Link safety checker
Paste any link — short or long — and see where it goes and whether it’s safe.
Check where a link goes before you open it
The danger of a link is that you can’t read it. A short URL hides its destination entirely, and even a full URL can point somewhere you don’t expect. This checker resolves the link to its real destination on our server — nothing opens on your device — and layers on the signals that separate a safe link from a phishing one.
What we check
- Final destination and redirect chain. Every hop the link takes, and where it truly ends up.
- Malware & phishing. The destination is checked against Google Safe Browsing’s threat lists.
- Domain age. Newly registered domains are a strong phishing signal.
- HTTPS. Whether the connection is encrypted.
- Lookalike & homograph domains.
paypa1.comor a non-Latin impersonation of a real brand. - Chained shorteners. A destination that is itself another shortener — a classic way to hide a bad link.
Is this link safe? The signs to read yourself
You won’t always have a tool open, so it’s worth knowing the tells. A safe link usually has three things going for it: it’s served over HTTPS, the domain is spelled exactly right, and that domain isn’t brand new. A phishing link fails one of those quietly.
- Read the domain, not the path. The real identity of a URL is the bit right before the first single slash — in
paypal.com.secure-login.co/verify, the domain issecure-login.co, not PayPal. - Watch for swapped characters.
paypa1.com,rnicrosoft.com, or an accented letter that renders identically. One character is the whole attack. - Be wary of urgency. “Account suspended”, “final notice”, “verify within 24 hours” — pressure is a phishing signature, not a bank’s house style.
This checker automates all of that in one pass, but the habit of reading the domain first is the single best defence you have.
Why the redirect chain matters
A dangerous link rarely points straight at the dangerous page. It bounces: a shortener, then an ad redirector, then another shortener, then the payload. Each hop is a chance to slip past a filter that only inspected the first URL. Because this checker follows every redirect to the true endpoint, a link that chains through several services — especially one that ends on another shortener — is flagged for what it is. Seeing the whole path is often more telling than the final domain alone.
Short links and the honest problem
Short links have the same weakness as QR codes: they hide the destination. It would be dishonest for a URL shortener to write about link safety and skip this — so, plainly: any shortener can be abused for phishing, including ours. What differs is what the platform does about it. We scan every destination for malware and phishing when a link is created and recheck periodically, give every link a public preview page, and action every abuse report. If safety matters when you choose a shortener, ask whether it scans destinations and offers previews — several popular ones do neither. For the QR-code angle on the same problem, see our guide to quishing.
Just want the destination?
If you only need to see where a short link leads — without the full safety breakdown — the link expander is the quicker tool.