How to Check if a Link Is Safe Before Clicking: 2026 Guide
Every day, billions of links are shared across email, social media, and messaging apps—and a growing percentage of them lead somewhere you don't want to go. Phishing pages, drive-by malware downloads, cryptocurrency scams, and credential harvesters all rely on one simple action: a user clicking a link without checking it first.
The good news is that verifying a link takes only a few seconds once you know what to look for. This guide walks through the exact methods security professionals use to check if a URL is safe, including free scanning tools, manual inspection techniques, and the red flags that should make you close the tab immediately.
Why Link Safety Matters More Than Ever in 2026
Link-based attacks are now the single most common entry point for cybercrime. According to recent industry reporting, more than 90% of successful cyberattacks begin with a malicious link delivered through phishing. Attackers have moved beyond obvious spam into highly convincing clones of banking portals, delivery notifications, and workplace tools like Microsoft 365 and Google Workspace.
Short links and QR codes add another layer of risk because they hide the real destination. A link that looks like bit.ly/xyz123 could point anywhere—a legitimate article, a phishing page, or a malware download. Learning to verify before you click is now a baseline digital literacy skill, not an advanced security practice.
What Makes a Link Dangerous?
A dangerous link is any URL that leads to a destination intended to harm the visitor, their device, or their accounts. Threats generally fall into four categories:
- Phishing pages that mimic trusted sites to steal login credentials, credit card data, or two-factor codes.
- Malware delivery that triggers downloads of ransomware, keyloggers, or remote-access tools, sometimes without any user interaction.
- Scam destinations such as fake investment platforms, counterfeit stores, or romance-scam intermediaries.
- Tracking and fingerprinting pages that silently harvest device data for targeted follow-up attacks.
The common thread is deception. Modern malicious links are rarely obvious; they rely on urgency, familiarity, or curiosity to bypass your judgment.
7 Steps to Check if a Link Is Safe Before Clicking
Follow this checklist whenever a link looks unfamiliar, arrives unexpectedly, or asks you to log in or download something. Most steps take under a minute.
- Hover before you click. On desktop, hovering your cursor over a hyperlink reveals the true destination in the bottom-left corner of the browser. On mobile, long-press the link to preview the URL instead of tapping it.
- Read the domain carefully. Look at the part immediately before the first single slash.
paypal.com.secure-login.xyzis not PayPal—it'ssecure-login.xyz. - Expand shortened URLs. Use a URL expander (covered below) to see where a
bit.ly,t.co, ortinyurllink actually leads before visiting it. - Scan the link with a reputation service. Paste it into Google Safe Browsing, VirusTotal, or URLVoid for an instant threat assessment.
- Check for HTTPS and a valid certificate. HTTPS alone doesn't mean safe, but its absence on a login page is a major red flag.
- Look up the domain's age and WHOIS record. Domains registered within the last 30 days and used for login forms are statistically very likely to be malicious.
- Trust the context. Did you expect this message? Does the tone match the sender? When in doubt, verify through a separate channel before clicking.
Best Free Tools to Check if a URL Is Safe
These free online scanners analyze a link against dozens of threat intelligence databases without requiring you to visit the site yourself.
| Tool | Best For | Cost | What It Checks |
|---|---|---|---|
| Google Safe Browsing | Quick phishing & malware check | Free | Google's own blocklist of unsafe sites |
| VirusTotal | Deep multi-engine analysis | Free | 70+ antivirus and URL scanners |
| URLVoid | Domain reputation | Free | 30+ blocklists, WHOIS, server location |
| PhishTank | Confirmed phishing lookup | Free | Community-verified phishing database |
| urlscan.io | Technical inspection | Free | Live screenshot, DOM, network requests |
| Sucuri SiteCheck | Website malware scan | Free | Malware signatures, blacklist status |
How to Use VirusTotal in 30 Seconds
- Go to
virustotal.com. - Click the URL tab.
- Paste the suspicious link and press Enter.
- Wait for the scan—any detection count above zero warrants caution; three or more is a strong signal to avoid the link.
How to Use urlscan.io for a Safe Preview
urlscan.io actually loads the page in a sandboxed environment and shows you a screenshot, the final redirect destination, and every network request made. This is the safest way to "look" at a suspicious page without exposing your own device.
How to Expand Shortened Links Safely
Short links from services like Bitly, TinyURL, or branded shorteners hide the real destination by design. Before clicking one from an unknown sender, expand it.
Free expanders include CheckShortURL, Unshorten.it, and ExpandURL. Paste the short link, and the service shows the full destination plus a basic safety rating.
If you create short links yourself, choose a reputable provider that offers HTTPS, click analytics, and link previews. Our 2026 buyer's guide to the best URL shorteners compares the leading options on exactly these criteria. Trustworthy platforms like Lunyb add scam-detection and preview pages that help recipients verify a destination before continuing, which is a feature every modern shortener should offer.
Red Flags: Warning Signs of an Unsafe Link
Even without a scanner, these patterns strongly suggest a link is malicious. If you spot two or more, don't click.
- Misspelled brand names such as
amaz0n.com,paypaI.com(capital I instead of lowercase l), ormicros0ft-support.com. - Unusual top-level domains for a well-known brand—a bank will not send you to a
.zip,.top, or.clickdomain. - Excessive subdomains designed to push the real domain off-screen on mobile, e.g.
login.security.account.verify.suspicious-site.com. - IP addresses instead of domain names in the URL, like
http://185.220.101.42/login. - Urgency and threats in the surrounding message: "Your account will be closed in 24 hours."
- Mismatched link text and destination. The displayed text says one thing, hovering reveals another.
- Requests for credentials, OTPs, or payment immediately after clicking.
- Attachments or auto-downloads that start the moment the page loads.
Checking Links on Mobile Devices
Mobile browsers hide most of the URL by default, which makes link verification harder—and attackers know this.
On iPhone (Safari)
- Press and hold the link without lifting your finger.
- A preview card appears showing the full URL and a page thumbnail.
- Read the domain carefully before tapping Open, or tap Copy to paste it into a scanner.
On Android (Chrome)
- Long-press the link.
- Choose Copy link address from the menu.
- Paste it into VirusTotal or Google Safe Browsing in a new tab.
Inside Messaging Apps
WhatsApp, Telegram, and Signal typically show the real URL when you long-press. Be especially cautious with links in SMS messages—so-called "smishing" is now one of the fastest-growing attack vectors because mobile users rarely verify before tapping.
How to Check if a QR Code Is Safe
QR codes are just links in visual form, and "quishing" attacks—malicious QR codes placed on parking meters, restaurant tables, and phishing emails—have exploded. To stay safe:
- Use a QR scanner app that shows the URL before opening it (iOS Camera and Google Lens both do this by default).
- Read the preview URL just like any other link—check domain, HTTPS, and spelling.
- Never scan QR codes from stickers that look placed over an original code.
- If a QR code demands a login or payment, open the official app or website manually instead.
What to Do If You Already Clicked a Suspicious Link
If you clicked before checking, don't panic—but act quickly.
- Disconnect from the internet if a download started or the page behaved strangely. This limits any ongoing communication with an attacker.
- Don't enter any information. If a login page appeared, close the tab immediately. Never type credentials into a page you reached from a suspicious link.
- Run a full antivirus scan using your built-in protection (Windows Defender, XProtect on macOS) or a reputable third-party tool.
- Change passwords for any account you may have exposed, starting with email and banking. Enable two-factor authentication everywhere.
- Check account activity for unfamiliar logins, forwarding rules, or new devices.
- Report the link to Google Safe Browsing, your email provider, or the brand being impersonated so others are protected.
Building Long-Term Habits for Safer Browsing
Tools help, but habits protect you consistently. A few practices make a disproportionate difference:
- Use a modern browser with built-in phishing protection—Chrome, Edge, Firefox, Brave, and Safari all block known malicious sites automatically.
- Enable encrypted DNS (DNS over HTTPS) in your browser or operating system to prevent tampering with the lookups that resolve domains.
- Keep software updated. Many malicious links exploit vulnerabilities patched months earlier.
- Use a password manager. It will refuse to autofill credentials on a lookalike domain, which is often the first clue that a page is fake.
- Turn on multi-factor authentication for every important account. Even if credentials leak, attackers can't log in without the second factor.
- Bookmark the sites you log into regularly and use those bookmarks instead of clicking email links.
For Businesses and Teams
Organizations should layer technical and human defenses. Deploy a secure email gateway that rewrites and scans links at click-time, enforce browser-level safe-browsing policies, and run regular phishing simulations so staff practice spotting unsafe links in realistic conditions. If your team shares links externally—for marketing, support, or sales—using a shortener with built-in abuse detection and HTTPS enforcement (compared in detail in our Rebrandly 2026 review) adds credibility and reduces the chance your brand gets associated with scam reports.
Frequently Asked Questions
Is a link safe just because it uses HTTPS?
No. HTTPS only means the connection between your browser and the server is encrypted; it says nothing about who runs the server. Attackers can and do obtain free TLS certificates for phishing domains. Always verify the domain itself, not just the padlock icon.
What is the fastest way to check if a link is safe?
Copy the link and paste it into Google Safe Browsing (transparencyreport.google.com/safe-browsing/search) or VirusTotal. Both return a verdict in under five seconds and don't require you to visit the actual page.
Can I get hacked just by clicking a link?
In most cases, you need to take a second action—entering credentials, approving a download, or granting a permission—for an attacker to succeed. However, drive-by exploits that compromise unpatched browsers do exist, which is why keeping your browser and operating system updated is essential.
Are shortened links always risky?
Not inherently. Reputable shortening services run abuse monitoring and block known malicious destinations. The risk comes from the hidden destination, so always expand or preview a short link from an unknown source before clicking. Shorteners with built-in preview pages, scam detection, and HTTPS by default are safer than those without.
How do I check if a link is safe on my phone without downloading an app?
Long-press the link to reveal the full URL, then copy it. Open your mobile browser and paste it into VirusTotal or Google Safe Browsing. No installation needed, and the whole process takes about 20 seconds.
What should I do if I accidentally entered my password on a phishing site?
Change that password immediately on the legitimate site, then change it anywhere else you reused it. Enable multi-factor authentication, check recent account activity for anything unfamiliar, and alert your bank if financial data was involved. Report the phishing page to Google Safe Browsing so the site gets added to blocklists.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Erase Your Browsing History Completely: The 2026 Guide
Clearing your browser history isn't enough to protect your privacy. This 2026 guide walks you through every layer — browser, synced accounts, DNS cache, router, and OS — so you can erase your browsing history completely and keep it from building up again.
How to Delete Yourself from People Search Sites: Complete 2026 Guide
People search sites expose your address, phone number, and family details to anyone with an internet connection. This complete 2026 guide shows you exactly how to delete yourself from Spokeo, Whitepages, BeenVerified, and dozens of other data brokers — and how to keep your information from coming back.
How to Create a Link in Bio Page in 2026: Step-by-Step Guide
A link in bio page lets you share multiple important URLs through a single tap-friendly link on your social profiles. This step-by-step 2026 guide shows you exactly how to build one, from choosing a tool to designing high-converting layouts.
How to Hide Photos with an Encrypted Photo Vault: Complete 2026 Guide
Learn exactly how to hide photos with an encrypted photo vault — from choosing the right app to importing, securing, and backing up your private images. This complete guide covers features that matter, common mistakes, and step-by-step setup.