Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Not always. Generating a link preview can cause a chat app or its servers to fetch the shared URL, exposing information about the link or the recipient’s IP address. Separately, a preview’s title, image, or displayed domain can be misleading. How much risk exists depends on how a particular app generates previews; end-to-end encryption alone does not prevent fetch-related exposure.
What happens when a chat app creates a link preview?
A preview is assembled from information fetched from the URL, such as a page title, description, or image. Depending on the app’s architecture, the request may come from the sender’s device, the recipient’s device, or the messaging service’s servers. That distinction matters: a server-side request can expose the URL to the service, while a recipient-side request can reveal the recipient’s IP address to the linked site.
Kirchner and colleagues’ 2024 black-box study monitored requests to test pages across messaging services and found materially different request patterns. Among 39 messengers that generally displayed previews, 17 (44%) displayed them only for pages that supplied metadata. Even when metadata was available, 10 messengers made more requests than the researchers considered necessary. These are results for the study’s tested services, not a current estimate of how all chat apps behave. Read the 2024 study.
Server-side fetching can expose the shared URL
For a server-side request (SSR), the app must extract the URL from a message, transmit it to a service server, and fetch the page there. The 2024 researchers describe this as less transparent and more privacy-intrusive than client-side fetching because the messaging provider processes the URL. In some tested services, requests recurred days or weeks after a message; that observation applies to those services and should not be read as universal behavior.
#1 Best Overall
Recipient-side fetching can expose an IP address
Client-side fetching avoids giving the messaging server access to the URL, but it is not risk-free. When the recipient’s device requests the page to create a preview, the destination server can see the device’s IP address. That request can happen before the recipient taps the link.
Can a preview hide a malicious link?
Yes. A preview is not a reliable safety check: its title, description, image, or visible domain may fail to reveal where a link ultimately leads. A manipulated preview can create a reassuring impression even when the destination is different or harmful. This is a problem of deceptive presentation; it does not mean that merely displaying a preview executes malware.
Rank #2
In a 2020 study of 20 social platforms, including instant-messaging apps, Stivala and Pellegrino found that crafted previews could conceal malicious targets on four platforms even from technically knowledgeable users. They found misleading previews could be made on the other 16 when an attacker could register a domain. The study also reported that 18 platforms lacked active or passive countermeasures against known malicious links or software, and that URL cross-checks could be bypassed through client- and server-side redirects. These are historical findings about the platforms and conditions tested, not an audit of today’s versions of every chat app. Read the NDSS 2020 study.
Does end-to-end encryption prevent preview-related exposure?
No, not by itself. End-to-end encryption protects message content in transit and from access by the service under the encryption model, but preview generation may involve a separate request to fetch the URL. If the service extracts the URL and fetches it on its servers, that processing is distinct from the encrypted message exchange. If a recipient’s device fetches it, the destination site may receive the recipient’s IP address. The exact behavior depends on the product’s design.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What privacy tradeoffs do preview designs involve?
The 2024 study’s authors considered zero server-side requests an acceptable design for app-based messengers, where previews can be fetched by a client, and one server-side request acceptable for browser-based chat previews, where browser same-origin protections limit a strictly client-side approach. Those are the researchers’ design judgments, not an industry standard or a guarantee that a particular product follows them. Their findings also show why the number and timing of requests matter, not just whether a preview appears.
What should you do when a preview appears?
- Check the actual domain. Do not treat a familiar logo, page title, or image as proof that a link goes where it appears to go.
- Be cautious with unexpected links. Urgency or pressure to act can be a reason to verify the message through another channel before opening the URL.
- Watch for redirects. A visible or initially checked URL may lead elsewhere after redirection, so a preview or reputation check cannot guarantee the final destination is safe.
- Review current app controls. If privacy matters, check the settings in your installed app version for preview controls; behavior and availability vary, and there is no reliable current cross-app settings matrix established here.
What does Messenger’s newer link protection do?
Meta’s March 9, 2026 engineering article describes Advanced Browsing Protection in Messenger as checking links clicked in chats, including end-to-end encrypted chats. Meta says the design combines private-information-retrieval-inspired lookup, URL-prefix matching, a confidential virtual machine using AMD SEV-SNP, and an Oblivious HTTP proxy intended to reduce what the service can learn about the lookup and its origin. Meta also describes a tradeoff: the client sends a bucket identifier, and privacy and efficiency depend partly on how finely those buckets are defined.
Rank #4
Meta’s explanation is a provider description, not an independent verification or a comparison with other apps. It describes protection when a link is clicked; it does not establish that link previews themselves cannot expose URLs or recipient IP addresses. Read Meta’s engineering explanation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

