Instant analysis runs locally as you type. “Deep scan” adds live SSL, DNS, WHOIS, redirect & blacklist intelligence.
Paste a link above to get an instant safety verdict, phishing & typosquat analysis and a trust score.
Loading…
Instant analysis runs locally as you type. “Deep scan” adds live SSL, DNS, WHOIS, redirect & blacklist intelligence.
Paste a link above to get an instant safety verdict, phishing & typosquat analysis and a trust score.
This free URL safety checker analyses any link for phishing, typosquatting, homograph (IDN) spoofing, malware indicators, dangerous schemes, URL shorteners and open redirects — instantly and in your browser — then gives a 0–100 trust score and a Safe/Low/Medium/High/Critical verdict. An optional keyless deep scan adds live intelligence: it follows the full redirect chain to the final destination, inspects the SSL/TLS certificate, grades HTTP security headers, resolves DNS (SPF/DMARC/DNSSEC), looks up the domain’s age and registrar via RDAP, identifies the hosting provider and country, and checks public DNS blacklists. Only the URL you submit is analysed; no browsing activity is tracked.
Check any link for phishing, typosquatting, homograph spoofing, malware indicators, redirects and reputation — instantly in your browser — then run an optional keyless deep scan for live SSL, DNS, WHOIS, security-header and blacklist intelligence. Only the URL you submit is ever analysed.
Every URL gets a 0–100 trust score, an A+–F grade and a Safe/Low/Medium/High/Critical verdict, computed from dozens of weighted structural and reputational signals — not a random number.
Flags credential-harvesting patterns: brand names placed in subdomains or paths, urgency/login keywords, fake-login structures, IP-hosted login pages and trust words stacked on throwaway TLDs, with a phishing confidence score.
Compares the domain against 60+ high-value brands using edit distance, keyboard-proximity, leetspeak (amaz0n) and substring techniques to catch look-alike domains like googIe.com or paypa1.com.
Decodes punycode (xn--) labels to Unicode, detects mixed scripts and Cyrillic/Greek look-alike characters, and reveals domains that imitate a trusted brand with confusable glyphs.
Follows 301/302 redirects, meta-refresh hops and URL-shortener expansions to the final destination, visualising every hop, detecting loops and cross-domain jumps — all SSRF-guarded.
Performs a live TLS handshake to read the certificate issuer, validity dates, days remaining, protocol version (TLS 1.2/1.3), cipher and SAN list, and flags expired or self-signed certificates.
Resolves A/AAAA/MX/NS/TXT records, SPF/DMARC/DNSSEC, looks up domain age, registrar and expiry via RDAP, and identifies the hosting provider, ASN, country and reputation of the server.
Checks public DNS blacklists, grades six HTTP security headers (CSP, HSTS, X-Frame-Options…), scans hundreds of URLs in bulk, and exposes a documented decode API with 15-language code samples.
Drop any link, domain, shortened URL, IP-based URL or a URL extracted from a QR code into the input box. The tool auto-detects the format, validates the structure (protocol, punycode, international domains) and normalises it for analysis. You can also paste many URLs for a bulk scan.
A trust score (0–100), risk grade and verdict — Safe, Low, Medium, High or Critical — appear immediately from a heuristic engine that runs entirely in your browser. It checks the URL structure, brand typosquatting, homograph/IDN spoofing, phishing keywords, dangerous schemes, shorteners, suspicious TLDs and open-redirect parameters.
Optionally fetch real network intelligence: follow the full redirect chain to the final destination, inspect the SSL/TLS certificate, grade the HTTP security headers, look up the domain’s WHOIS age and registrar via RDAP, resolve DNS (A/MX/NS/TXT/SPF/DMARC/DNSSEC), identify the hosting provider and country, and check public DNS blacklists.
Review each risk factor and recommendation, expand the phishing and reputation breakdowns, then copy the result or export a professional report as TXT, CSV, JSON or PDF. Recent checks and favourites are saved privately in your browser, and a developer API lets you automate the same analysis.
URL safety is the practice of determining whether a web address is trustworthy before you visit it or act on it. Every day, attackers distribute malicious links through email, text messages, social media, search ads, and QR codes, betting that you will click without checking where the link actually leads. A single click can land you on a convincing fake login page that steals your password, a checkout clone that captures your card, or a page that quietly triggers a malicious download. Because a URL is just text, the human eye is easily fooled — which is exactly why a tool that inspects the address character by character is so valuable.
A safe-looking link can hide real danger in several ways. The visible domain might be a near-perfect misspelling of a brand you trust, a look-alike built from Cyrillic or Greek characters that render identically to Latin letters, or a legitimate brand name buried in a subdomain while the real registered domain belongs to an attacker. Shortened links hide their destination entirely, and redirect chains can bounce you through a trusted domain into a hostile one. This URL Safety Checker is built to surface all of these tricks instantly, so the decision to click is an informed one.
Crucially, checking a URL is something you can do without any risk to yourself. Analysing the address — its structure, its certificate, its DNS records, its reputation — never requires you to actually open the page in your own browser, where a malicious script could run. This tool does the structural analysis entirely on your device and performs the optional live network checks server-side, so you get the intelligence of visiting the site without the exposure of doing so. Treat any unexpected link the way you would an unfamiliar door: inspect it before you walk through.
Phishing is a social-engineering attack that tricks you into handing over sensitive information — usually a password, a one-time code, or payment details — by pretending to be a service you trust. The attacker sets up a page that looks identical to the real login screen of a bank, email provider, or shopping site, then drives victims to it with an urgent message: your account is suspended, a payment failed, a package is held, you must verify now. Under pressure, people skip the one check that would save them: looking carefully at the address bar.
The URL is almost always where phishing reveals itself. Because an attacker cannot register the real brand’s domain, they must use something close: a misspelling (paypa1.com), an extra word (paypal-secure-login.com), the brand pushed into a subdomain (paypal.com.account-verify.tk), a look-alike Unicode character, or a raw IP address. They often add login-related keywords to the path and host the page on a cheap, recently registered domain with a free or suspicious TLD. Each of these is a measurable signal, and this tool scores all of them: typosquatting distance, homograph glyphs, brand-in-subdomain placement, urgency keywords, domain age, TLD risk and more.
Modern phishing also leans on legitimacy cues. Many fake pages now use HTTPS, so the padlock alone proves nothing — it confirms the connection is encrypted, not that the site is honest. Attackers buy real certificates for their look-alike domains in seconds. That is why a thorough check looks past the padlock to who the certificate was issued to, how old the domain is, whether the domain is on any blacklist, and whether the registered domain genuinely belongs to the brand. The combination of those signals is far harder to fake than a green padlock.
Typosquatting — also called URL hijacking — is the registration of domain names that are deliberate misspellings or variations of popular sites, in the hope of catching people who mistype an address or skim past a small difference. Classic examples include doubling a letter (gooogle.com), dropping one (microsft.com), swapping a visually similar character (paypa1.com, using the digit 1 for the letter l), adding a hyphenated word (amazon-support.com), or changing the TLD (yourbank.co instead of .com). The squatted domain might host a phishing page, serve malware, run ads, or simply be parked waiting to be sold.
What makes typosquatting effective is that the differences are small and we read domains by shape rather than letter by letter. A domain that is one character off from a brand you use daily can pass a quick glance, especially on a small phone screen or inside an email where you cannot hover to preview. Keyboard-proximity typos (typing “gmaul” because U sits next to I) and leetspeak substitutions (g00gle, micr0soft) are common variants. This tool measures the edit distance between the domain you entered and dozens of major brands, applies keyboard-proximity and leetspeak normalisation, and flags any close match with a similarity score.
Defending against typosquatting comes down to verifying the registered domain, not the surrounding text. Bookmark the sites you log into and use the bookmark rather than links. When you do follow a link, read the domain from right to left: the real owner is the part immediately before the TLD (the “registrable domain”), so in login.secure.paypal.com.evil.tk the owner is evil.tk, not paypal. This checker highlights exactly that registrable domain and tells you when it merely resembles, rather than matches, a brand you might be expecting.
A homograph attack exploits the fact that many characters from different alphabets look identical. Internationalised Domain Names (IDNs) allow non-Latin scripts in domains, so an attacker can register a name that uses, for example, the Cyrillic “а” (U+0430) in place of the Latin “a” (U+0061). The two are visually indistinguishable, so аpple.com can look exactly like apple.com while pointing somewhere entirely different. Browsers store these names in “punycode”, an ASCII encoding that begins with xn--, which is the form this tool decodes and inspects.
Detecting homograph attacks requires looking beneath the rendered text. This checker decodes any xn-- label back to its Unicode characters, identifies which scripts are present, and flags two danger signs: characters that are known confusables of Latin letters, and domains that mix scripts (Latin combined with Cyrillic or Greek) where a single-script name would be expected. When a decoded IDN spells out a brand name using look-alike glyphs, it is treated as a high-confidence spoof, because there is almost no legitimate reason for a brand’s domain to be built from mixed-script confusables.
Most modern browsers now defend against the worst cases by displaying the punycode form (xn--…) instead of the look-alike when a domain mixes scripts suspiciously — but this protection is inconsistent across browsers, and plenty of mixed-script tricks still render normally. Relying on the browser alone is risky. Running a link through a checker that explicitly decodes and analyses the IDN gives you a definitive answer about whether the characters are what they appear to be, rather than trusting that your browser happened to catch this particular combination.
URL shorteners such as Bitly, TinyURL and t.co replace a long address with a short one that redirects to the original. They are convenient and legitimate, but they also hide the destination: when you see bit.ly/3xYz, you have no idea whether it leads to a news article or a credential-harvesting page until you follow it. Attackers exploit this opacity to slip malicious links past people and past filters that would have flagged the real domain. A shortened link should always be expanded and inspected before it is trusted, especially when it arrives unexpectedly.
Redirects compound the problem. A single link can pass through a chain of hops — HTTP 301/302 redirects, meta-refresh tags, or JavaScript redirects — before landing on its final page, and each hop can change domains. Attackers use “open redirects” on trusted sites (a parameter like ?redirect=… or ?url= that bounces you onward) to make a malicious destination appear to come from a reputable domain. The deep scan in this tool follows the entire redirect chain server-side, shows every hop and its status code, detects loops and cross-domain jumps, and reports the true final URL so nothing is hidden.
Because following untrusted redirects in your own browser is itself risky, this checker does it for you in a sandboxed, SSRF-guarded way: it refuses to follow links to private, loopback or cloud-metadata addresses, caps the number of hops, and times out slow responses. You get to see exactly where a short link or redirect chain ends up — and what the destination’s certificate, headers and reputation look like — without ever exposing your own device or network to the journey.
An SSL/TLS certificate encrypts the connection between your browser and a website and proves the site controls its domain. The deep scan reads the certificate directly from a live TLS handshake: who it was issued to and by which authority, the validity dates and days remaining, the protocol version (you want TLS 1.2 or 1.3, never the deprecated SSL 2.0/3.0), and whether it is expired or self-signed. But remember the key limitation — a valid certificate confirms encryption and domain control, not honesty. A phishing site can hold a perfectly valid certificate for its look-alike domain, so the certificate is one signal among many, not a verdict on its own.
DNS and domain registration data add powerful context. Resolving a domain’s records reveals its mail servers, name servers, and whether it publishes SPF, DKIM and DMARC policies (which legitimate organisations almost always do) and whether it is DNSSEC-signed. Registration data from RDAP shows the registrar, the creation date and the expiry date — and domain age is one of the strongest single predictors of risk. The overwhelming majority of phishing and scam domains are days or weeks old, because they are registered in bulk, used briefly, and abandoned. A domain registered yesterday that claims to be a major bank is a glaring red flag.
Reputation pulls these threads together. This tool identifies the hosting provider, ASN and country of the server, checks the resolved IP against public DNS blacklists used to track spam and abuse, and combines that with the structural heuristics into a single trust score. No single source is infallible — blacklists lag behind brand-new threats, and a clean record does not guarantee safety — which is why the verdict is presented with its underlying factors visible. You can see precisely why a URL scored the way it did and weigh the evidence yourself, rather than trusting an opaque “safe/unsafe” stamp.
The most effective habit is to navigate to important sites yourself rather than following links. For anything involving money or credentials — your bank, email, or a shopping account — type the address from memory or use a saved bookmark instead of clicking a link in a message. This single change defeats the vast majority of phishing, because the attack depends on you using their link rather than the real one. When you must use a link, hover to preview it on desktop, or long-press on mobile, and read the registrable domain carefully before tapping.
Treat urgency as a warning sign, not a reason to act. Phishing messages manufacture pressure — your account will be closed, a payment failed, a prize expires — precisely to stop you from checking. Legitimate organisations do not ask you to “verify” your password through an emailed link, and they will still be reachable through their normal website if you go there directly. Be especially wary of links that arrive unexpectedly, of QR codes in public places (which are trivial to swap with a sticker), and of any page that asks for a password or one-time code after you arrived via a link.
Layer your defences. Enable multi-factor authentication everywhere so a stolen password alone is not enough; use a password manager, which will refuse to autofill credentials on a look-alike domain because it matches on the exact domain, not on appearance; keep your browser and devices updated so known exploits are patched; and run suspicious links through a checker like this one before acting. No single measure is perfect, but together they make you a very hard target. When in doubt, do not click — verify the source through a channel you already trust.
