facebook-pixel

How to Check if a Link Is Safe Before Clicking: 2026 Guide

L
Lunyb Security Team
··9 min read

Every day, billions of links flow through emails, text messages, social media posts, and chat apps. Most are harmless, but a small percentage lead to phishing pages, malware downloads, or scam sites designed to steal your money or identity. Knowing how to check if a link is safe before you click is one of the most valuable digital skills you can build in 2026.

This guide walks you through 10 practical methods to verify any URL, the red flags to watch for, and the free tools professionals use to scan suspicious links in seconds.

What Does a "Safe Link" Actually Mean?

A safe link is a URL that points to a legitimate website, uses a secure connection (HTTPS), has not been flagged for malware or phishing, and does not attempt to deceive you about its destination. An unsafe link, by contrast, may redirect you to a spoofed login page, trigger an automatic download, or exploit a browser vulnerability.

Link safety involves three layers: the domain reputation, the transport security (SSL/TLS), and the content served once you arrive. A truly safe link passes all three checks.

Why Checking Links Matters More Than Ever

Phishing attacks now account for over 36% of all data breaches, according to the 2025 Verizon Data Breach Investigations Report. Attackers use AI-generated messages that mimic banks, delivery services, and colleagues with alarming accuracy. A single careless click can lead to:

  • Credential theft and account takeover
  • Ransomware infection on your device or network
  • Financial fraud through fake payment portals
  • Identity theft via harvested personal data
  • Cryptocurrency wallet draining

The good news: nearly all of these attacks can be stopped at the click stage if you take 15 seconds to verify the link first.

10 Ways to Check if a Link Is Safe

1. Hover Over the Link Before Clicking

On desktop, hover your mouse over any hyperlink without clicking. Your browser will display the actual destination URL in the bottom-left corner. On mobile, press and hold the link to see a preview. If the visible text says "paypal.com" but the real URL reads "paypa1-secure.xyz," you have found a phishing attempt.

2. Inspect the Domain Carefully

Attackers rely on lookalike domains. Read the URL from right to left, starting with the top-level domain (.com, .org, .net) and working back to identify the true root domain. Watch for:

  • Character swaps: "rn" for "m," "0" for "o," "1" for "l"
  • Extra words: "apple-support-login.com" instead of "apple.com"
  • Unusual TLDs: ".zip," ".xyz," ".top" often host scams
  • Subdomain tricks: "amazon.com.verify-account.ru" is a Russian domain, not Amazon

3. Check for HTTPS and a Valid Certificate

Legitimate sites use HTTPS, indicated by a padlock icon in the address bar. Click the padlock to view the SSL certificate details. A valid certificate issued to the correct organization is a positive signal, though not a guarantee, since attackers can also obtain free certificates for their phishing domains.

4. Use a URL Scanner

Free online scanners analyze links against multiple threat databases in seconds. The most trusted include:

  • VirusTotal (virustotal.com) - scans against 70+ security engines
  • Google Safe Browsing (transparencyreport.google.com/safe-browsing/search) - checks Google's blocklist
  • URLVoid (urlvoid.com) - reputation report across 30+ blocklists
  • PhishTank (phishtank.org) - community-verified phishing database
  • Sucuri SiteCheck (sitecheck.sucuri.net) - scans for malware and blacklisting

Copy the suspicious link, paste it into one of these tools, and review the report before clicking.

5. Expand Shortened URLs Before Visiting

Short links from services like bit.ly, tinyurl, or t.co hide the true destination. Use an unshortener before clicking:

  • CheckShortURL (checkshorturl.com)
  • Unshorten.it (unshorten.it)
  • ExpandURL (expandurl.net)

Reputable shortening platforms also help here. For example, Lunyb provides link previews and scan-on-click protection so recipients can see where a shortened URL actually leads before committing to the visit. If you want to compare providers, our 2026 URL shortener buyer's guide breaks down the safest options.

6. Look Up the Domain's Age and Owner

Scam sites are typically brand new. Use a WHOIS lookup tool (whois.domaintools.com or who.is) to check when the domain was registered. A "bank" or "crypto exchange" domain that was registered three weeks ago is almost certainly fraudulent. Legitimate businesses usually have domains that are years old with transparent registrant information.

7. Search the URL in Google

Paste the full URL (or just the domain) into Google with quotation marks. If the site is legitimate, you will find references, reviews, and social media presence. If it is a scam, you may find warnings, complaints, or nothing at all, both of which are red flags.

8. Check the Context of the Message

The link itself is only half the equation. Ask:

  1. Was I expecting this message?
  2. Does the sender's email address match the claimed organization exactly?
  3. Is there urgency or fear ("your account will be closed in 24 hours")?
  4. Are there spelling or grammar mistakes?
  5. Does it ask for credentials, payment, or personal information?

If any answer raises suspicion, do not click. Instead, navigate to the organization's website directly by typing the URL yourself.

9. Use Browser and DNS-Level Protection

Modern browsers include built-in Safe Browsing features. Ensure they are enabled in Chrome, Firefox, Edge, and Safari settings. For an extra layer, configure encrypted DNS resolvers that block known malicious domains at the network level:

  • Cloudflare 1.1.1.1 for Families (1.1.1.2)
  • Quad9 (9.9.9.9)
  • NextDNS with threat intelligence filters enabled

These services silently block thousands of phishing and malware domains before your browser even attempts to load them.

10. Open Suspicious Links in a Sandbox

If you must open a link but are not fully confident, use an isolated environment. Free options include:

  • Browserling or Browserstack - view sites in a remote browser
  • urlscan.io - renders the page in a sandbox and shows screenshots, network requests, and any suspicious behavior
  • Windows Sandbox - a disposable virtual environment on Windows 10/11 Pro

This lets you see exactly what the page does without exposing your real device.

Comparison of Free Link-Checking Tools

Tool Best For Speed Shows Screenshot Cost
VirusTotal Multi-engine malware scan 5-15 sec No Free
urlscan.io Full sandbox rendering 20-40 sec Yes Free
Google Safe Browsing Quick blocklist check Instant No Free
URLVoid Domain reputation 10 sec No Free
PhishTank Confirmed phishing lookup Instant No Free
Sucuri SiteCheck Website malware scan 15 sec No Free

Warning Signs a Link Is Probably Unsafe

Even without running a scan, these red flags should stop you from clicking:

  • The URL contains random strings of numbers and letters
  • You see an IP address (like http://192.168.4.22/login) instead of a domain name
  • The domain uses homoglyphs from non-Latin alphabets (Cyrillic "а" looks identical to Latin "a")
  • The link is buried in an unexpected attachment or QR code
  • The sender uses a display name that does not match the email address
  • The page prompts you to install software, disable antivirus, or enable macros
  • You are asked to "verify" your password on a page that arrived unsolicited

Special Cases: QR Codes, PDFs, and Chat Apps

QR Codes

"Quishing" (QR phishing) has exploded since 2023. Before scanning a QR code in the wild (parking meters, restaurant tables, flyers), use a scanner app that shows the destination URL first without opening it. Most modern iOS and Android cameras do this by default; check the URL carefully before tapping.

Links in PDFs and Office Documents

Attackers embed malicious links inside invoices, resumes, and shipping notifications. Hover to reveal the true URL, or open the document in a preview mode (Gmail, Google Drive, or the built-in browser preview) that disables active content.

Chat App Links (WhatsApp, Telegram, Discord)

Messaging platforms often display link previews that can be spoofed. Do not trust the preview image or title; always inspect the actual URL. Be especially cautious of "job offers," "crypto opportunities," and "delivery notifications" from unknown numbers.

What to Do If You Already Clicked a Suspicious Link

If you clicked before verifying, act quickly:

  1. Disconnect from the internet to stop any active download or data exfiltration.
  2. Do not enter any information on the page that opened.
  3. Run a full antivirus scan using Windows Defender, Malwarebytes, or your preferred tool.
  4. Change passwords for any account that may be affected, starting with email and banking.
  5. Enable two-factor authentication on critical accounts if you have not already.
  6. Monitor bank and credit card statements for the next 30-60 days.
  7. Report the link to Google Safe Browsing, PhishTank, and the impersonated brand.

Building Long-Term Habits

The best defense is a routine. Adopt these habits and share them with family, colleagues, and clients:

  • Never click links in unsolicited messages. Navigate to the site manually.
  • Bookmark the login pages for your bank, email, and workplace tools.
  • Use a password manager, which refuses to autofill credentials on lookalike domains.
  • Keep your browser, operating system, and antivirus fully updated.
  • Enable multi-factor authentication everywhere it is offered.
  • When you shorten links you send to others, choose a trustworthy provider. Read our honest Lunyb review or the Rebrandly 2026 review to compare safe options.

Frequently Asked Questions

Can a link infect my device just by clicking it?

Yes, though it is uncommon on fully patched modern browsers. "Drive-by download" attacks exploit unpatched vulnerabilities to execute code the moment a page loads. Most successful attacks still rely on the user entering credentials or downloading a file, but keeping your browser updated is critical.

Is HTTPS enough to prove a website is safe?

No. HTTPS only guarantees the connection is encrypted, not that the site is legitimate. Free certificate authorities like Let's Encrypt issue SSL certificates to anyone, including scammers. Always verify the domain name in addition to the padlock.

Are shortened links inherently dangerous?

Not at all. Shortened links are simply redirects and are used by millions of legitimate businesses. The risk comes from not knowing the destination. Use an unshortener, choose a reputable provider that offers link previews, and inspect the final URL before continuing.

What is the fastest way to check a link on my phone?

Long-press the link to reveal the full URL without opening it. If it looks suspicious, copy the link and paste it into VirusTotal or urlscan.io in your mobile browser. Both tools work well on phones and return results in under a minute.

How do I report a phishing link?

Report to Google Safe Browsing at safebrowsing.google.com/safebrowsing/report_phish, submit to PhishTank, and forward phishing emails to reportphishing@apwg.org. If the link impersonates a specific brand (bank, retailer, courier), also forward it to that company's abuse address, usually abuse@ or phishing@ their domain.

Final Thoughts

Learning how to check if a link is safe is not about paranoia. It is about pausing for 15 seconds before you click, so you can enjoy the internet without fearing every message in your inbox. Combine hovering, domain inspection, a quick scan through VirusTotal or urlscan.io, and healthy skepticism about unsolicited messages, and you will avoid the vast majority of online threats.

Bookmark this guide, share it with the people you care about, and make link-checking as automatic as buckling your seatbelt.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles