two detections from reputable engines warrants caution.
How to Handle Shortened Links
Shortened URLs (bit.ly, t.co, tinyurl, and similar services) hide the real destination, which is convenient for sharing but also useful for attackers. Never click a shortened link from an untrusted source without expanding it first.
Expanding a Short URL
Use a link expander to reveal the full destination before visiting:
- CheckShortURL.com — paste the short link, see the full URL plus a preview
- Unshorten.it — expands and runs basic safety checks
- ExpandURL.net — simple, fast expansion
Choosing a Trustworthy Shortener Yourself
When you create short links, use a reputable service that scans destinations, offers HTTPS by default, and provides transparent analytics. Our 2026 buyer's guide to the best URL shorteners compares the leading providers on safety, features, and pricing. Services like Lunyb add malware filtering and click analytics so recipients can trust the links you share, and enterprise options like Rebrandly offer branded domains that signal legitimacy.
Advanced Verification Techniques
For high-stakes links — bank notifications, invoices, cryptocurrency sites, or messages claiming urgent action — go beyond basic scans.
1. Check the Domain's Age with WHOIS
Legitimate businesses usually own their domains for years. Phishing domains are often registered days or weeks before an attack. Use whois.domaintools.com or who.is to look up any domain's registration date. A domain created three days ago claiming to be your bank is a giant red flag.
2. Preview Pages with urlscan.io
urlscan.io loads the URL inside an isolated sandbox and shows you a screenshot, list of loaded scripts, network requests, and any redirects. You get to see the page without exposing your device. Search the public database first — someone may have already scanned the same link.
3. Inspect Redirect Chains
Malicious links often bounce through multiple redirects to obscure the final destination. Tools like Redirect Detective or wheregoes.com map every hop. If a link claiming to be a shipping tracker redirects through five ad networks and lands on a foreign domain, close it immediately.
4. Verify the Sender Through a Second Channel
If a link arrives from a person or company you know, contact them through a separate verified method — a saved phone number, an official app, or by typing their website directly into your browser. Never use contact details from the suspicious message itself.
Red Flags That Should Stop You Immediately
Even without tools, certain patterns almost always indicate a scam. Treat any link accompanied by these signals as hostile until proven otherwise.
Message Content Warning Signs
- Urgency and threats: "Your account will be closed in 24 hours"
- Unexpected prizes: "You've won a gift card — claim now"
- Payment problems: "Update your billing to avoid suspension"
- Package deliveries you didn't order
- Grammar and spelling errors in supposedly professional messages
- Generic greetings like "Dear Customer" from a company that knows your name
URL Warning Signs
- IP addresses instead of domain names (http://192.168.x.x/login)
- Excessive subdomains (login.secure.verify.account.paypal.example.ru)
- Unusual top-level domains for major brands (.xyz, .top, .click for a supposed bank)
- Special characters or non-Latin lookalikes (Cyrillic "а" instead of Latin "a")
- Random strings of letters and numbers as the domain
Browser and Device Protections to Enable
Your first line of defense should be automatic. Configure these settings once and gain passive protection on every link you encounter.
1. Turn On Enhanced Safe Browsing
Chrome, Firefox, Edge, and Safari all include phishing and malware protection. In Chrome, go to Settings → Privacy and security → Security → Enhanced protection. Similar options exist in other browsers. This checks URLs in real time against threat databases.
2. Use Encrypted DNS
Services like Cloudflare's 1.1.1.1, Quad9 (9.9.9.9), and NextDNS block known malicious domains at the network level — before your browser even loads them. Setup takes two minutes in your device's network settings and works across every app.
3. Keep Everything Updated
Browsers, operating systems, and antivirus software receive threat updates constantly. An outdated browser may miss a warning that a current one would catch. Enable automatic updates everywhere.
4. Use a Password Manager
Password managers only auto-fill credentials on the exact domain they were saved for. If you land on a look-alike phishing page, your manager will refuse to fill — a silent but powerful warning that something is wrong.
