facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··8 min read

Every day, billions of links are shared through email, social media, and messaging apps — and a growing number of them lead to phishing pages, malware downloads, or scam sites. Knowing how to check if a link is safe before clicking is no longer optional; it's a fundamental digital literacy skill. This guide walks you through the exact tools, techniques, and warning signs that security professionals use to verify URLs in seconds.

Why Checking Links Before Clicking Matters

A single click on a malicious link can trigger credential theft, drive-by malware downloads, or session hijacking. According to industry threat reports, phishing remains the #1 initial attack vector, and shortened or disguised URLs are the delivery mechanism of choice.

The good news: verifying a link takes less than 30 seconds when you know what to look for. The bad news: attackers are getting better at making dangerous URLs look legitimate, which is why relying on your gut alone is no longer enough.

Common Threats Hidden Behind Links

  • Phishing pages — fake login screens designed to steal usernames and passwords.
  • Malware droppers — sites that automatically download trojans, ransomware, or spyware.
  • Scam redirects — pages promising prizes, refunds, or urgent action to extract personal data.
  • Cryptocurrency drainers — malicious dApps that empty connected wallets on a single approval.
  • Tracking traps — URLs that fingerprint your device or leak your IP and location.

7 Warning Signs a Link May Be Unsafe

Before touching any tool, train your eyes to catch these red flags. Most malicious URLs give themselves away if you slow down for five seconds.

  1. Misspelled domains — paypa1.com, arnazon-support.net, or g00gle.com. Attackers rely on lookalike characters.
  2. Suspicious subdomains — paypal.com.secure-login.xyz is NOT PayPal; the real domain is whatever appears just before the final .com/.net/.org.
  3. Uncommon TLDs — legitimate brands rarely use .zip, .top, .click, or .xyz for login pages.
  4. Excessive hyphens or numbers — apple-id-verify-2026-secure.com screams phishing.
  5. Urgency or fear in the surrounding message — "Your account will be closed in 24 hours!"
  6. Mismatched anchor text — the visible text says bank.com but hovering reveals a different URL.
  7. Unexpected shortened links — from senders who don't usually send them, especially in DMs or SMS.

How to Check if a Link Is Safe: 8 Proven Methods

Here are the most reliable techniques, ordered from fastest to most thorough. Combine two or three for high-risk links.

1. Hover to Preview the Real URL

On desktop, hover your mouse over any hyperlink without clicking. The true destination appears in the bottom-left corner of your browser or email client. On mobile, press and hold the link until a preview menu appears. If the preview URL doesn't match the visible text, don't click.

2. Use a Link Scanner Service

Free online scanners check URLs against dozens of threat databases in seconds. Paste the suspicious link into one of these:

  • Google Safe Browsing (transparencyreport.google.com/safe-browsing/search)
  • VirusTotal — cross-references 70+ security engines
  • URLVoid — reputation report from 30+ blocklists
  • PhishTank — community-verified phishing database
  • Sucuri SiteCheck — scans for malware and blacklist status

3. Expand Shortened URLs Before Clicking

Short links from services like bit.ly, t.co, tinyurl, or custom shorteners hide the final destination. Use an unshortener before you click:

  • CheckShortURL.com
  • Unshorten.It
  • ExpandURL.net

These tools reveal the full destination plus a safety rating. Reputable shortener platforms like Lunyb actually help here — they run link-level abuse detection and let recipients preview destinations, which is a big advantage over generic shorteners. If you use short links professionally, choosing a trustworthy provider matters for your audience's safety too; our 2026 URL shortener comparison breaks down which platforms take safety seriously.

4. Inspect the Domain Carefully

Read the URL from right to left. The root domain is the part directly before the top-level domain (.com, .org, .net). Everything to the left of that can be faked.

Example: In https://login.microsoft.com.verify-account.ru/signin, the real domain is verify-account.ru — not Microsoft. This one trick catches the majority of phishing attempts.

5. Check the WHOIS Registration

Legitimate businesses have domains registered for years. Phishing sites are often registered days before the attack. Use whois.domaintools.com or who.is to check:

  • Domain age (under 90 days = suspicious)
  • Registrar (obscure registrars are a yellow flag)
  • Country of registration vs. claimed business location

6. Verify HTTPS — But Don't Trust It Blindly

The padlock icon means traffic is encrypted, not that the site is trustworthy. Free SSL certificates are issued in minutes to anyone, including scammers. HTTPS is a minimum requirement — never a guarantee of safety.

7. Preview Pages in a Sandbox

For high-risk links, open them inside an isolated environment where malware can't touch your real device:

  • urlscan.io — renders the page in a sandbox and shows screenshots, redirects, and scripts loaded.
  • Browserling or Hybrid Analysis — full behavior analysis.
  • Google Cache — view a text snapshot without executing scripts.

8. Enable Browser and DNS-Level Protection

Modern browsers block known malicious sites automatically — but only if the feature is turned on. Enable Enhanced Safe Browsing in Chrome, SmartScreen in Edge, or Enhanced Tracking Protection in Firefox. For an extra layer, switch your device to an encrypted DNS resolver like 1.1.1.1 for Families, Quad9, or NextDNS, which block malware and phishing domains at the network level before your browser ever loads them.

Link Safety Tools Compared

Not every tool is the right one for every situation. Here's a quick comparison of the most useful options:

Tool Best For Speed Cost Depth
Google Safe Browsing Quick reputation check Instant Free Basic
VirusTotal Multi-engine scan 5-10 sec Free High
urlscan.io Sandboxed page preview 10-30 sec Free Very high
URLVoid Blocklist aggregation 5 sec Free Medium
CheckShortURL Expanding short links Instant Free Basic
WHOIS lookup Domain age & ownership 5 sec Free Medium
Hybrid Analysis Malware behavior 1-3 min Free Very high

How to Check Links on Mobile Devices

Mobile is where most people get caught, because hover previews don't exist by default. Here's how to stay safe on phones and tablets.

On iOS

  1. Long-press any link in Safari, Messages, or Mail to see the full URL preview.
  2. Enable Settings → Safari → Fraudulent Website Warning.
  3. Use Mail's built-in link previews before tapping.

On Android

  1. Long-press links in Chrome to see the destination.
  2. Enable Chrome → Settings → Privacy and Security → Safe Browsing → Enhanced Protection.
  3. Install a reputable mobile security app that scans links in messaging apps.

In Messaging Apps

WhatsApp, Telegram, and Signal don't scan links for you. Copy the URL and paste it into VirusTotal or urlscan.io before opening. Never tap links from unknown senders — even if the message appears to come from a known contact whose account may be compromised.

What to Do If You Already Clicked a Suspicious Link

If you clicked before checking, don't panic — but act fast.

  1. Disconnect from the internet to stop any downloads or callbacks in progress.
  2. Do not enter any credentials, even if the page looks legitimate.
  3. Close the tab and clear your browser cache and cookies.
  4. Run a full antivirus scan using Windows Defender, Malwarebytes, or your preferred security suite.
  5. Change passwords for any accounts you may have logged into recently, starting with email and banking.
  6. Enable two-factor authentication on every important account if you haven't already.
  7. Monitor bank and card statements for unauthorized activity over the next 30 days.
  8. Report the phishing URL to Google Safe Browsing, PhishTank, and the impersonated brand.

Best Practices for Long-Term Link Safety

Beyond checking individual URLs, build habits that reduce your exposure overall.

  • Bookmark critical sites — banks, email, cloud storage — and only access them via bookmarks, never search results or email links.
  • Use a password manager that auto-fills only on the real domain. If it refuses to fill, you're likely on a phishing clone.
  • Turn on multi-factor authentication everywhere. Even stolen credentials become useless without the second factor.
  • Keep your browser and OS updated — most zero-click drive-by attacks target unpatched systems.
  • Use a privacy-respecting browser like Brave, Firefox, or hardened Chrome with strict tracking protection.
  • Choose reputable link shorteners when sharing your own URLs. Providers with abuse monitoring and preview features — see our Rebrandly review for one example — protect both you and your audience.

Frequently Asked Questions

Is a link safe if it starts with HTTPS?

Not necessarily. HTTPS only means the connection is encrypted between you and the server. Scammers can and do obtain free SSL certificates, so phishing sites regularly display the padlock icon. HTTPS is a bare minimum, not proof of legitimacy.

Can I get hacked just by clicking a link without entering anything?

Yes, though it's rarer than credential theft. Zero-click and one-click exploits target browser or OS vulnerabilities to install malware without any input. Keeping your browser and operating system fully updated closes almost all of these paths.

Are shortened links always dangerous?

No. Shortened links are widely used for legitimate marketing, tracking, and character-limit reasons on social platforms. The risk comes from the fact that the destination is hidden. Use a link expander for any short URL from an unknown or unexpected source, and stick with well-known shortener brands when creating your own.

What's the fastest way to check a link on my phone?

Long-press the link to preview the destination URL. If it looks suspicious, copy it (don't open it) and paste it into VirusTotal or urlscan.io through your browser. The whole process takes under 20 seconds.

How do I report a malicious link?

Submit phishing URLs to Google Safe Browsing (safebrowsing.google.com/safebrowsing/report_phish), PhishTank, and the Anti-Phishing Working Group (reportphishing@apwg.org). Also notify the brand being impersonated — most large companies have a dedicated abuse or phishing email address.

Final Thoughts

Learning how to check if a link is safe is one of the highest-return security habits you can build. It costs nothing, takes seconds, and prevents the majority of everyday cyber attacks. Combine visual inspection with a scanner like VirusTotal or urlscan.io, keep your browser's safe browsing features enabled, and use encrypted DNS for a network-level safety net. Do that consistently, and clicking the wrong link becomes a very rare event.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles