facebook-pixel

How to Check if a Link Is Safe Before Clicking: Complete 2026 Guide

L
Lunyb Security Team
··10 min read

Every day, billions of links are shared across emails, text messages, social media, and chat apps. Most are harmless. But a growing percentage lead to phishing pages, malware downloads, credential-stealing forms, or scam marketplaces. Knowing how to check if a link is safe before clicking is now a core digital literacy skill, not a niche technical trick.

This guide walks you through practical, step-by-step methods to verify any URL in under 60 seconds, including free scanners, browser-based checks, and red flags that trained security teams look for.

Why Link Safety Matters More Than Ever in 2026

A single malicious click can expose login credentials, install ransomware, or drain a bank account. According to recent industry reports, phishing and malicious URLs are now the entry point for more than 80% of successful cyberattacks against individuals and small businesses.

Attackers have also become smarter. Modern phishing links often:

  • Use HTTPS and valid SSL certificates (so the padlock icon alone means nothing).
  • Mimic legitimate brand domains using Unicode characters or minor misspellings.
  • Hide behind URL shorteners or redirect chains.
  • Appear in trusted channels like LinkedIn messages, SMS from "your bank," or shared Google Docs.

The good news: you don't need expensive tools to defend yourself. A few free resources and a short mental checklist can block the vast majority of threats.

What Makes a Link Dangerous? Common Red Flags

A dangerous link is any URL designed to deceive you, steal information, or deliver malicious code. Before you click anything, scan the link for the following warning signs.

1. Misspelled or Lookalike Domains

Attackers register domains that look almost identical to real ones. Examples include paypa1.com (number 1 instead of letter l), arnazon.com (rn instead of m), or micros0ft-support.com. Always read the domain character by character.

2. Suspicious Top-Level Domains (TLDs)

While not inherently bad, certain TLDs are heavily abused in phishing campaigns, including .zip, .mov, .top, .xyz, and free subdomains on services like .weebly.site or .000webhostapp.com. Treat these with extra caution.

3. Excessive Subdomains or Hyphens

A link like login-secure-verify.account-update.com-session.ru is almost always malicious. The real domain is always the part just before the final TLD — in this example, com-session.ru, not login-secure-verify.

4. URL Shorteners With No Preview

Shortened links hide the destination. This isn't automatically bad — reputable services like Lunyb are used by millions of legitimate marketers — but you should always preview short links before clicking (we'll show how below).

5. Urgency, Threats, or Too-Good-to-Be-True Offers

The link context matters as much as the link itself. Messages that say "Your account will be suspended in 24 hours" or "You've won a $1,000 gift card" are classic phishing bait.

How to Check if a Link Is Safe: 7 Methods That Actually Work

Here are seven reliable techniques, from the simplest to the most thorough. Use at least two for anything suspicious.

Method 1: Hover Before You Click

On desktop, hover your mouse over any link without clicking. The real destination URL appears in the bottom-left corner of your browser or email client. On mobile, long-press (don't tap) the link to see a preview. If the displayed text says "paypal.com" but the URL points to something else, do not click.

Method 2: Use a Free URL Scanner

Several trusted services scan URLs against databases of known threats. Copy the link (right-click → Copy link address) and paste it into one of these:

  1. Google Safe Browsing Transparency Report — transparencyreport.google.com/safe-browsing/search
  2. VirusTotal — virustotal.com (scans with 70+ security engines)
  3. URLVoid — urlvoid.com (reputation across 30+ blocklists)
  4. PhishTank — phishtank.org (community-reported phishing)
  5. Sucuri SiteCheck — sitecheck.sucuri.net (checks for malware and blacklist status)

Each scan takes under 10 seconds. If multiple engines flag the URL, do not visit it.

Method 3: Expand Shortened URLs

Before clicking any short link, use an unshortening service to see where it really goes:

  • CheckShortURL.com — expands and previews most major shorteners.
  • Unshorten.it — shows the final destination plus a reputation score.
  • GetLinkInfo.com — follows redirect chains and lists every hop.

Quality shortener providers also make this easy. For example, Lunyb's links can be previewed in supported tools, giving recipients confidence in the destination.

Method 4: Inspect the Domain's WHOIS Record

A domain registered three days ago that claims to be your bank is a huge red flag. Use whois.domaintools.com or who.is to check when a domain was registered. Legitimate businesses typically own their domains for years.

Method 5: Check for a Valid HTTPS Certificate (But Don't Rely on It Alone)

Click the padlock icon in your browser's address bar to inspect the certificate. Look at who it was issued to. A certificate issued to "Free SSL" for a domain mimicking your bank is suspicious. Remember: HTTPS only means the connection is encrypted, not that the site is trustworthy.

Method 6: Open the Link in a Sandbox or Isolated Browser

For links you absolutely must open but don't fully trust, use an isolated environment:

  • urlscan.io — opens the URL in a sandbox and shows you screenshots, redirects, and what resources it loads.
  • Browserling or Hybrid Analysis — remote browsers that keep threats off your device.
  • Your phone's reader mode or a disposable browser profile can also reduce risk.

Method 7: Verify Through a Separate Channel

If a link arrives claiming to be from your bank, employer, or a service you use, don't click it. Instead, open a new browser tab and type the official URL manually, or call the organization using a number from their official website. This simple habit defeats most phishing attempts.

Comparison: Top Free Link-Checking Tools

Here's how the most popular free URL scanners compare across the features that matter most.

ToolBest ForScans Multiple EnginesShows ScreenshotExpands Short URLsPrice
VirusTotalDeep malware scanningYes (70+)NoPartialFree
urlscan.ioBehavioral analysisYesYesYesFree
Google Safe BrowsingQuick reputation checkGoogle onlyNoNoFree
URLVoidBlocklist reputationYes (30+)NoNoFree
CheckShortURLPreviewing short linksNoYesYesFree
Sucuri SiteCheckWebsite malwareYesNoNoFree

Pros and Cons of Relying on Automated Link Scanners

Pros

  • Fast — results in under 30 seconds.
  • Free and require no installation.
  • Catch known phishing and malware campaigns with high accuracy.
  • Provide screenshots and technical details for suspicious URLs.

Cons

  • Zero-day phishing pages (less than a few hours old) may not yet be in databases.
  • Scanners can be fooled by cloaking (serving a safe page to bots and a malicious one to real users).
  • They don't evaluate social-engineering context — a technically clean site can still be a scam.

That's why combining automated tools with the manual red-flag checklist above is the gold standard.

How to Check Links Safely on Mobile Devices

Phones make link inspection harder because browsers hide the full URL. Use these mobile-specific tactics:

  1. Long-press, don't tap. iOS and Android both show a preview card with the destination.
  2. Copy the link and paste it into a scanner app or urlscan.io via your mobile browser.
  3. Enable Safe Browsing in Chrome (Settings → Privacy and Security → Safe Browsing → Enhanced Protection).
  4. Use encrypted DNS like Cloudflare's 1.1.1.1 for Families or NextDNS, which blocks known malicious domains at the network level before your browser even loads them.
  5. Keep your OS and browser updated — most mobile exploits target outdated software.

Email Link Safety: A Special Case

Email is the number one delivery channel for malicious links. Apply these extra rules to every email link:

  • Check the sender's full email address, not just the display name. "Apple Support <noreply@apple-id-verify.ru>" is not Apple.
  • Beware of mismatched link text. If the visible text says one URL but hovering shows another, it's phishing.
  • Never click "Unsubscribe" in a clearly spammy email — it often confirms your address is active or triggers a malicious script. Mark as spam instead.
  • Legitimate companies rarely ask you to log in via an email link. Visit the site directly.

How to Check Links on Social Media and Messaging Apps

Scammers love social platforms because trust is implied. On WhatsApp, Telegram, Instagram DMs, and X, treat every unexpected link like email — especially if it's a shortened URL from a stranger or a hacked friend's account.

If you share links yourself and want recipients to trust them, use a reputable shortener with analytics and malware protection. We cover the leading options in our 2026 buyer's guide to URL shorteners, which compares safety features, custom domains, and pricing side by side.

Building a Personal Link-Safety Routine

Security experts don't make case-by-case decisions — they follow habits. Adopt this simple five-step routine for any link you didn't expect:

  1. Pause. Urgency is the attacker's best weapon. Give yourself 10 seconds.
  2. Read the full URL. Hover, long-press, or copy it.
  3. Expand if shortened. Use CheckShortURL or urlscan.io.
  4. Scan it. Paste into VirusTotal or Google Safe Browsing.
  5. Verify out-of-band. If in doubt, contact the sender through a known channel.

This takes less than a minute and blocks the overwhelming majority of threats you'll encounter.

For Businesses: Protecting Your Team From Malicious Links

If you manage a team, individual vigilance isn't enough. Layer these protections:

  • Deploy an email security gateway that rewrites and sandboxes URLs (Microsoft Defender, Proofpoint, Mimecast).
  • Enable multi-factor authentication everywhere — even if credentials are phished, attackers can't log in.
  • Train staff with simulated phishing exercises every quarter.
  • Use branded, trackable short links for internal and marketing communications so staff learn to trust only your domain. Services like Rebrandly and Lunyb let you build this kind of recognizable link brand.

Frequently Asked Questions

Is a link safe if it starts with HTTPS?

Not necessarily. HTTPS only means the connection between your browser and the server is encrypted — it says nothing about who runs the server. Modern phishing sites almost always use HTTPS because free certificates are easy to obtain. Always verify the domain itself, not just the padlock.

Can I get a virus just by clicking a link without downloading anything?

Yes, though it's rare on updated devices. "Drive-by downloads" exploit browser or plugin vulnerabilities to install malware automatically. Keeping your browser, operating system, and extensions updated eliminates most of this risk. Clicking a phishing link that only shows a fake login page is far more common — the real damage happens when you type credentials.

Are URL shorteners dangerous?

URL shorteners are tools, not threats. Reputable shorteners scan for malicious destinations and give creators useful analytics. The risk comes from not knowing where a short link leads. Preview any short URL with CheckShortURL or urlscan.io before clicking, and when sharing your own links, use a trusted provider.

What should I do if I already clicked a suspicious link?

Don't panic, but act quickly. If you only clicked and didn't enter any information, close the tab, clear your browser cache, and run a malware scan. If you entered credentials, immediately change that password everywhere you reused it and enable multi-factor authentication. If you entered payment details, contact your bank to freeze the card. Monitor accounts for unusual activity for the next 30 days.

Which free link checker is the most accurate?

For most people, combining VirusTotal (broad engine coverage) with urlscan.io (behavioral analysis and screenshots) gives the best results. Google Safe Browsing is excellent for a quick reputation check and is already built into Chrome, Firefox, and Safari behind the scenes.

Final Thoughts

Learning how to check if a link is safe is one of the highest-leverage security skills you can develop. The tools are free, the habits take seconds, and the payoff is avoiding phishing, malware, and financial fraud. Build the five-step routine into your daily workflow, share it with family and colleagues, and you'll be ahead of the vast majority of internet users — and the attackers who prey on them.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles