# Is there a safe way to check out a suspicious URL?

**URL:** <https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435>\
**Category:** Factual Questions\
**Created:** [February 15, 2011, 9:40am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435 "2011-02-15T09:40:19Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nobody](https://avatars.discourse-cdn.com/v4/letter/n/94ad74/32.png) [@Nobody](https://boards.straightdope.com/u/Nobody)\
**Post date:** [February 15, 2011, 9:40am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/1 "2011-02-15T09:40:19Z")

</div>

Sometimes when I get a link I’m not familiar with I Google it and sometimes I get a result, sometimes not. When a link doesn’t get any hits, what other way can I check it out safely? Yes, I have a virus scanner and other anti malware/spyware programs, but I’d still not rather go to a Website that will try to infect my computer.

Thanks.

---

<div class="post-metadata">

**Author:** ![TravisFromOR](https://avatars.discourse-cdn.com/v4/letter/t/cc9497/32.png) [@TravisFromOR](https://boards.straightdope.com/u/TravisFromOR)\
**Post date:** [February 15, 2011, 9:47am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/2 "2011-02-15T09:47:46Z")

</div>

You could go and use a “friend’s” computer…

Other than that, I’m at a loss.

(Actually, I recommend using a public computer, that doesn’t have anyone’s personal information on it. (Of, if it does, it’s their own damn fault.))

---

<div class="post-metadata">

**Author:** ![scudsucker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scudsucker/32/14101_2.png) [@scudsucker](https://boards.straightdope.com/u/scudsucker)\
**Post date:** [February 15, 2011, 9:48am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/3 "2011-02-15T09:48:31Z")

</div>

There is nothing that is 100% safe, as new threats appear all the time. Aside from using someone else’s computer instead of yours!

I would recommend Firefox with the NoScript add-on. This combination prevents many common problems (usually associated with Internet Explorer - I assume you use Windows) and in addition block malicious (or rather, all) javascript, which is a common vector for attack.

If you are really really paranoid and have not got access to (ab)use someone else’s computer, you could get hold of on of several Linux distributions that run as a stand-alone operating system on a thumb-drive.

Even if this was compromised - which is very, very unlikely - the damage would be limited to that OS, which could be overwritten if you realize there was a problem.

---

<div class="post-metadata">

**Author:** ![matt](https://avatars.discourse-cdn.com/v4/letter/m/a6a055/32.png) [@matt](https://boards.straightdope.com/u/matt)\
**Post date:** [February 15, 2011, 10:02am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/4 "2011-02-15T10:02:33Z")

</div>

The Offbyone free mini-browser is pretty hard to hurt. As far as I know, it renders html and that’s it. No java, no flash, no activex scripts, nothing. Hard to get an infection that way. It’s becoming increasingly useless as an actual browser though!

[http://offbyone.com/offbyone/](http://offbyone.com/offbyone/)

---

<div class="post-metadata">

**Author:** ![Nobody](https://avatars.discourse-cdn.com/v4/letter/n/94ad74/32.png) [@Nobody](https://boards.straightdope.com/u/Nobody)\
**Post date:** [February 15, 2011, 10:11am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/5 "2011-02-15T10:11:20Z")

</div>

I might try it. I do use Firefox with Flashblock, NoScript, and Adblock, but I have run across sites I had to quickly close down.

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [February 15, 2011, 11:31am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/6 "2011-02-15T11:31:09Z")

</div>

Put the link domain in this URL, in place of [example.com](http://example.com):

[http://www.google.com/safebrowsing/diagnostic?site=example.com](http://www.google.com/safebrowsing/diagnostic?site=example.com)

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [February 15, 2011, 11:59am UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/7 "2011-02-15T11:59:31Z")

</div>

You could put the domain name in a whois search and see what pops up. If it is hosted in China, Russia, Bulgaria, or Nigeria, unless you are an exporter to those areas or have relatives there, it’s probably not something you want to mess with.

---

<div class="post-metadata">

**Author:** ![Tim\_T-Bonham.net](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@Tim\_T-Bonham.net](https://boards.straightdope.com/u/Tim_T-Bonham.net)\
**Post date:** [February 15, 2011, 12:56pm UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/8 "2011-02-15T12:56:57Z")

</div>

There is also the Web of Trust. This is basically a voting scheme for internet sites; members flag sites that contain problems (malware, spyware, email grabbers). Then when you get a list of url’s (like from a Google search, etc.) the WOT Add-on marks each url with a stop-light type symbol (green, yellow, or red) to indicate how trustworthy the url is.

This obviously only partially helpful; it depends on others having gone to the same url before, discovered problems, and flagged that url. So newly-created or obscure bad urls may just show up with nothing known about them. And it could be subject to manipulation; there seem to be some church groups trying to flag all atheist or gay sites as ‘untrustworthy’. But at least this gives you some idea of which urls are bad.

---

<div class="post-metadata">

**Author:** ![Panurge](https://avatars.discourse-cdn.com/v4/letter/p/fbc32d/32.png) [@Panurge](https://boards.straightdope.com/u/Panurge)\
**Post date:** [February 15, 2011, 1:14pm UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/9 "2011-02-15T13:14:43Z")

</div>

You could try [sandboxing](http://en.wikipedia.org/wiki/Sandbox_%28computer_security%29). Either by running your browser within a sandboxing program such as [sandboxie](http://www.sandboxie.com/) or by using a browser extension that lets you run a tab in sandbox mode. I think Chrome has that option - I’m not sure about IE, FF or Safari.

---

<div class="post-metadata">

**Author:** ![Lare](https://avatars.discourse-cdn.com/v4/letter/l/53a042/32.png) [@Lare](https://boards.straightdope.com/u/Lare)\
**Post date:** [February 15, 2011, 2:29pm UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/10 "2011-02-15T14:29:10Z")

</div>

> [@tellyworth](#):
>
> Put the link domain in this URL, in place of [example.com](http://example.com):
> 
> [Google Transparency Report](http://www.google.com/safebrowsing/diagnostic?site=example.com)

Hey, that’s pretty cool! Thanks **tellyworth!**

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [February 15, 2011, 2:48pm UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/11 "2011-02-15T14:48:26Z")

</div>

> [@tellyworth](#):
>
> Put the link domain in this URL, in place of [example.com](http://example.com):
> 
> [Google Transparency Report](http://www.google.com/safebrowsing/diagnostic?site=example.com)

This is a good resource. I also use the following to check out suspicious links:

[http://www.virustotal.com/index.html](http://www.virustotal.com/index.html)  
[http://www.siteadvisor.com/](http://www.siteadvisor.com/)  
[http://www.trustedsource.org/](http://www.trustedsource.org/)

> **[Safeweb](https://safeweb.norton.com/)**

> **[MalwareURL Listing Report](https://www.malwareurl.com/listing-urls.php)**
>
> Detailed reports of malicious URLs from MalwareURL.com

I like to check suspicious sites with multiple resources, since none of them can keep track of all the bad guys out there.

Another good resource is [http://www.unshorten.com/](http://www.unshorten.com/). If you have a shortened URL, like a tinyurl or bit.ly URL, this will show you the original URL. You can then feed that to one of the resources above.

Best of luck.

---

<div class="post-metadata">

**Author:** ![Lare](https://avatars.discourse-cdn.com/v4/letter/l/53a042/32.png) [@Lare](https://boards.straightdope.com/u/Lare)\
**Post date:** [February 15, 2011, 2:55pm UTC](https://boards.straightdope.com/t/is-there-a-safe-way-to-check-out-a-suspicious-url/571435/12 "2011-02-15T14:55:06Z")

</div>

And that’s even better. I recognized the possible security threats of shortened URLs some time ago, too.
