facebook-pixel

How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide

L
Lunyb Security Team
··9 min read

Every day, billions of links are shared through email, social media, messaging apps, and websites. Unfortunately, a growing percentage of them lead to phishing pages, malware downloads, or scam sites designed to steal your money or identity. Learning how to check if a link is safe before clicking is one of the most important digital safety skills you can develop in 2026.

This guide walks you through the exact steps, tools, and warning signs security professionals use to evaluate suspicious URLs — no technical background required.

Why Link Safety Matters More Than Ever

A malicious link is a URL that leads to a website designed to harm you, either by installing malware, tricking you into entering credentials, or executing fraudulent transactions. According to recent cybersecurity reports, over 90% of successful cyberattacks begin with a single click on a bad link.

Attackers have become remarkably sophisticated. Modern phishing pages are pixel-perfect clones of legitimate banking, email, and shopping sites. Shortened URLs, QR codes, and AI-generated messages make it harder than ever to tell what's real. That's why manual verification — before you click — is essential.

Common Risks Hiding Behind Unsafe Links

  • Phishing: Fake login pages that harvest usernames, passwords, and 2FA codes.
  • Drive-by malware: Sites that automatically download malicious files when visited.
  • Financial fraud: Fake payment portals, cryptocurrency scams, and invoice fraud.
  • Session hijacking: URLs that steal your active login cookies.
  • Tracking and profiling: Links that fingerprint your device for future attacks.

7 Warning Signs of a Suspicious Link

Before you use any tool, train your eye. Most dangerous links share visible red flags. Here are the seven biggest ones:

  1. Misspelled domains: "arnazon.com", "paypa1.com", or "faceb00k.net" are classic tricks. Attackers rely on you not looking closely.
  2. Excessive subdomains: A URL like paypal.com.secure-login.verify-account.xyz is not owned by PayPal — the real domain is verify-account.xyz.
  3. Unusual top-level domains: Legitimate businesses rarely use rare TLDs like .zip, .top, .xyz, or .click for critical services.
  4. Urgency or fear in the surrounding message: "Your account will be closed in 24 hours" is a psychological trap.
  5. Mismatched anchor text: The visible link says "bank.com" but hovering reveals a completely different destination.
  6. No HTTPS or invalid certificate warnings: While HTTPS alone doesn't guarantee safety, its absence on a login page is a huge red flag.
  7. Random character strings: URLs packed with long, meaningless character sequences often signal automated phishing kits.

Step-by-Step: How to Check if a Link Is Safe

Follow this five-step process every time you receive a link from an unfamiliar or unexpected source.

Step 1: Hover Before You Click

On desktop, hover your mouse over the link without clicking. Your browser will display the true destination URL in the bottom-left corner. On mobile, press and hold the link (don't tap) to reveal a preview. If the displayed URL doesn't match what you'd expect, stop immediately.

Step 2: Expand Shortened URLs

Shortened links (bit.ly, t.co, tinyurl, and similar) hide the real destination. Before clicking, paste the short link into a URL expander such as:

  • CheckShortURL.com — free and instant
  • Unshorten.It — includes a basic safety score
  • ExpandURL.net — shows the full redirect chain

Reputable shortening services like Lunyb maintain strict anti-abuse policies and automated malware scanning, which helps reduce the risk of shortened links being used for phishing. Still, always expand any short link from an unknown sender before visiting.

Step 3: Run the URL Through a Link Scanner

Free online scanners analyze links against massive threat databases in seconds. Copy and paste the URL — never click it — into one of these trusted services:

ScannerBest ForCost
VirusTotalChecking against 70+ security enginesFree
Google Safe BrowsingMalware and phishing detectionFree
URLVoidReputation history and blacklist statusFree
Sucuri SiteCheckWebsite malware and defacementFree
PhishTankCommunity-verified phishing URLsFree
urlscan.ioDetailed technical analysis and screenshotsFree

For maximum confidence, check the same URL on two or three scanners. If any of them flag it, do not proceed.

Step 4: Inspect the Domain's Reputation

A legitimate website usually has a history. Use tools like WHOIS lookup (whois.domaintools.com) to see:

  • When the domain was registered — brand-new domains (less than 90 days old) are statistically more likely to be malicious.
  • Whether the registrant hides behind privacy protection on a login-critical service.
  • The registrar's reputation.

You can also search the domain name in Google along with words like "scam", "review", or "phishing" to see if others have reported it.

Step 5: Open in a Sandbox If Still Unsure

If you absolutely must visit a questionable link, use an isolated environment where any malicious code can't reach your real system. Options include:

  • Browserling or urlscan.io — visit the site inside a remote browser.
  • Windows Sandbox — built into Windows 10/11 Pro.
  • A dedicated virtual machine with no personal data.

Understanding URL Anatomy

To spot fakes reliably, you need to know how a URL is actually structured. Consider this example:

https://accounts.google.com/signin?service=mail

  • https:// — protocol
  • accounts — subdomain
  • google.com — the real domain (this is what matters most)
  • /signin — path
  • ?service=mail — query parameters

The critical part is the domain immediately before the first single slash. Everything to the left is a subdomain (which anyone can create), and everything to the right is a path (which the site owner controls). Attackers abuse subdomains constantly — for example, google.com.attacker.ru is owned by attacker.ru, not Google.

Special Cases: Emails, QR Codes, and Social Media

Email Links

Email remains the #1 delivery method for malicious links. Always check the sender's full email address (not just the display name), look for generic greetings, and never click "verify your account" links from banks or payment providers — go directly to the site by typing the URL yourself.

QR Codes

"Quishing" (QR phishing) is exploding. Fake QR codes are pasted over legitimate ones on parking meters, restaurant menus, and even bank ATMs. Use a scanner app that previews the URL before opening it — iOS Camera and most modern Android scanners do this by default. Apply the same 5-step check to any URL revealed by a QR code.

Social Media DMs

Compromised friend accounts are a common attack vector. If a contact suddenly sends you a link out of context ("OMG is this you in this video?"), assume the account is hacked. Confirm through another channel before clicking.

Browser and System-Level Protections

Beyond manual checks, layer your defenses with built-in protections:

  • Enable Enhanced Safe Browsing in Chrome or the equivalent in Firefox, Edge, and Safari.
  • Use encrypted DNS (DNS-over-HTTPS) with a filtering provider like Quad9 or NextDNS, which blocks known malicious domains at the network level.
  • Keep your browser and OS updated — most drive-by malware exploits vulnerabilities patched months ago.
  • Install a reputable ad blocker like uBlock Origin, which also blocks many malicious redirect chains.
  • Use a password manager — it won't autofill on lookalike domains, giving you a built-in phishing detector.

What to Do If You Already Clicked a Suspicious Link

Mistakes happen. If you've clicked something you shouldn't have, act quickly:

  1. Disconnect from the internet to prevent data exfiltration or further downloads.
  2. Do not enter any information if a login or payment page appeared — close it immediately.
  3. Run a full malware scan using Windows Defender, Malwarebytes, or your preferred security suite.
  4. Change passwords for any account you may have exposed, starting with email and banking.
  5. Enable two-factor authentication everywhere it's offered.
  6. Monitor bank and credit card statements for the next 60 days.
  7. Report the link to Google Safe Browsing, PhishTank, and the impersonated brand.

Choosing Trustworthy Link Services

Not all URL shorteners are created equal. Some have become notorious for hosting spam and malware because they lack proper moderation. When you need to shorten or share links, use services with active abuse teams, transparent policies, and built-in scanning.

For a full comparison, see our 2026 buyer's guide to the best URL shorteners, our honest review of Lunyb, and our detailed Rebrandly review to see how the top providers handle security and abuse.

Quick Reference: The 30-Second Link Safety Check

Short on time? Use this rapid checklist before any click:

  1. Hover to preview the true URL.
  2. Identify the real domain (immediately left of the first single slash).
  3. Look for typos, weird TLDs, or excessive subdomains.
  4. Paste into VirusTotal or Google Safe Browsing.
  5. If anything feels off — don't click. Navigate manually instead.

Frequently Asked Questions

Is a link with HTTPS always safe?

No. HTTPS only means the connection is encrypted — it does not verify the site's intent or legitimacy. Attackers routinely obtain free SSL certificates for phishing sites. Treat HTTPS as necessary but not sufficient; always verify the domain itself.

Can I get a virus just by hovering over a link?

No. Hovering only displays the destination URL; it does not execute any code. You are safe to hover, inspect, and copy links. Danger begins only when you click and load the page.

Are shortened URLs inherently dangerous?

Not inherently, but they hide the destination, which attackers exploit. Reputable services like Lunyb, Bitly, and Rebrandly scan for malicious content, but you should still expand any short link from an unknown sender using a tool like CheckShortURL before clicking.

What's the single best free tool to check a link?

VirusTotal is the industry gold standard for a reason — it checks your URL against 70+ security vendors simultaneously and provides a detailed report in seconds. Combine it with urlscan.io for a full technical picture including a screenshot of the destination page.

How can I check a link safely on my phone?

Long-press (don't tap) any link to preview the URL. Copy it and paste into VirusTotal.com through your mobile browser. Enable Safe Browsing in Chrome or the equivalent setting in your default browser, and consider a filtering DNS service like NextDNS or Quad9 which works system-wide.

Final Thoughts

Learning how to check if a link is safe takes only a few minutes to master but pays dividends for the rest of your digital life. The combination of a trained eye, free scanning tools, and layered browser protections will neutralize the vast majority of threats you'll ever encounter. When in doubt, remember the golden rule: if you can't verify it, don't click it. Navigate directly to the source instead — it takes ten extra seconds and can save you thousands of dollars and countless hours of recovery.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles