How to judge a short link before you tap it
Aug 28, 2026 · 5 min read
A short link hides where it goes. That is the entire point of it, and it is also the reason scammers like them. Both things are true at once, and treating short links as either universally fine or universally suspect will get you the wrong answer about half the time. What follows is how to actually check one, and — if you publish links yourself — how to make yours easy to trust.
Start with the observation that does most of the work: the danger is almost never the shortener, it is the destination. A short link is a redirect. It cannot install anything, and the domain in front of the slash tells you nothing except which service was used. So the only question worth asking is where it lands, and the practical move is to answer that before you arrive rather than after.
Most services, this one included, will show you. Anything you can inspect without visiting the destination is worth doing: preview features, expanders, or simply long-pressing the link on a phone to read the target instead of opening it. If a link is in an email or a message, hovering shows the destination in the status bar on desktop — and if the visible text says one domain while the status bar says another, you have already learned everything you need.
Context does more work than any technical check. The overwhelming majority of harmful short links arrive attached to urgency: a delivery that needs a fee, an account that will close today, a refund waiting, a prize, a parcel held at customs. That pattern is the signal, and it does not change when the wrapper does. A message you did not expect, that wants you to act quickly, pointing at a link you cannot read, is the shape of nearly every successful scam regardless of which shortener carries it.
A short list of things that should stop you outright. A link asking for a password, a card number, or a one-time code, when you did not initiate the request. A destination that is a login page for a service you use — always reach those by typing the address yourself, because a convincing copy costs an attacker nothing. A file that downloads on arrival without you asking. And a chain of redirects that passes through several hops before settling, which is done to defeat exactly the kind of inspection described above.
It is worth knowing what a shortener can and cannot do on its side. Links here can be reported by anybody through the report page, reports are read by a person rather than scored by a filter, and a confirmed harmful link is removed — at which point it stops resolving everywhere it was ever posted or printed. What no shortener can do is guarantee a destination stays safe, because the page behind a link can change after the link is created. Removal is a response, not a shield.
If you are on the publishing side, most of this inverts into things you can do for your readers. Use a custom alias that names the destination — luud.link/menu tells somebody more than luud.link/x7Kp2, and readable aliases are the single cheapest trust signal available. Say where the link goes in the surrounding text rather than making the link carry the whole explanation. Keep one link per campaign instead of repointing a link people have already learned, because a link that quietly starts going somewhere new is behaving exactly like a compromised one.
And do not send unexpected short links to people who have no reason to expect them from you. It trains your own audience into the habit that scammers rely on, which costs you more than the click was worth.