A Practical 30-Second Link Safety Checklist
Use this routine every time you encounter a link from an unfamiliar or unexpected source:
- Hover or long-press to see the true URL
- Read the domain right before the first single slash
- Look for typos, extra words, or unusual TLDs
- If shortened, expand it with CheckShortURL or similar
- If uncertain, paste into VirusTotal for a multi-engine scan
- For high-value actions, verify through a second channel
Thirty seconds of caution can prevent hours or years of recovery from identity theft or fraud.
What to Do If You Already Clicked
Mistakes happen. If you clicked a suspicious link, act quickly to limit damage:
- Disconnect from the internet if a download started
- Do not enter any information on the page that loaded
- Close the tab and clear your browser cache and cookies
- Run a full antivirus scan with an updated tool
- Change passwords for any account that might be affected, starting with email and banking
- Enable two-factor authentication everywhere it isn't already on
- Monitor bank and credit card statements for the next 30–90 days
- Report the link to Google Safe Browsing, PhishTank, or the impersonated company
Frequently Asked Questions
Is a link with HTTPS always safe?
No. HTTPS only means the connection between your browser and the server is encrypted — it does not verify the identity or intent of the site owner. Most phishing sites now use free HTTPS certificates. Always combine the padlock check with domain verification and, if unsure, a scan through VirusTotal or urlscan.io.
Can I get a virus just by clicking a link without downloading anything?
Yes, though it is less common than it used to be. "Drive-by downloads" exploit browser or plugin vulnerabilities to install malware silently. Keeping your browser, operating system, and extensions fully updated dramatically reduces this risk. Enabling enhanced safe browsing and encrypted DNS adds another layer.
Are shortened links dangerous?
Shortened links themselves are neutral — they simply forward to another URL. The danger is that you cannot see the destination before clicking. Reputable shortener services scan destinations for malware and offer previews. When receiving a short link, expand it first with a free tool like CheckShortURL. When creating them, choose a trustworthy provider that filters malicious destinations.
What is the safest way to check a link on my phone?
Long-press (don't tap) the link to preview the full URL in a popup. Copy the link instead of opening it, then paste it into VirusTotal or urlscan.io through your mobile browser. On iOS and Android, you can also enable safe browsing features in Chrome or Safari and use an encrypted DNS resolver like Cloudflare's 1.1.1.1 app for network-wide filtering.
How can I tell if an email link is really from my bank?
Never trust the link in the email itself. Instead, open a new browser tab and type your bank's known URL directly, or use the bank's official mobile app. Legitimate banks never ask you to verify credentials, transfer funds, or "confirm your identity" through an emailed link. When in doubt, call the phone number printed on the back of your card — not any number provided in the message.
Final Thoughts
Learning how to check if a link is safe is no longer optional — it is a core digital literacy skill. The combination of visual inspection, free scanning tools, and browser-level protections will catch the overwhelming majority of threats you face. Build the 30-second checklist into your routine, keep your software updated, and stay skeptical of urgency and unexpected messages.
The internet is full of opportunities, and a small amount of caution lets you enjoy them without becoming a statistic. When you share links yourself, choose transparent, safety-focused shortener services so the people who trust you can click with confidence.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Report a Scam Phone Number: A Complete 2026 Guide
Scam calls and texts are relentless, but reporting them is easier than you think. This complete guide covers how to report a scam number to the FTC, FCC, mobile carriers, and international agencies, plus how to protect yourself going forward.
How to Check if Your Password Was Leaked in a Data Breach
Discover how to quickly check if your password was exposed in a data breach using free, trusted tools like Have I Been Pwned and browser password monitors. Learn what to do if your credentials are compromised and how to prevent future leaks.
How to Safely Share Your Location with Family: A Complete 2026 Guide
Location sharing keeps families connected, but careless setup can expose your daily movements to hackers and data brokers. This guide shows you exactly how to share location with family safely — the best apps, privacy settings, and habits to protect everyone involved.
How to Hide Photos with an Encrypted Photo Vault: Complete 2026 Guide
Learn how to hide photos using an encrypted photo vault with strong AES-256 protection. This step-by-step guide covers choosing the right app, importing safely, avoiding common leaks, and building a private photo workflow that actually holds up.