Shortened Links and Redirects
Short links and redirect chains hide where a link really goes, which phishers love. How shorteners and redirects work, and safe ways to see the real destination first.

Short links are convenient: a long address becomes a few characters that fit in a text. But they also hide the destination, which is exactly what a phisher wants. Redirects do the same trick in a different way, starting on a trusted site and ending somewhere else.
How they hide the destination
- Link shorteners turn a long URL into a short code on the shortener's domain.
- Redirect chains bounce you through several addresses before landing on the phishing page.
- Open redirects on legitimate sites forward you anywhere, so the link starts with a domain you trust.
- QR codes hide the address entirely until scanned. See QR code phishing.
Safe ways to check
- Ask: was I expecting this link? If not, go to the organization directly.
- Use a preview: some shorteners show the destination if you add a preview character or visit their preview page.
- Use a checker that expands links without you visiting them.
- Watch the address bar after any link opens; if it lands on an unfamiliar domain, close it.
A trusted domain at the start of a link is not enough. Redirects can take you from a real site to a fake one in an instant. Check where you end up before typing anything.
For organizations
- Avoid short links in messages to customers where possible, or use a branded short domain.
- Fix open redirects on your websites.
- Tell customers you will never send links asking for passwords or codes.
Got a short link? Paste it into CyberWatch AI Scan for a free check before opening it.
For more, read our phishing guide.
Frequently asked questions
Are all short links dangerous?
No. Many organizations use them legitimately. The problem is that you cannot see the destination, so treat short links in unexpected messages with extra caution.
How can I see where a short link goes?
Some shorteners offer a preview page, and link-expanding tools can show the destination without visiting it. The safest option is to go to the organization directly.
What is an open redirect?
A link on a legitimate website that forwards you anywhere. Phishers use them so the link starts with a trusted domain but ends on a fake site.
Sources
- How To Recognize and Report Spam Text Messages, US Federal Trade Commission
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre


