facebook-pixel

How to Check if a Link Is Safe Before Clicking: 2026 Guide

L
Lunyb Security Team
··10 min read

Every day, billions of links are shared through email, social media, messaging apps, and search results. Most are harmless, but a small percentage lead to phishing pages, malware downloads, or scam websites designed to steal your money or identity. Knowing how to check if a link is safe before you click is one of the most valuable digital skills you can develop in 2026.

This guide walks you through practical, free methods to verify any URL, from quick visual checks to professional-grade scanning tools. Whether you received a suspicious email, a shortened link on social media, or an unexpected text message, these techniques will help you stay safe.

Why Link Safety Matters More Than Ever

Malicious links are the number one delivery method for cyberattacks. According to industry reports, over 90% of successful cyberattacks begin with a phishing link. Attackers have grown sophisticated, using URL shorteners, look-alike domains, and AI-generated content to disguise dangerous destinations.

A single click can lead to:

  • Credential theft on fake login pages
  • Automatic malware downloads (drive-by attacks)
  • Financial fraud through fake payment portals
  • Ransomware infections that lock your files
  • Identity theft using harvested personal data

The good news: with a few habits and free tools, you can identify most threats in under a minute.

Quick Visual Checks You Can Do in Seconds

Before using any tool, train your eyes to spot the most common warning signs. These visual checks catch the majority of low-effort phishing attempts.

1. Hover Before You Click

On desktop, hover your mouse over any hyperlink without clicking. The real destination URL appears in the bottom-left corner of your browser or email client. If the visible text says "paypal.com" but the hover reveals "paypa1-secure.ru", you have your answer.

On mobile, press and hold the link (don't tap) to preview the full URL in a popup.

2. Examine the Domain Carefully

Attackers rely on you glancing quickly. Look at the domain right before the first single slash — that is the true owner of the page.

  • Legitimate: https://accounts.google.com/signin
  • Fake: https://accounts.google.com.verify-login.co/signin

In the fake example, the real domain is verify-login.co, not Google.

3. Watch for Typosquatting

Common tricks include swapping letters, adding hyphens, or using look-alike characters:

  • amaz0n.com (zero instead of "o")
  • micros0ft-support.com
  • faceb00k-login.net
  • rn instead of m (rnicrosoft.com)

4. Check for HTTPS — But Don't Trust It Alone

The padlock icon and "https://" prefix mean the connection is encrypted, but they do not guarantee the site is legitimate. Over 80% of phishing sites now use HTTPS. Treat the padlock as necessary but not sufficient.

Free Online Tools to Scan Any URL

When visual inspection isn't enough, these free scanners analyze links against threat databases and behavioral signals. Copy the suspicious link (right-click → Copy Link Address) and paste it into any of these services — never click first.

Top Link Scanners Compared

Tool What It Checks Best For Cost
VirusTotal Scans URL against 70+ antivirus and blocklist engines Comprehensive multi-engine verdict Free
URLVoid Reputation across 30+ blocklists, domain age, location Domain reputation history Free
Google Safe Browsing Google's own phishing and malware database Quick single-source check Free
PhishTank Community-verified phishing URL database Confirming known phishing sites Free
urlscan.io Loads URL in sandbox, shows screenshots and behavior Seeing the page without visiting it Free tier available

Step-by-Step: Using VirusTotal

  1. Go to virustotal.com in your browser
  2. Click the "URL" tab
  3. Paste the suspicious link into the search box
  4. Press Enter and wait for the scan (usually 5–15 seconds)
  5. Review the results: any red flags from major vendors (Google, Kaspersky, Fortinet, Sophos) should be taken seriously

A clean result across all 70+ engines is a strong safety signal. Even one or two detections from reputable engines warrants caution.

How to Handle Shortened Links

Shortened URLs (bit.ly, t.co, tinyurl, and similar services) hide the real destination, which is convenient for sharing but also useful for attackers. Never click a shortened link from an untrusted source without expanding it first.

Expanding a Short URL

Use a link expander to reveal the full destination before visiting:

  • CheckShortURL.com — paste the short link, see the full URL plus a preview
  • Unshorten.it — expands and runs basic safety checks
  • ExpandURL.net — simple, fast expansion

Choosing a Trustworthy Shortener Yourself

When you create short links, use a reputable service that scans destinations, offers HTTPS by default, and provides transparent analytics. Our 2026 buyer's guide to the best URL shorteners compares the leading providers on safety, features, and pricing. Services like Lunyb add malware filtering and click analytics so recipients can trust the links you share, and enterprise options like Rebrandly offer branded domains that signal legitimacy.

Advanced Verification Techniques

For high-stakes links — bank notifications, invoices, cryptocurrency sites, or messages claiming urgent action — go beyond basic scans.

1. Check the Domain's Age with WHOIS

Legitimate businesses usually own their domains for years. Phishing domains are often registered days or weeks before an attack. Use whois.domaintools.com or who.is to look up any domain's registration date. A domain created three days ago claiming to be your bank is a giant red flag.

2. Preview Pages with urlscan.io

urlscan.io loads the URL inside an isolated sandbox and shows you a screenshot, list of loaded scripts, network requests, and any redirects. You get to see the page without exposing your device. Search the public database first — someone may have already scanned the same link.

3. Inspect Redirect Chains

Malicious links often bounce through multiple redirects to obscure the final destination. Tools like Redirect Detective or wheregoes.com map every hop. If a link claiming to be a shipping tracker redirects through five ad networks and lands on a foreign domain, close it immediately.

