How to Check if a Link is Safe Before Clicking
You received a link in an email, text message, or social media DM. It looks a bit suspicious — maybe it's shortened, maybe the domain looks unfamiliar. Should you click it?
Every day, millions of malicious links are sent via phishing emails, fake social media accounts, and compromised websites. Clicking the wrong link can lead to stolen credentials, malware infections, or financial fraud.
The good news: you can verify almost any link before clicking. Here are 6 methods to check if a link is safe.
Why You Should Check Links Before Clicking
Cybercriminals use malicious links to:
- Steal login credentials through fake login pages (phishing)
- Install malware that captures keystrokes or encrypts your files
- Redirect to scam sites that trick you into payments or personal info
- Compromise your accounts by hijacking sessions or cookies
Short links and unfamiliar domains make this worse — you can't see where you're going until it's too late.
Method 1: Hover Over the Link (Don't Click)
The simplest check: hover your mouse over a link without clicking. Most browsers display the actual destination URL in the bottom-left corner of the window.
What to look for:
- Does the displayed URL match what you expect?
- Is there a domain mismatch? (e.g., the email says "PayPal" but the link goes to
paypa1-secure.com) - Are there suspicious subdomains? (e.g.,
paypal.malicious-site.com)
Limitation: This doesn't work on mobile devices, and some link shorteners hide the final destination.
Method 2: Use a URL Scanner Tool
Several free tools scan URLs against databases of known malicious sites:
| Tool | What It Checks |
|---|---|
| Google Safe Browsing | Checks against Google's malware and phishing database |
| VirusTotal | Scans URL with 70+ security engines |
| URLVoid | Checks domain reputation across multiple blacklists |
| PhishTank | Community-driven phishing URL database |
How to use: Copy the suspicious link (right-click → "Copy link address"), paste it into the scanner, and review the results before visiting.
Method 3: Expand Shortened URLs
Shortened links (bit.ly, tinyurl.com, t.co, etc.) hide the destination. Before clicking, expand them to see where they actually go.
URL expander tools:
- CheckShortURL.com — Reveals the destination of most short links
- Unshorten.It — Shows full URL chain and safety rating
- GetLinkInfo.com — Provides detailed redirect analysis
Pro tip: Many legitimate shorteners (including Linkly) let you preview destinations. Add a + to the end of bit.ly links (e.g., bit.ly/abc123+) to see a preview page.
Method 4: Check for Red Flags in the URL
Train yourself to spot suspicious URL patterns:
Domain misspellings:
arnazon.cominstead ofamazon.compaypa1.com(number 1 instead of letter l)g00gle.com(zeros instead of o's)
Suspicious subdomains:
amazon.malicious-site.com— The actual domain ismalicious-site.com, not Amazonsecure-login.bank.suspicious.com— Legitimate banks don't do this
Missing HTTPS:
- While HTTPS alone doesn't guarantee safety, legitimate sites handling sensitive data should always use it
- Look for the padlock icon in your browser's address bar
Unusual TLDs:
- Be cautious of unfamiliar extensions like
.xyz,.top,.buzzon supposedly legitimate business sites
Method 5: Check the Link's Context
Consider where the link came from:
Warning signs:
- Urgency: "Your account will be suspended in 24 hours!"
- Too good to be true: "You've won a $1,000 gift card!"
- Unexpected sender: A "friend" you haven't heard from in years
- Generic greeting: "Dear Customer" instead of your name
- Grammar/spelling errors in the message
Safer sources:
- Links from verified social media accounts
- URLs you typed yourself or bookmarked
- Links from known contacts about expected topics
Method 6: Use a Trusted Link Shortener's Preview Feature
Not all short links are suspicious. Reputable link shorteners provide transparency features:
What trustworthy shorteners offer:
- Destination previews — See where the link goes before clicking
- SSL encryption — Secure redirects that protect your data
- Spam monitoring — Active detection and blocking of malicious links
- Branded domains — Custom domains that show the source (e.g.,
yourbrand.com/offerinstead ofbit.ly/xyz)
Linkly, for example, provides full transparency: users can see the destination URL, and all links use HTTPS with active spam monitoring. Our anti-spam policy ensures malicious links are detected and removed.
How to Stay Safe: Quick Checklist
Before clicking any link:
- Hover to preview the URL (on desktop)
- Check for domain misspellings or suspicious subdomains
- Verify HTTPS is present
- Consider the context — is this expected?
- For short links, use an expander tool
- When in doubt, go directly to the site by typing the URL yourself
What to Do If You Clicked a Suspicious Link
If you accidentally clicked:
- 1Don't enter any information — Close the page immediately
- 2Disconnect from the internet — Prevents malware from communicating
- 3Run a security scan — Use your antivirus software
- 4Change passwords — Especially if you entered credentials on a fake site
- 5Monitor accounts — Watch for unauthorized activity
- 6Report the link — Submit to Google Safe Browsing or PhishTank
The Bottom Line
Verifying links before clicking takes seconds but can save you from identity theft, financial loss, and malware infections. Use the methods above to stay safe:
- 1Hover to preview
- 2Use URL scanners
- 3Expand shortened links
- 4Look for red flags
- 5Consider the context
- 6Trust only reputable shorteners
When sharing links yourself, use a trusted service like Linkly that provides branded domains, destination transparency, and active spam protection. Your recipients will thank you.
Need to share links people can trust? Use a free link shortener like Linkly with branded domains and active spam protection — no credit card required.
Frequently Asked Questions
How can I tell if a shortened link is safe?
Use a URL expander tool like CheckShortURL.com or Unshorten.It to reveal the destination before clicking. You can also paste the shortened URL into VirusTotal to scan it against malware databases. Reputable link shorteners like Linkly also provide destination previews and use HTTPS encryption.
What should I do if I accidentally clicked a phishing link?
Don't enter any information and close the browser immediately. Run a full antivirus scan, change any passwords you may have entered, and monitor your accounts for suspicious activity. Report the phishing link to Google Safe Browsing or PhishTank to help protect others.
Are all URL shorteners safe?
Not all shorteners are equally trustworthy. Look for services that offer HTTPS encryption, destination previews, active spam monitoring, and branded domain options. Free anonymous shorteners are more commonly abused for malicious links.
How do hackers use malicious links?
Hackers use malicious links for phishing (fake login pages to steal credentials), malware distribution (drive-by downloads), and scams (fake prize notifications or urgent warnings). They often disguise these links using URL shorteners or domain names that look similar to legitimate sites.
Can I get a virus just from clicking a link?
In some cases, yes. "Drive-by downloads" can install malware just by visiting a compromised page, especially if your browser or plugins are outdated. Always keep your browser and security software updated, and verify links before clicking.