Think about the last link you opened on your phone. Chances are you didn't type it. It arrived — in a WhatsApp group, in a text message from a number you don't know, in an email that looked like it came from your bank, or printed as a QR code on a restaurant table or a parking meter. You tapped it because tapping is what we do with links.

That habit is exactly what bad links rely on. Most people who get burned online didn't go looking for trouble. Someone sent them something, and it looked normal enough to open. So we built a small tool into the Vela app that does one job: it lets you check a link before you open it. We call it Scan.

Why forwarded links are where people get burned

In much of the Middle East, WhatsApp is where life happens — family groups, work groups, school groups, neighborhood groups. That's what makes it such an effective way to spread a bad link. A message that says 'Your parcel is waiting, confirm delivery here' or 'Look at this offer before it ends' travels from phone to phone, forwarded by people who mean well. By the time it reaches you, it comes from your cousin or a colleague, not from a stranger.

SMS works the same way: short messages about a delivery fee, a blocked account, a traffic fine or a prize, each with a link to 'sort it out'. And QR codes have made the problem harder to see. A QR code is just a link you can't read. You point your camera, a page opens, and you never saw the address at all. A sticker placed over a real QR code on a menu or a payment sign is enough to send people somewhere else.

None of this needs clever hacking. It needs you to open the link. That's why the moment before you tap is the most useful place to put a check.

A link from someone you trust is still a link you didn't write. Your friend forwarded it; that doesn't mean your friend checked it. Trust the person, and still check the link.

What Scan is

Scan is a link checker built into the Vela app. You give it a link in one of two ways: paste it in, or point your camera at a QR code. You can also paste a whole message — Scan pulls the web address out of the text for you. Then, before anything opens, it gives you a verdict and the reasons behind it.

That last part matters. A tool that just says 'bad' or 'fine' asks you to trust it blindly. Scan tells you what it noticed, in plain words, so you can make your own decision — and so you slowly learn what bad links tend to look like.

What Scan checks

Scan looks at two kinds of evidence. The first is a list of sites already known to spread malware. If the address is on that list, you'll see it straight away. The list is kept up to date in the background, so you don't need to do anything to refresh it.

The second is a set of risky signs — patterns in the address itself that bad links often share, even when they're too new to be on any list. Here's what Scan looks for, and what each one means:

Scan is also careful not to cry wolf. A single weak sign on its own — say, a short link from a friend — is shown to you, but it won't turn the verdict into a warning. It takes one strong sign, or two weaker ones together, to do that.

What each verdict means — and what to do

Dangerous

The address is on the list of known malware sites. This is the one verdict that isn't a judgment call — the site has already been reported. Tap 'Don't open' and delete the message. If it came from someone you know, tell them; their account or phone may be the thing sending it.

Suspicious

The address isn't on the malware list, but it shows risky signs, and Scan lists them. Read the reasons. If you weren't expecting this link, don't open it. If you need to reach the service it claims to be — your bank, a delivery company, a government office — go there yourself, by typing the address you know or using their official app, rather than through the link you were sent. You can still open it with 'Open anyway (not recommended)', but that choice is yours, made with the facts in front of you.

No warning signs

The address isn't on the malware list and nothing risky stood out. That's good news, but notice the wording: we deliberately don't call it 'safe'. It means Scan found nothing wrong, not that nothing could be wrong. Open it if you were expecting it, and stay alert on the page that loads — especially if it asks for a password or a card number.

No link found

Scan couldn't find a web address in what you pasted. Try pasting just the address itself, or use 'Scan a QR code' if the link came as a code.

Privacy: checked on your phone, not on our servers

A link checker that sends every link you check to a company somewhere would be a strange thing for a privacy app to ship. The links you're unsure about are often the most personal ones — a bank alert, a medical result, a message you'd rather nobody else saw.

So Scan works entirely on your device. The link is checked privately on your phone — it never leaves it, and Vela never sees your links. The list of known malware sites lives in the app and is updated in the background with a plain download that contains nothing about you or anything you've checked. And as mentioned above, Scan never follows a short link to see where it leads, because that would quietly announce your interest to whoever is on the other end.

This fits the way we run the rest of Vela. If you want to know what we do and don't keep, our post on what a no-logs VPN really means explains how to judge that claim for any provider, including us.

What Scan can't promise

We'd rather be honest about the limits than oversell a feature. No link checker catches everything, and Scan is no exception.

Think of Scan as a second opinion that takes two seconds, not as a shield that makes caution unnecessary. The habits still matter: be wary of urgency ('your account will be closed today'), go to important services directly rather than through links, and never type a password into a page you reached from a message you weren't expecting.

How to use Scan

Scan is in the Vela app on Android. Here's the quickest way in:

  1. Open Vela and find the Ask before you click card on the Home screen. Tap it to open Scan.
  2. To check a link, copy it from WhatsApp, SMS or email, then paste it into Paste a link and tap Check link. Pasting the whole message works too.
  3. To check a QR code, tap Scan a QR code and point your camera at it. Scan reads the code and checks the link inside without opening it.
  4. Read the verdict and the reasons, then choose: Don't open, Open link, Copy link, or Check another.

If you'd rather not give the camera permission, that's fine — you can still paste links and check them the same way.

Scan sits alongside the other protections in Vela: WireGuard encryption for everything leaving your phone, a kill switch that stops traffic if the tunnel drops, and alerts when you join an unsafe Wi-Fi network. If you often connect in cafés, hotels and airports, our guide to whether public Wi-Fi is actually dangerous covers the other half of staying safe on the move.

The next time a link lands in the family group with 'forward this to everyone', you don't have to guess. Paste it into Scan first. It takes a couple of seconds, it stays on your phone, and it might be the most useful thing you do all week.

Ask before you click

Scan checks links and QR codes privately on your phone — known malware sites plus the risky signs that give bad links away. It's in the Vela app now, next to everything else that keeps you safe online.