facebook-pixel

How to Check if a Link Is Safe Before Clicking (2026 Guide)

L
Lunyb Security Team
··8 min read

Every day, billions of links are shared across email, social media, and messaging apps — and a worrying percentage of them lead to phishing pages, malware downloads, or scam sites. Learning how to check if a link is safe before clicking is one of the most valuable digital safety skills you can develop in 2026.

This guide walks you through 10 practical methods — from free online scanners to visual inspection tricks — so you can confidently decide whether to click, copy, or delete any suspicious URL.

Why Checking Links Before You Click Matters

A malicious link is a URL designed to harm the person who clicks it. It may redirect to a fake login page, trigger a drive-by malware download, steal cookies, or load a browser exploit. According to recent industry reports, phishing attacks remain the number one entry point for data breaches, and over 90% begin with a single click.

Checking links takes seconds and protects your passwords, bank accounts, work systems, and personal data. It is especially critical when the link arrives:

  • In an unexpected email, SMS, or direct message
  • Shortened (bit.ly, tinyurl, t.co, etc.) so the real destination is hidden
  • From a sender creating urgency ("Your account will be closed in 24 hours")
  • Attached to a prize, refund, invoice, or delivery notice you didn't expect

10 Proven Ways to Check if a Link Is Safe

Below are the methods trusted by security professionals, ordered from quickest visual checks to deeper scanner-based analysis. Combine two or three for the strongest confidence.

1. Hover Over the Link to Preview the Real URL

On desktop, hover your mouse over any hyperlink without clicking. The actual destination appears in the bottom-left corner of your browser or email client. On mobile, press and hold the link to reveal a preview.

If the visible text says paypal.com but the preview shows paypa1-security-login.ru, you've just caught a phishing attempt in two seconds.

2. Inspect the Domain Carefully

Attackers rely on lookalike domains. Train your eye to spot:

  • Character swaps: rn instead of m (rnicrosoft.com), 0 instead of o, 1 instead of l
  • Extra subdomains: apple.com.secure-id-verify.co — the real domain is secure-id-verify.co, not apple.com
  • Wrong TLD: amazon.shop, amazon-support.net instead of amazon.com
  • Hyphenated variants: face-book-login.com, netflix-billing.help

The real domain is always the part immediately before the first single slash, reading right to left from the .com/.net/.org.

3. Use a Free Online Link Scanner

Several reputable scanners analyze URLs against threat databases and sandbox the page. Copy the link (right-click → Copy link address) and paste it into one of these tools:

  • VirusTotal (virustotal.com) — checks the URL against 70+ security vendors
  • Google Safe Browsing (transparencyreport.google.com/safe-browsing/search) — Google's own threat database
  • URLVoid — reputation scoring from multiple blacklists
  • Sucuri SiteCheck — scans for malware and defacement
  • PhishTank — community-reported phishing URLs

If two or more scanners flag the link, do not click it.

4. Expand Shortened Links Before Clicking

Shortened URLs hide the final destination. Before clicking any bit.ly, t.co, tinyurl, or similar short link, expand it with a free tool:

  • CheckShortURL.com
  • Unshorten.it
  • GetLinkInfo.com

Paste the short link and the tool reveals the full destination, HTTP status, and sometimes a safety score. Reputable shortener platforms like Lunyb also provide link previews and analytics that make the destination transparent to recipients, which is one reason trustworthy brands prefer them over anonymous shorteners.

5. Check for HTTPS and a Valid Certificate

A padlock icon and https:// prefix mean traffic between you and the site is encrypted — but it does not mean the site is legitimate. Over 85% of phishing sites now use HTTPS too, because free certificates are easy to obtain.

Click the padlock to view certificate details. If the certificate was issued yesterday to a random-looking organization, treat the site with suspicion.

6. Look Up the Domain's Age with WHOIS

Legitimate businesses usually have domains registered years ago. Phishing domains are often less than 30 days old. Use who.is, whois.domaintools.com, or icann.org/lookup to check the registration date. A brand-new domain claiming to be a major bank is almost always a scam.

7. Use Your Browser's Built-In Protection

Modern browsers include safe-browsing features. Make sure they are enabled:

  • Chrome: Settings → Privacy and security → Safe Browsing → Enhanced protection
  • Firefox: Settings → Privacy & Security → scroll to Deceptive Content and Dangerous Software Protection
  • Edge: Settings → Privacy, search, and services → Microsoft Defender SmartScreen
  • Safari: Preferences → Security → Warn when visiting a fraudulent website

These features block known malicious URLs automatically before the page loads.

8. Preview the Page Safely with a Sandbox

If you must see the content of a suspicious link without risking your device, use a browser sandbox:

  • Browserling or urlscan.io — load the URL in an isolated cloud browser and show you a screenshot
  • Hybrid Analysis — detonates the URL in a sandbox and reports behavior

You see the page without any code touching your computer.

9. Check Link Reputation on Search Engines

Copy the full domain (not the full link, which may contain tracking tokens) and search for it in quotes on Google along with words like scam, review, or phishing. Real users and watchdog sites quickly expose fraudulent domains, so a single search can reveal weeks of complaints.

10. Trust Context and Your Gut

Technical checks matter, but context is king. Ask:

  • Was I expecting this message?
  • Does the sender's email address actually match the organization?
  • Is the message creating artificial urgency or fear?
  • Does the request bypass normal channels ("Don't call support, just click here")?

If anything feels off, don't click. Go to the organization's website directly by typing the address yourself.

Comparison of Popular Link-Checking Tools

Not all scanners are equal. Here's how the most-used free tools stack up in 2026:

Tool Best For Checks Speed Cost
VirusTotal Multi-vendor consensus 70+ engines, file & URL 5–15 sec Free
Google Safe Browsing Quick phishing check Google's blocklist Instant Free
urlscan.io Visual sandbox preview Screenshot, DOM, requests 10–30 sec Free
URLVoid Reputation history 30+ blacklists, WHOIS 5–10 sec Free
Sucuri SiteCheck Malware detection Site code, blacklists 10–20 sec Free
PhishTank Known phishing URLs Community reports Instant Free

Common Red Flags in Malicious Links

Even without tools, these warning signs should stop you from clicking:

  1. Numeric IP addresses instead of a domain name (http://192.168.x.x/login)
  2. Excessive subdomains stacked before the real domain
  3. Punycode / Unicode characters that mimic Latin letters (xn-- prefixes)
  4. Random strings in the domain (asdf8e7w.xyz)
  5. Unusual TLDs for a supposed major brand (.zip, .mov, .click, .tk)
  6. Credentials in the URL (http://user:pass@evil.com)
  7. @ symbols inside the URL — everything before @ is ignored by the browser

What to Do if You Already Clicked a Suspicious Link

Mistakes happen. If you clicked something you shouldn't have:

  1. Disconnect from the internet immediately to stop any ongoing download or data exfiltration.
  2. Do not enter any information if a login or payment form appeared — close the tab.
  3. Run a full antivirus scan with Microsoft Defender, Malwarebytes, or your preferred tool.
  4. Change passwords for any account you may have exposed, starting with email and banking.
  5. Enable two-factor authentication everywhere, if you haven't already.
  6. Monitor financial statements for the next 60–90 days.
  7. Report the link to Google Safe Browsing, PhishTank, or your IT department.

How to Share Links Others Can Trust

If you create and share links as part of your work — marketing, support, newsletters — your audience is doing the same checks on your URLs. To build trust:

  • Use a branded short domain so the link name signals legitimacy
  • Choose a shortener that supports link previews, analytics, and spam protection
  • Keep HTTPS enabled on every destination
  • Avoid redirect chains that pass through unknown third parties

Platforms like the top URL shorteners of 2026 are compared in detail in our buyer's guide, and services such as Rebrandly and Lunyb both offer features designed specifically to make shortened links transparent and trustworthy for recipients.

Frequently Asked Questions

Is a link safe if it starts with https://?

Not necessarily. HTTPS only means the connection is encrypted — it does not verify that the website itself is legitimate. Most phishing sites now use HTTPS because free certificates are easy to obtain. Always combine the padlock check with a domain inspection or scanner result.

What is the fastest way to check if a link is safe?

Paste the URL into Google Safe Browsing's transparency report tool or VirusTotal. Both return a verdict in under 15 seconds and are free. For shortened links, run them through CheckShortURL.com first to reveal the real destination.

Can I get hacked just by clicking a link?

Yes, in rare cases. A fully patched modern browser is highly resistant, but zero-day exploits and malicious scripts can occasionally compromise a device on click alone. The far more common risk is being tricked into entering credentials on a fake page or downloading a malicious file after the page loads.

Are shortened links more dangerous than regular links?

Shortened links aren't inherently dangerous — they're used by legitimate businesses every day — but they hide the destination, which attackers exploit. Reputable shortener services include link previews and spam filtering; unknown or anonymous shorteners deserve more caution. Always expand short links from unfamiliar senders before clicking.

What should I do if I receive a suspicious link from a friend?

Their account may be compromised. Don't click the link. Contact the friend through a different channel (phone call, in person, or a separate app) to confirm whether they actually sent it. If they didn't, advise them to change their password and scan their device.

Final Thoughts

Checking a link takes 10 to 60 seconds and can save you from identity theft, drained bank accounts, or a company-wide ransomware incident. Build the habit of hovering, inspecting the domain, and running anything suspicious through a scanner before you click. Combine technical tools with contextual awareness — the sender, the urgency, the request — and you'll avoid the vast majority of modern online threats.

The internet rewards the curious but punishes the hasty. A moment of caution is always cheaper than a cleanup.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles