Where does this link actually go? Check without clicking
Short links hide the destination, and that's the point of them. One curl command tells you where a link lands before you commit to going there, and there's a version for people who don't live in a terminal.
Someone sends you a bit.ly link. Or a QR code in a car park. Or a tracking link from a delivery company you're not sure you ordered from.
You can see where it goes without going there.
The command
curl -sIL -o /dev/null -w '%{url_effective}\n' https://bit.ly/example
That follows the redirects and prints the final URL. Nothing else. Breaking it down:
-squiet-IHEAD request, so you ask for the headers and not the page-Lfollow redirects-o /dev/nullthrow the body away-w '%{url_effective}'print where you ended up
If you want to see every hop rather than just the last one:
curl -sIL https://bit.ly/example | grep -i '^location:'
That's often more interesting. Shorteners chained through three other shorteners is a shape that honest links don't usually have.
Some servers behave differently for a HEAD request. If you get nothing useful, drop the -I and it'll do a GET instead while still throwing the body away:
curl -sL -o /dev/null -w '%{url_effective}\n' https://bit.ly/example
If you're not in a terminal
Most shorteners will show you the destination if you add a character to the link:
- bit.ly — add a
+on the end - tinyurl — put
preview.in front of it
Those aren't universal, so don't rely on them for anything that matters.
On a phone, long-press the link instead of tapping it. Both iOS and Android show you the real URL in the preview.
Reading what comes back
You've got the real URL. Now read it right to left.
Find the last two labels before the first single slash. That's the registrable domain, and it's the only part that tells you who owns this.
https://secure.microsoft.com.account-verify.co/login
^^^^^^^^^^^^^^^^^^^
That's account-verify.co. Everything to the left is a subdomain they made up, and you can put anything in a subdomain. This trick works on nearly everyone because we read left to right and stop as soon as we see something we recognise.
Two honest limits
They know you looked. curl still makes a request. The server sees your IP and that something fetched the link. For a suspicious link in a targeted message, that confirms the address is live and someone is paying attention. Use a VPN or a throwaway box if that matters to you.
They can lie to curl. Phishing kits routinely serve a harmless redirect to anything that doesn't look like a real browser, and the real payload to everyone else. So a clean result is reassuring, not proof.
The one that gets people
A link can resolve to a domain you genuinely trust and still be a problem. Open redirects, file-sharing links on real Google or Microsoft infrastructure, tracking links from a real marketing platform that the sender has an account with.
The domain check tells you who's hosting. It doesn't tell you who uploaded.
If the link came in an email and you want the fuller picture, paste the raw message into the phishing email analyzer — it reads the headers and the paths together, in your browser. And if you want to get faster at the URL-reading part, that's one of the things the daily drill puts in front of you.