Link safety checks
A flipbook can carry links to anywhere on the web, and a link is only as trustworthy as wherever it lands. So when you add a link, we check where it goes.
This runs quietly in the background. Most of the time you will never see it, which is the point.
What we check, and when
Section titled “What we check, and when”Links are checked when you save them, not when a reader clicks. A published flipbook never waits on a safety service to draw itself, so nothing here slows your document down.
We look at two things:
- Whether the address is a known bad one. Shared threat lists, maintained across the industry, cover sites already reported for malware or phishing. This comes back in milliseconds.
- What is actually on the page. A deeper check opens the destination and looks at what it serves. This takes longer, so it runs after your save rather than holding it up — a link can be saved and then flagged a minute later.
Results are remembered for a while and shared between documents, so a link you use on twenty pages costs one check, not twenty. A remembered result eventually goes stale, and the next time that link is saved it gets a fresh check.
What happens when something looks wrong
Section titled “What happens when something looks wrong”If a link is flagged as dangerous, you cannot add it. You will see a message saying so when you try to save. If a link you already published is flagged later, it stops working for readers — the area stays on the page, but clicking it does nothing rather than taking anyone to the destination.
If a link is uncertain — something looks off, but not clearly enough to call it dangerous — the link still works, and readers see a warning first. It shows them the full address and asks whether they want to continue. They can go back or carry on; it is their call, not ours.
We deliberately word these warnings as suspected. A warning means “we could not vouch for this”, not “this is definitely an attack”.
What this cannot promise
Section titled “What this cannot promise”We would rather be straight with you than oversell this.
No check like this is ever complete. Threat lists depend on somebody having found and reported a site already, so a phishing page set up this morning may not be on any list yet. That is true of every service that does this, including the ones built into browsers.
A destination can change after we check it. A page that was fine when you saved the link can be compromised, sold, or quietly repointed afterwards. A link published a year ago was checked a year ago — we are not continuously re-checking every published link, so a destination that goes bad later will not be caught on its own.
Some sites behave differently depending on who is looking. A page can serve something harmless to an automated check and something else to a real visitor.
Not every link in every document goes through the same checks. Treat the absence of a warning as “we found nothing”, never as “this has been approved”.
So please keep your own judgement. Only link somewhere you would happily send someone yourself, and if you are publishing on behalf of a client, check their destinations before you publish rather than assuming we will catch a bad one.
If you spot something we missed
Section titled “If you spot something we missed”Tell us. A large part of what makes checks like this work is people reporting what they run into — shared threat lists exist because someone reported each entry, and ours get better the same way.
If you find a Living Page document linking somewhere malicious, use Report misuse. You do not need an account, and you do not need to be the person affected. We would much rather look at something that turns out to be fine than miss something that isn’t.
If one of your links has been flagged and you believe that is wrong, get in touch and we will look at it. False positives happen, and we want to know about them.
Links and video overlays — drawing, editing and publishing the links themselves.