Are short links safe?
A short link is as safe as the page it leads to. Shortening does not make a page dangerous and does not make it safe. What it does is hide the destination, so the question to ask is not "is this shortener safe" but "where does this link go, and who sent it to me".
Three ways to see where a short link goes
- Ask the link, without opening the page. On a computer with a terminal, this prints the link's answer and stops there:
Put the link you want to check in place of SHORT-LINK, and keep the quotes around it: they make the terminal treat the whole link as one address, whatever characters it holds. The line that starts with location is where the link sends you next, and nothing from that address is loaded. Treat it as a first look, not as proof: a link can pass through more than one address, and a few services answer this kind of request differently from a browser.curl -sI -- 'SHORT-LINK' - Ask the sender, another way. If the link came from a person or a business you know, call them or write to them through a number, a site or an app you already use. Do not ask by replying to the message: if the account was taken over, the reply reaches whoever took it.
- Go around the link. If a message says it is from your bank, a courier or a shop, open their site or app the way you always do and look for the same notice there. If it is real, it will be there.
After a link's destination is in front of you, read the domain name slowly, from the right. In paypal.example.com the site is example.com, not PayPal.
Signs that a link deserves a second look
- You did not expect the message, or you do not know the sender.
- It pushes you to act now: a parcel that will be returned, an account that will be closed, a payment that failed.
- It asks you to sign in, to pay, or to install something.
- The words around the link name one company and the destination belongs to another.
None of these proves a link is bad. Together they are a reason to use one of the three checks above before you tap.
What a URL shortener can screen, and what it cannot
A shortener sees the destination at the moment a link is created or changed. It can compare that address with lists of pages that are already known to be harmful, and refuse the link.
What screening can do
Refuse a destination that is on a list of known phishing, malware or unwanted-software pages. Check again later and disable a link whose destination was added to a list. Take a link down after a report.
What it cannot do
Know about a harmful page that nobody has listed yet. See what a destination does after the visitor arrives, including where the destination itself redirects. Judge whether a message that carries the link is honest.
So screening lowers the risk and never removes it. The checks in this guide stay useful on every shortener, including ours.
What ktzr.io does
- Every destination is checked against Google Web Risk when a link is created and every time its destination is changed. A destination that is listed is refused. If Web Risk does not answer in time, the link is allowed and checked again in the next daily scan.
- Links are checked again every day during their first 30 days, and a link whose destination becomes listed in that time is disabled.
- Anyone can report a link, with no account. A reported link that is found harmful is disabled.
- A disabled link answers 410 Gone and leads nowhere.
- A link's code is never reused, so an old link cannot start pointing at someone else's page.
Found a ktzr.io link that leads somewhere harmful? Tell us, or write to abuse@ktzr.io.
More guides: Do short links expire?, URL shorteners without ads, Bitly free plan limits