To check where a short link goes, look at its destination before your browser follows it: add + to a zou.sh link, use the preview feature of the shortener that made it, or paste it into a link expander. Then read the destination’s domain carefully, because the domain, not the short link, tells you who you are dealing with. This guide covers each method, the red flags of phishing links and what to do if you already clicked.
Why short links deserve a second look
A short link hides its destination by design. That is what makes it tidy, and it is also why scammers like it: a short link in a text message can lead to a fake bank login page and look exactly like a link to a real one.
Reputable shorteners fight abuse. Blinkhop checks every destination at creation against a blocklist of about 390,000 phishing and malware domains, refreshed every night from two open sources, URLhaus (run by abuse.ch) and the Phishing.Database project. It also refuses links with embedded credentials, links to private or local network addresses and links to other zou.sh links. The link safety page explains these checks.
No blocklist is complete, though. A phishing site registered this morning may not be on any list yet. That is why the habits below matter even when a link comes from a service you trust.
First, get the real link without opening it
In an email or a web page, the text you see is not always the address behind it. A link that reads “mybank.com” can point anywhere. Before any of the checks below, find out what the link really is:
- On a computer, hover over the link. Most browsers and email apps show its address in a corner of the window. For a short link, that only reveals the short address, which is where the next sections come in.
- On a phone, press and hold the link instead of tapping it, then choose the option to copy it. Some phones show a live preview of the page in that menu, which loads the page, so copy the link rather than waiting on the preview.
- In a text message, the link is usually shown in full. Copy it the same way.
Once you have the short link as text, you can preview it safely.
How to check where a short link goes on zou.sh
Add + to the end of the link
Every zou.sh link has a public preview page. Add a plus sign to the end of the link:
https://zou.sh/launch+
Instead of redirecting, zou.sh shows a page with:
- The full destination URL
- The date the link was created
- The total number of clicks
- A “Report this link” form
If the destination looks right, you can continue to it from there. If the link has been disabled for abuse, you see a “This link was disabled” page instead, served with HTTP status 410.
From code or an AI assistant
Developers can get the same information from the API. A GET request returns the destination, the click count and the creation date, or a 404 if the link does not exist:
curl -s https://api.blinkhop.com/v1/links/launch
If your AI assistant is connected to Blinkhop’s MCP server, ask it “Where does zou.sh/launch go?” and it can answer with the expand_link tool.
Preview tricks for other shorteners
Several other services have their own preview features. As of October 2026, these are documented by the services themselves:
| Shortener | How to preview a link | Where it is documented |
|---|---|---|
| zou.sh (Blinkhop) | Add + to the end of the link | This guide |
| bit.ly (Bitly) | Add + to the end of the link, or use Bitly’s Link Checker | Bitly Trust Center |
| is.gd | Add a dash (-) to the end of the link | is.gd FAQ |
| v.gd | Shows a preview page by default | is.gd FAQ |
| tinyurl.com, t.co and others | Use a link expander, as described below |
Features can change, so if a trick does not work, fall back on a link expander.
Use a link expander for any short link
A link expander follows the redirects of a short link for you and shows where they end, without opening the destination in your browser.
Blinkhop’s free link expander
Paste any short link into the link expander, including bit.ly, tinyurl.com and t.co links, to see where it leads. Developers can call the same feature through the API. It follows up to 10 redirects and returns each hop of the chain, the final destination and a safety verdict:
curl -s -G https://api.blinkhop.com/v1/expand \
--data-urlencode "url=https://bit.ly/XXXXXXX"
Seeing every hop matters. Some phishing links chain several shorteners together, so that the first one looks harmless and the real destination only appears at the end.
From the command line
With curl, the -I option asks for the response headers only. It shows the redirect without following it, so your browser never touches the destination:
curl -sI https://zou.sh/launch | grep -i '^location'
The location line is the destination. If there is no such line, the service may redirect in another way, and a link expander or the service’s own preview is the better tool.
Red flags of phishing links
Once you can see the destination, read it carefully. These are the warning signs to look for, with made-up examples:
- Look-alike spelling.
rnybank.comuses “rn” to imitate “m”, andexamp1e.comuses the digit 1 instead of the letter l. - A brand name in the wrong place. Read the host name from right to left. In
login.mybank.com.account-check.net, the site you are visiting isaccount-check.net, notmybank.com. - An @ sign in the address. In
https://mybank.com@203.0.113.7/login, browsers treat everything before the @ as a user name and go to203.0.113.7. Blinkhop refuses links like this. - A raw IP address instead of a domain name.
- Strange characters or
xn--in the domain. Letters from other alphabets can imitate Latin letters, and browsers sometimes display such domains in their encodedxn--form. - A chain of several shorteners, or a short link that leads to another short link.
- An unexpected login, payment or download page. If you clicked to read an article and land on a sign-in form, stop.
- Pressure in the message around the link. The FTC’s guide to phishing scams lists signs such as generic greetings, claims that your account is on hold because of a billing problem, invitations to update payment details through a link, and fake alerts about suspicious log-in attempts.
The padlock in the address bar is not a safety signal. It only means the connection is encrypted, and phishing sites use HTTPS too.
What to do if you clicked a suspicious link
Clicking does not always mean harm was done. What matters most is what happened next.
- If you only opened the page, close it without typing anything.
- If you typed a password, change it right away on the real site, by typing its address yourself rather than using a link. Change it anywhere else you reused it, turn on two-factor authentication, and check recent activity and signed-in devices.
- If you entered card or bank details, contact your bank or card issuer using the phone number on your card or statement.
- If a file downloaded, do not open it. The FTC advises updating your security software, then running a scan and removing anything it flags.
- If you gave away information such as a Social Security number (in the United States), the FTC points to IdentityTheft.gov for the specific steps to take.
Report it
Reporting helps protect the next person:
- In the United States, the FTC recommends forwarding phishing emails to reportphishing@apwg.org, forwarding scam text messages to SPAM (7726) and reporting the attempt at ReportFraud.ftc.gov.
- For a zou.sh link, open its preview page with + and use the “Report this link” form, or use the abuse report form. Abusive links are disabled.
- For a Bitly link, the Bitly Trust Center links to a report form for suspicious links.
Developers can also report a zou.sh link through the API:
curl -s https://api.blinkhop.com/v1/reports \
-H "Content-Type: application/json" \
-d '{"short_url": "https://zou.sh/7Kp2x", "reason": "Fake bank login page"}'
Key takeaways
- Add + to any zou.sh link to see its destination, creation date and total clicks before you visit.
- Bitly supports the same + trick, is.gd uses a dash, and v.gd shows a preview page by default.
- For any other short link, use a link expander, which follows every redirect and shows the final destination.
- Read the destination’s domain from right to left and watch for look-alike spelling, @ signs, raw IP addresses and unexpected login pages.
- If you clicked and typed a password, change it on the real site and turn on two-factor authentication.
- Report phishing links to the shortener and, in the US, to the FTC.