How to Check if a Link Is Safe Before Clicking: The Complete 2026 Guide
Every day, billions of links are shared through email, social media, messaging apps, and websites. Unfortunately, a growing percentage of them lead to phishing pages, malware downloads, or scam sites designed to steal your money or identity. Learning how to check if a link is safe before clicking is one of the most important digital safety skills you can develop in 2026.
This guide walks you through the exact steps, tools, and warning signs security professionals use to evaluate suspicious URLs — no technical background required.
Why Link Safety Matters More Than Ever
A malicious link is a URL that leads to a website designed to harm you, either by installing malware, tricking you into entering credentials, or executing fraudulent transactions. According to recent cybersecurity reports, over 90% of successful cyberattacks begin with a single click on a bad link.
Attackers have become remarkably sophisticated. Modern phishing pages are pixel-perfect clones of legitimate banking, email, and shopping sites. Shortened URLs, QR codes, and AI-generated messages make it harder than ever to tell what's real. That's why manual verification — before you click — is essential.
Common Risks Hiding Behind Unsafe Links
- Phishing: Fake login pages that harvest usernames, passwords, and 2FA codes.
- Drive-by malware: Sites that automatically download malicious files when visited.
- Financial fraud: Fake payment portals, cryptocurrency scams, and invoice fraud.
- Session hijacking: URLs that steal your active login cookies.
- Tracking and profiling: Links that fingerprint your device for future attacks.
7 Warning Signs of a Suspicious Link
Before you use any tool, train your eye. Most dangerous links share visible red flags. Here are the seven biggest ones:
- Misspelled domains: "arnazon.com", "paypa1.com", or "faceb00k.net" are classic tricks. Attackers rely on you not looking closely.
- Excessive subdomains: A URL like
paypal.com.secure-login.verify-account.xyzis not owned by PayPal — the real domain isverify-account.xyz. - Unusual top-level domains: Legitimate businesses rarely use rare TLDs like .zip, .top, .xyz, or .click for critical services.
- Urgency or fear in the surrounding message: "Your account will be closed in 24 hours" is a psychological trap.
- Mismatched anchor text: The visible link says "bank.com" but hovering reveals a completely different destination.
- No HTTPS or invalid certificate warnings: While HTTPS alone doesn't guarantee safety, its absence on a login page is a huge red flag.
- Random character strings: URLs packed with long, meaningless character sequences often signal automated phishing kits.
Step-by-Step: How to Check if a Link Is Safe
Follow this five-step process every time you receive a link from an unfamiliar or unexpected source.
Step 1: Hover Before You Click
On desktop, hover your mouse over the link without clicking. Your browser will display the true destination URL in the bottom-left corner. On mobile, press and hold the link (don't tap) to reveal a preview. If the displayed URL doesn't match what you'd expect, stop immediately.
Step 2: Expand Shortened URLs
Shortened links (bit.ly, t.co, tinyurl, and similar) hide the real destination. Before clicking, paste the short link into a URL expander such as:
- CheckShortURL.com — free and instant
- Unshorten.It — includes a basic safety score
- ExpandURL.net — shows the full redirect chain
Reputable shortening services like Lunyb maintain strict anti-abuse policies and automated malware scanning, which helps reduce the risk of shortened links being used for phishing. Still, always expand any short link from an unknown sender before visiting.
Step 3: Run the URL Through a Link Scanner
Free online scanners analyze links against massive threat databases in seconds. Copy and paste the URL — never click it — into one of these trusted services:
| Scanner | Best For | Cost |
|---|---|---|
| VirusTotal | Checking against 70+ security engines | Free |
| Google Safe Browsing | Malware and phishing detection | Free |
| URLVoid | Reputation history and blacklist status | Free |
| Sucuri SiteCheck | Website malware and defacement | Free |
| PhishTank | Community-verified phishing URLs | Free |
| urlscan.io | Detailed technical analysis and screenshots | Free |
For maximum confidence, check the same URL on two or three scanners. If any of them flag it, do not proceed.
Step 4: Inspect the Domain's Reputation
A legitimate website usually has a history. Use tools like WHOIS lookup (whois.domaintools.com) to see:
- When the domain was registered — brand-new domains (less than 90 days old) are statistically more likely to be malicious.
- Whether the registrant hides behind privacy protection on a login-critical service.
- The registrar's reputation.
You can also search the domain name in Google along with words like "scam", "review", or "phishing" to see if others have reported it.
Step 5: Open in a Sandbox If Still Unsure
If you absolutely must visit a questionable link, use an isolated environment where any malicious code can't reach your real system. Options include:
- Browserling or urlscan.io — visit the site inside a remote browser.
- Windows Sandbox — built into Windows 10/11 Pro.
- A dedicated virtual machine with no personal data.
Understanding URL Anatomy
To spot fakes reliably, you need to know how a URL is actually structured. Consider this example:
https://accounts.google.com/signin?service=mail
- https:// — protocol
- accounts — subdomain
- google.com — the real domain (this is what matters most)
- /signin — path
- ?service=mail — query parameters
The critical part is the domain immediately before the first single slash. Everything to the left is a subdomain (which anyone can create), and everything to the right is a path (which the site owner controls). Attackers abuse subdomains constantly — for example, google.com.attacker.ru is owned by attacker.ru, not Google.
Special Cases: Emails, QR Codes, and Social Media
Email Links
Email remains the #1 delivery method for malicious links. Always check the sender's full email address (not just the display name), look for generic greetings, and never click "verify your account" links from banks or payment providers — go directly to the site by typing the URL yourself.
QR Codes
"Quishing" (QR phishing) is exploding. Fake QR codes are pasted over legitimate ones on parking meters, restaurant menus, and even bank ATMs. Use a scanner app that previews the URL before opening it — iOS Camera and most modern Android scanners do this by default. Apply the same 5-step check to any URL revealed by a QR code.
Social Media DMs
Compromised friend accounts are a common attack vector. If a contact suddenly sends you a link out of context ("OMG is this you in this video?"), assume the account is hacked. Confirm through another channel before clicking.
Browser and System-Level Protections
Beyond manual checks, layer your defenses with built-in protections:
- Enable Enhanced Safe Browsing in Chrome or the equivalent in Firefox, Edge, and Safari.
- Use encrypted DNS (DNS-over-HTTPS) with a filtering provider like Quad9 or NextDNS, which blocks known malicious domains at the network level.
- Keep your browser and OS updated — most drive-by malware exploits vulnerabilities patched months ago.
- Install a reputable ad blocker like uBlock Origin, which also blocks many malicious redirect chains.
- Use a password manager — it won't autofill on lookalike domains, giving you a built-in phishing detector.
What to Do If You Already Clicked a Suspicious Link
Mistakes happen. If you've clicked something you shouldn't have, act quickly:
- Disconnect from the internet to prevent data exfiltration or further downloads.
- Do not enter any information if a login or payment page appeared — close it immediately.
- Run a full malware scan using Windows Defender, Malwarebytes, or your preferred security suite.
- Change passwords for any account you may have exposed, starting with email and banking.
- Enable two-factor authentication everywhere it's offered.
- Monitor bank and credit card statements for the next 60 days.
- Report the link to Google Safe Browsing, PhishTank, and the impersonated brand.
Choosing Trustworthy Link Services
Not all URL shorteners are created equal. Some have become notorious for hosting spam and malware because they lack proper moderation. When you need to shorten or share links, use services with active abuse teams, transparent policies, and built-in scanning.
For a full comparison, see our 2026 buyer's guide to the best URL shorteners, our honest review of Lunyb, and our detailed Rebrandly review to see how the top providers handle security and abuse.
Quick Reference: The 30-Second Link Safety Check
Short on time? Use this rapid checklist before any click:
- Hover to preview the true URL.
- Identify the real domain (immediately left of the first single slash).
- Look for typos, weird TLDs, or excessive subdomains.
- Paste into VirusTotal or Google Safe Browsing.
- If anything feels off — don't click. Navigate manually instead.
Frequently Asked Questions
Is a link with HTTPS always safe?
No. HTTPS only means the connection is encrypted — it does not verify the site's intent or legitimacy. Attackers routinely obtain free SSL certificates for phishing sites. Treat HTTPS as necessary but not sufficient; always verify the domain itself.
Can I get a virus just by hovering over a link?
No. Hovering only displays the destination URL; it does not execute any code. You are safe to hover, inspect, and copy links. Danger begins only when you click and load the page.
Are shortened URLs inherently dangerous?
Not inherently, but they hide the destination, which attackers exploit. Reputable services like Lunyb, Bitly, and Rebrandly scan for malicious content, but you should still expand any short link from an unknown sender using a tool like CheckShortURL before clicking.
What's the single best free tool to check a link?
VirusTotal is the industry gold standard for a reason — it checks your URL against 70+ security vendors simultaneously and provides a detailed report in seconds. Combine it with urlscan.io for a full technical picture including a screenshot of the destination page.
How can I check a link safely on my phone?
Long-press (don't tap) any link to preview the URL. Copy it and paste into VirusTotal.com through your mobile browser. Enable Safe Browsing in Chrome or the equivalent setting in your default browser, and consider a filtering DNS service like NextDNS or Quad9 which works system-wide.
Final Thoughts
Learning how to check if a link is safe takes only a few minutes to master but pays dividends for the rest of your digital life. The combination of a trained eye, free scanning tools, and layered browser protections will neutralize the vast majority of threats you'll ever encounter. When in doubt, remember the golden rule: if you can't verify it, don't click it. Navigate directly to the source instead — it takes ten extra seconds and can save you thousands of dollars and countless hours of recovery.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Erase Your Browsing History Completely: A Full Guide
Your browsing history reveals more about you than you think. This guide shows you how to erase your browsing history completely across browsers, cloud accounts, and system caches, and how to prevent it from piling up again.
How to Hide Photos with an Encrypted Photo Vault: 2026 Guide
Learn how to hide photos with an encrypted vault using AES-256 protection, zero-knowledge apps, and step-by-step setup. This guide covers app selection, secure import, backups, and the mistakes that quietly leak your private images.
How to Protect Your Privacy Online in 2026: The Complete Guide
Online tracking, AI profiling, and data broker networks make 2026 the toughest year yet for digital privacy. This step-by-step guide shows you exactly how to protect your accounts, devices, communications, and identity using proven tools and habits.
How to Block Trackers on Your Phone: The Complete 2026 Guide
Trackers follow you across apps, websites, and networks — but you can shut most of them down in under an hour. This complete 2026 guide walks through iOS and Android settings, private browsers, encrypted DNS, and app-level fixes to block trackers on your phone.