Paste a suspicious link from a text, DM, or email and instantly check it for common scam patterns before you click.
The link you paste is never sent anywhere. This tool analyzes the link's structure entirely in your browser using pattern-matching rules — not a lookup against any external database. No accounts, no cookies, no analytics tracking what you type.
bit.ly/abc123 ·
amaz0n-security.com ·
paypal.com.verify-user.info ·
google.com
This checker looks at the structure of the link itself — not what's on the page it leads to — for patterns commonly used in scam and phishing links: raw IP addresses used as a website name, URL shorteners that hide the real destination, excessive subdomains used to bury a fake page behind a familiar-looking brand name, a brand name appearing somewhere other than the actual domain, and domain endings disproportionately used in scam campaigns.
A "clean" result means no obvious structural red flags — it doesn't guarantee the site is safe, since scammers do sometimes use completely normal-looking domains. Always still apply the basics: don't enter passwords or personal details unless you're certain of the site, and when in doubt, go directly to the official website yourself instead of clicking the link.
A dangerous link rarely looks dangerous. It arrives wrapped in a believable story — a parcel that could not be delivered, a shared document, a bank alert — and the URL itself is usually dressed up: extra subdomains (netflix.account.verify-secure.com), hyphens substituting for dots, or well-known brands buried deep in the path. This tool inspects the structure of a link for the patterns attackers rely on.
No automated check is perfect, and the strongest signal is context: Were you expecting this link? If not, do not rely on the checker alone — go to the site by typing its address yourself, or contact the sender through a different channel to confirm they sent it.
Almost every phishing attack depends on you glancing at a link rather than reading it. Learning to read one properly takes about two minutes and protects you for life.
Take this address: https://www.paypal.com.secure-login.xyz/verify. Most people see "paypal.com" near the start and stop there. The part that decides where you actually go is the last two labels before the first single slash — here, secure-login.xyz. Everything to the left of that is subdomain, and anybody who owns a domain can put any words they like in a subdomain. "paypal.com" in that position is decoration, not identity.
So the rule is: find the first single slash after the "https://", then read backwards from it. The two labels immediately before that slash are the real site. login.microsoftonline.com/x is Microsoft. microsoft.login-verify.net/x is not.
The padlock in the address bar means traffic between you and that site is encrypted. It says nothing about whether the site is honest. Certificates are free and issued automatically, so the overwhelming majority of phishing sites have one. The padlock tells you nobody is eavesdropping on the conversation. It does not tell you who you are talking to.
The tool on this page examines the structure of the address you paste: the domain layout, subdomain count, character substitutions, known shortener services, raw IP addresses, and domain endings that appear disproportionately in scam campaigns. It runs entirely in your browser and does not visit the link or send it anywhere.
It cannot tell you what is on the page, whether the site was compromised an hour ago, or whether a brand-new domain with a perfectly ordinary name is a fake. A clean result means "no obvious structural red flags", which is useful but is not a guarantee. Treat it as one input alongside your own judgement.
Do not click links in messages you were not expecting. Go to the site yourself — type the address, use a bookmark, or open the official app. If your bank genuinely needs you, it will still need you when you log in through the app thirty seconds later. If the message was fake, you have lost nothing.
This one habit defeats nearly every phishing attempt regardless of how convincing the message is, because it removes the attacker's only delivery mechanism. It costs a few seconds and it is worth more than any tool on this site, including this one.
Find the first single slash after https:// and read the two labels immediately before it. In example.paypal.com.verify.xyz/login the real site is verify.xyz, not PayPal. Anything further left is a subdomain and can say anything at all.
No. It means the connection is encrypted, nothing more. Certificates are free and automated, so most phishing sites display a padlock too. Judge the domain name, not the padlock.
On an up-to-date device, usually the harm comes from what you do next — typing a password, entering card details, or running a download. Clicking alone is rarely enough on its own, but keeping your browser and operating system updated is what keeps that true.
No, they are used legitimately all the time. They are a warning sign in a message you were not expecting, because they hide the destination. Many shortener services let you preview the target by adding a character to the address.
No. It analyses the structure of the address only, entirely in your browser, and never visits the site. For checking whether a page or file is known to be malicious you would need an online scanning service, which necessarily means sending the address to a third party.