Guide · Trust and privacy

How to see where a short link goes before you open it

A short link hides its destination; that is both its use and its risk. This guide covers how to read one safely, whichever service made it.

Why the destination is hidden

A shortener replaces a long address with a short code, and the code says nothing about where it leads. OWASP counts unvalidated redirects among the classic vulnerabilities because a trusted-looking address can send the reader somewhere else.

The short address you see tells you who runs the shortener. It does not tell you who made the link or where it goes.

What can be checked without opening it

  • The sender. Who sent it, and did they expect to send it? A link from a compromised account arrives with a familiar name on it.
  • The message around it. Urgency, a prize, a threat about an account: the wording is often more telling than the address.
  • A preview, where the service offers one. On this service a free link opens a page that shows the full destination and the destination’s own title before anything loads from it. If the shortener you were sent has no preview, treat that as information.
  • The code itself. Codes carry no meaning, so nothing in them is evidence either way.

When to stop

If the destination is not one you expected, do not continue. A reputable site reached by typing its name yourself is a safer route than any link.

Report a link that leads somewhere harmful. On this service the report control is on the preview page, and a reported link stops working while it is reviewed.

Questions

Can a short link be checked without opening it?

Often, yes: the sender, the message and a preview page show a good deal. On this service the preview page prints the full destination first.

Is the code in a short link a clue?

No. A code carries no meaning, so it is not evidence of safety or danger.

What if the shortener has no preview?

Ask the sender for the original address, or reach the site by typing its name yourself.

Sources

The documents this guide's statements rest on. Each link opens in a new page.

  1. OWASP: Unvalidated Redirects and Forwards Cheat Sheet