4. Verify the Sender Through a Second Channel

If a link arrives from a person or company you know, contact them through a separate verified method — a saved phone number, an official app, or by typing their website directly into your browser. Never use contact details from the suspicious message itself.

Red Flags That Should Stop You Immediately

Even without tools, certain patterns almost always indicate a scam. Treat any link accompanied by these signals as hostile until proven otherwise.

Message Content Warning Signs

  • Urgency and threats: "Your account will be closed in 24 hours"
  • Unexpected prizes: "You've won a gift card — claim now"
  • Payment problems: "Update your billing to avoid suspension"
  • Package deliveries you didn't order
  • Grammar and spelling errors in supposedly professional messages
  • Generic greetings like "Dear Customer" from a company that knows your name

URL Warning Signs

  • IP addresses instead of domain names (http://192.168.x.x/login)
  • Excessive subdomains (login.secure.verify.account.paypal.example.ru)
  • Unusual top-level domains for major brands (.xyz, .top, .click for a supposed bank)
  • Special characters or non-Latin lookalikes (Cyrillic "а" instead of Latin "a")
  • Random strings of letters and numbers as the domain

Browser and Device Protections to Enable

Your first line of defense should be automatic. Configure these settings once and gain passive protection on every link you encounter.

1. Turn On Enhanced Safe Browsing

Chrome, Firefox, Edge, and Safari all include phishing and malware protection. In Chrome, go to Settings → Privacy and security → Security → Enhanced protection. Similar options exist in other browsers. This checks URLs in real time against threat databases.

2. Use Encrypted DNS

Services like Cloudflare's 1.1.1.1, Quad9 (9.9.9.9), and NextDNS block known malicious domains at the network level — before your browser even loads them. Setup takes two minutes in your device's network settings and works across every app.

3. Keep Everything Updated

Browsers, operating systems, and antivirus software receive threat updates constantly. An outdated browser may miss a warning that a current one would catch. Enable automatic updates everywhere.

4. Use a Password Manager

Password managers only auto-fill credentials on the exact domain they were saved for. If you land on a look-alike phishing page, your manager will refuse to fill — a silent but powerful warning that something is wrong.

A Practical 30-Second Link Safety Checklist

Use this routine every time you encounter a link from an unfamiliar or unexpected source:

  1. Hover or long-press to see the true URL
  2. Read the domain right before the first single slash
  3. Look for typos, extra words, or unusual TLDs
  4. If shortened, expand it with CheckShortURL or similar
  5. If uncertain, paste into VirusTotal for a multi-engine scan
  6. For high-value actions, verify through a second channel

Thirty seconds of caution can prevent hours or years of recovery from identity theft or fraud.

What to Do If You Already Clicked

Mistakes happen. If you clicked a suspicious link, act quickly to limit damage:

  1. Disconnect from the internet if a download started
  2. Do not enter any information on the page that loaded
  3. Close the tab and clear your browser cache and cookies
  4. Run a full antivirus scan with an updated tool
  5. Change passwords for any account that might be affected, starting with email and banking
  6. Enable two-factor authentication everywhere it isn't already on
  7. Monitor bank and credit card statements for the next 30–90 days
  8. Report the link to Google Safe Browsing, PhishTank, or the impersonated company

Frequently Asked Questions

Is a link with HTTPS always safe?

No. HTTPS only means the connection between your browser and the server is encrypted — it does not verify the identity or intent of the site owner. Most phishing sites now use free HTTPS certificates. Always combine the padlock check with domain verification and, if unsure, a scan through VirusTotal or urlscan.io.

Can I get a virus just by clicking a link without downloading anything?

Yes, though it is less common than it used to be. "Drive-by downloads" exploit browser or plugin vulnerabilities to install malware silently. Keeping your browser, operating system, and extensions fully updated dramatically reduces this risk. Enabling enhanced safe browsing and encrypted DNS adds another layer.

Are shortened links dangerous?

Shortened links themselves are neutral — they simply forward to another URL. The danger is that you cannot see the destination before clicking. Reputable shortener services scan destinations for malware and offer previews. When receiving a short link, expand it first with a free tool like CheckShortURL. When creating them, choose a trustworthy provider that filters malicious destinations.

What is the safest way to check a link on my phone?

Long-press (don't tap) the link to preview the full URL in a popup. Copy the link instead of opening it, then paste it into VirusTotal or urlscan.io through your mobile browser. On iOS and Android, you can also enable safe browsing features in Chrome or Safari and use an encrypted DNS resolver like Cloudflare's 1.1.1.1 app for network-wide filtering.

How can I tell if an email link is really from my bank?

Never trust the link in the email itself. Instead, open a new browser tab and type your bank's known URL directly, or use the bank's official mobile app. Legitimate banks never ask you to verify credentials, transfer funds, or "confirm your identity" through an emailed link. When in doubt, call the phone number printed on the back of your card — not any number provided in the message.

Final Thoughts

Learning how to check if a link is safe is no longer optional — it is a core digital literacy skill. The combination of visual inspection, free scanning tools, and browser-level protections will catch the overwhelming majority of threats you face. Build the 30-second checklist into your routine, keep your software updated, and stay skeptical of urgency and unexpected messages.

The internet is full of opportunities, and a small amount of caution lets you enjoy them without becoming a statistic. When you share links yourself, choose transparent, safety-focused shortener services so the people who trust you can click with confidence.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles