Share
HOW-TO - LINK SAFETY

Where does this shortened link actually go? Check a t.co or bit.ly link before you click

Ten characters of t.co or bit.ly can hide a news article, a coupon, or a fake bank login, and they all look identical until the page loads. Here are the preview tricks that still work in 2026, and the habit that settles it: check where the link ends, not where it starts.

SafeBrowz Threat Research Security ResearchJuly 20, 20267 min read

TL;DR: how to see where a short link goes

You cannot judge a link you cannot read, so reveal the destination first. Add a plus sign to the end of any bit.ly link and Bitly shows the destination instead of redirecting; for TinyURL, put "preview." in front of the domain. For t.co, X's automatic wrapper, there is no preview trick at all. The fastest universal answer: paste the short link into the free SafeBrowz URL checker. It follows the redirect chain and scans the final landing page, the only part of the link that can hurt you.

Why you cannot read a short link

Short links exist for honest reasons: Bitly and TinyURL make long URLs fit a poster or a text, and give marketers click counts. X wraps every posted link in t.co automatically, whether the poster wants it or not, which is why so many people paste bare t.co URLs into a search engine asking what site they redirect to. The services themselves are legitimate, not the threat.

The problem is what shortening removes: the domain, the single most useful signal an ordinary person has. A short link like t.co/AbCd1234 (an illustrative example, not a real link) strips it away. Scammers use this deliberately:

  • It hides the destination. A phishing domain that would scream fake in an email looks like nothing behind a shortener.
  • It slips past casual inspection. Hovering over it on desktop only reveals the short URL itself; nothing gets past the wrapper.
  • The target can change after the link is shared. Some shortener plans let the owner edit where a link points, and attacker-run redirect hops can be re-pointed at any time, so a link that was harmless yesterday can go somewhere else today.

Phishing was the most reported cybercrime of 2024 in the FBI's IC3 annual report, with 193,407 complaints, and short links are a standard delivery wrapper, especially in texts; our complete guide to text message scams shows the pattern across delivery notices, bank alerts, and toll fines.

The redirect chain: the danger lives at the end

A short link is rarely one hop. Click it and a chain unrolls: shortener to click tracker, sometimes to a second shortener, and only then the final page. X even checks t.co destinations against known-dangerous site lists before redirecting, which helps, but no shortener's blocklist catches a phishing page that went live an hour ago.

The chain is the whole game. The front domain is reputable, which is exactly why attackers use it as the front door: any reputation check on it comes back clean, and means nothing. What matters is the last domain, the one that renders in your browser and asks for your password. It is the same trick behind the cloaked pages in the FBI's 2026 alert on redirect-hidden fake login sites: keep the visible link respectable, put the trap at the end. So "is this short link safe?" really means "where does it end, and is that page safe?"

Scan the end of the chain, not the front door

SafeBrowz is a free browser extension for Chrome, Firefox, and Edge, with Safari pending, plus a live Android app. When a link opens, it checks the page that actually loads, after redirects resolve, and can flag it before you type anything. On your phone, where short links in texts do the most damage, the Android app brings the same scan.

Chrome Add to Chrome Firefox Add to Firefox Edge Add to Edge Google Play Get it on Google Play

Manual preview tricks that still work in 2026

We tested each of these. Two still work, one never existed, one has mostly left the stage.

Bitly: add a plus sign. Type a + at the end, so a link like bit.ly/sb-example2026 (an illustrative alias, not a live link) becomes bit.ly/sb-example2026+. Instead of redirecting, Bitly serves an information page that displays the destination URL. We verified it live in July 2026: the destination displayed without the target page ever loading. The plus also works on Bitly's branded short domains.

TinyURL: use the preview subdomain. Change tinyurl.com/sb-example2026 to preview.tinyurl.com/sb-example2026 (the same illustrative alias) and TinyURL shows where the link points before you commit. An official, documented feature, with a cookie setting that turns previews on for every TinyURL link.

t.co: there is no preview trick. No plus suffix, no preview subdomain, no official expander. Inside X the link text usually shows a fragment of the original URL, but a bare t.co link forwarded in a text or email tells you nothing; an external checker is the only option.

goo.gl: mostly retired. Google stopped creating new goo.gl links in 2019 and deactivated inactive ones on August 25, 2025; actively used links and those made inside Google apps still resolve.

One caveat covers them all: a browser cannot expand a short link without visiting it, so "I'll just load it carefully" is a click, not a preview. And a preview may show a tracker or second shortener rather than the true final page; that gap is what an automated checker closes.

Red flags, even without any tool

No checker handy? These should stop you before the tap:

  • A short link in a text from an unknown number. Real couriers and banks send full URLs on their own domains. A bare shortener from an unknown number is the signature move of smishing, the pattern behind the fake USPS delivery text wave.
  • A login page immediately after landing. A short link that resolves straight into a sign-in form is the classic credential trap; kits now proxy the real login to steal session codes, as our adversary-in-the-middle 2FA bypass explainer shows.
  • The brand and the final domain do not match. If a "Netflix offer" ends anywhere but netflix.com, that mismatch is your answer, no matter how perfect the logo. Attackers even fake address bars, as the browser-in-the-browser trick shows.
  • Urgency attached to an unreadable link. "Your package is held" plus a link you cannot read: pressure plus opacity is the scam formula, by SMS, email, or a WhatsApp message from a hijacked contact.

Still: a short link is not automatically malicious. Newsletters, airlines, and your coworkers use them every day, and every link on X wears t.co whether the poster is a scammer or a museum. You cannot judge a link you cannot read, so read it first, then decide.

See the final destination before you click

The SafeBrowz URL checker is built for exactly this question. Paste the short link as you received it and the scanner follows the redirect chain, then scans the final landing page rather than the shortener in front of it. When we fed it a Bitly link wrapping a video page during testing, the verdict came back on the real final domain, not on bit.ly. Scanning the end of the chain is the difference between rating the envelope and reading the letter.

Behind the checker sits SafeBrowz's 3-layer detection architecture: Local + APIs + AI. Shorteners are a routing trick, so the principle is resolve first, judge last.

  • Layer 1 - Local detection: 60+ URL patterns and a 550+ brand database run in the extension before a page renders. Because the check applies to the page that loads, an impersonation page reached through three hops trips the same brand-on-wrong-domain signal as a direct link.
  • Layer 2 - API checks: the resolved final domain is cross-referenced server-side against Google Safe Browsing, PhishTank, URLhaus, ScamAdviser feeds, and 30+ scam TLD lists. A landing domain registered last week carries weight on its own, something the reputable shortener in front of it would never reveal.
  • Layer 3 - AI deep scan (Premium, $14.99/year): AI content analysis via our proxy reads the final landing page, in 100+ languages, and catches brand-new phishing pages no blocklist has seen yet, exactly the gap fresh short links are minted to exploit.

The honest limits: SafeBrowz cannot preview a link inside your SMS app, so pasting it into the checker first is a habit you build, and a scan reflects where a link goes right now; a chain re-pointed tomorrow deserves a fresh check. What it guarantees: the verdict covers the end of the chain, where the danger lives.

Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.

🛡 LIVE CHECK

Scan a short link right now

Paste the t.co, bit.ly, or TinyURL link as you received it. The scanner follows the redirect chain and returns a verdict on the final page in ~3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

How can I see where a t.co link goes without clicking it?

t.co, the shortener X applies to every posted link, has no built-in preview: no plus suffix, no preview subdomain, no official expander. A bare t.co address received in a text or email tells you nothing. The only way to see the destination without visiting it is an external checker: paste the link into the free SafeBrowz URL checker and it follows the redirect, shows the resolved final domain, and scans that page.

Does adding a plus sign to a bit.ly link still work in 2026?

Yes. Typing a + at the end of any bit.ly link opens a Bitly information page that displays the destination URL instead of redirecting. We verified this live in July 2026; it also works on Bitly's branded domains. Two limits: it only covers Bitly links, and it shows the next hop, which can itself be another shortener. For anything sensitive, scan the link so the whole chain is resolved.

Are shortened links dangerous?

Not by themselves. Bitly, TinyURL, and t.co are legitimate services, and X wraps every posted link in t.co automatically. The risk is opacity: a short link hides the destination domain, and some setups let the target change after the link is shared. Treat it as unread mail: probably fine, but verify the destination before entering credentials or payment details on whatever page it opens.

Is it safe to open a shortened link from a text message?

Treat it as hostile until proven otherwise. A short link in a text from an unknown number is the standard opener for smishing: fake delivery fees, toll fines, and bank alerts all use the wrapper to hide the scam domain. Copy the link into a checker first, and never log in or pay on a page a text delivered you to. If it claims to be your bank, go to the bank's app directly.

Last updated 2026-07-20

Related SafeBrowz coverage