Go to content
cutty.dev
All posts

How to check where a shortened link leads (before you click)

A shortened link hides the true destination address. We show you how to safely check where it leads before you click on it, and how to recognize a scam attempt.

A shortened link has one problem. Nothing is visible after it. cutty.dev/aB3k9 could open a cheesecake recipe or a fake bank website waiting for your login. The letters are the same. The risk is completely different.

Therefore, before you click, it is worth knowing how to check a shortened link and preview where it actually leads.

Three ways to take a look underneath

Hover with the cursor. On a computer, it is enough to hover over the link without clicking. The full destination address will pop up in the bottom left corner of the browser. It has worked for years, yet few people use it.

Expand the address. Most shorteners (including cutty.dev) have a preview page or the link can be expanded using an "expand URL" type tool. You paste the shortened one, you get the long one. That's it.

Run it through a scanner. Public URL scanners will show not only the target, but also whether the domain is already reported as malicious. Useful when a link comes from someone you don't know.

There is still a fourth, lazy trick: paste the link in the chat to yourself. Usually, a preview with the destination page title will be pulled in. Sometimes that is enough to let it go immediately.

Red flags

Certain things should set off alarm bells for you before you even reach for the scanner. The link came from nowhere, in an SMS or email, and is very urgent ("pay an extra 1 PLN for your package", "your account will be blocked within 24 hours"). Haste is a scammer's favorite tool because it shuts down thinking.

Second flag: the link leads to a bank or email login, and you didn't start any login process. Third: the sender is unknown, or the address looks "almost" real. InPost vs inp0st. One digit, all the difference.

And one obvious thing, which is often overlooked. If after expanding the target domain has nothing to do with the company that is supposedly writing to you, then the conversation is over. Do not click. Go to the company's website manually by typing the address from memory or from your bookmarks.

What a trimmer can do by itself

A good URL shortener makes life harder for scammers, not just shorter. Here at cutty.dev, it is impossible to redirect a link to trap addresses or technically reserved domains, as this is a classic trick used in abuses. The rate of creating links from a single source is limited so that no one can generate a thousand spam links in bulk.

Tips are also not recycled. Once used, they do not return to the pool. This way, no one can take over an old, trusted link and replace the destination under it.

You can also secure your own link with a password. In that case, even after clicking, the recipient must enter a PIN before they can see anything. We wrote about this separately.

The rest is up to you. A second to hover your cursor or expand the address costs less than undoing a wiped account. Next time you receive a mysterious xyz/aB3k9 from someone strangely impatient, just take a look underneath first.