This tool is privacy-first by design. The instant heuristic analysis — trust score, phishing, typosquatting, homograph and structural risk factors — runs entirely in your browser using local JavaScript. Nothing about that analysis is sent anywhere; you can run it with your network disconnected once the page has loaded. Your browsing activity is never tracked, and the tool has no idea what other pages you visit. The only data involved is the specific URL you choose to paste in.
The optional deep scan does make network requests, but only to analyse the single URL you submitted: it resolves that domain’s DNS, performs a TLS handshake with that host, fetches its headers, looks up its public registration record, and checks its IP against blacklists. These are the same lookups any security analyst would run, and they reveal information about the target site, not about you. We do not log the URLs you check, build a profile, or store your history on a server — your recent checks and favourites live only in your browser’s local storage, which you can clear or disable at any time, and a private mode lets you scan without recording anything.
For automation, the developer API follows the same principle: it is stateless and analyses only the URL in the request, returning the report without persisting it. Use the in-browser tool for ad-hoc checks where privacy matters most, and the API where you need to screen links programmatically on your own infrastructure. Either way, there are no accounts to create for basic use and no limit on how many links you check.
How this checker fits alongside the major URL-reputation and safe-browsing services. They are complementary — blocklists are authoritative but lag new threats, while heuristics catch them the instant they appear.
| Service | Type | What it covers |
|---|---|---|
| Google Safe Browsing | Blocklist / API | Known phishing & malware URLs, used by Chrome/Firefox/Safari |
| Microsoft Defender SmartScreen | Reputation | Phishing, malware & untrusted downloads in Edge/Windows |
| VirusTotal | Aggregator | 70+ AV/URL scanners aggregated into one verdict |
| PhishTank / OpenPhish | Phishing feed | Community & automated phishing URL feeds |
| Cisco Talos / URLVoid | Reputation | Domain & IP reputation across many blocklists |
| Spamhaus / DNSBLs | Blacklist | IPs & domains linked to spam, botnets and abuse |
| This tool | Heuristic + live | Structural phishing/typosquat/homograph heuristics + live SSL/DNS/WHOIS/redirect/DNSBL intelligence, client-side first |
| URL | Domain | |
|---|---|---|
| What it is | The full address of a resource | The registered name part of the address |
| Example | https://shop.example.com/cart?id=9 | example.com |
| Includes | Scheme, host, path, query, fragment | Second-level domain + TLD only |
| Reputation | A page can be malicious on a safe domain | Reputation applies to the whole registered name |
| Who controls it | The site owner / app | The registrant via a registrar |
| HTTP | HTTPS | |
|---|---|---|
| Encryption | None — sent in clear text | Encrypted with TLS |
| Port | 80 | 443 |
| Tamper protection | No — can be modified in transit | Yes — integrity protected |
| Padlock in browser | No (marked “Not secure”) | Yes |
| Safe for passwords? | Never | Encryption yes, but HTTPS ≠ trustworthy site |
| SSL | TLS | |
|---|---|---|
| Status | Deprecated (SSL 2.0/3.0 broken) | Current standard (TLS 1.2 / 1.3) |
| Released | 1995–1996 | 1999 → 2018 (1.3) |
| Security | Vulnerable (POODLE, etc.) | Strong, modern ciphers |
| Common usage | “SSL certificate” is a legacy name | What actually runs today |
| Recommendation | Disable entirely | Require TLS 1.2+ |
| Phishing | Malware | |
|---|---|---|
| Goal | Trick you into revealing credentials/data | Run malicious code on your device |
| Delivery | Fake pages, emails, QR codes | Drive-by downloads, infected files |
| You are the target of | Deception / social engineering | A software exploit or download |
| Tell-tale URL | Look-alike domain, login keywords | Direct .exe/.apk/.zip download |
| Defence | Verify the domain before logging in | Don’t run unexpected downloads |
| Typosquatting | Homograph attack | |
|---|---|---|
| Technique | Misspelling with ASCII letters | Look-alike Unicode characters |
| Example | gooogle.com, paypa1.com | pаypal.com (Cyrillic а) |
| Visible to eye? | Often, if you look carefully | Usually not — glyphs look identical |
| Relies on | Typos & misreading | Internationalised domain names (IDN) |
| Detection | Edit distance / keyboard proximity | Punycode decode + mixed-script check |
| Standard DNS | DNSSEC | |
|---|---|---|
| Integrity | No cryptographic signing | Records signed and verifiable |
| Spoofing risk | Vulnerable to cache poisoning | Protects against forged answers |
| Adoption | Universal | Partial — many domains still unsigned |
| What it proves | Where to connect | That the answer is authentic |
| Tool shows | A/MX/NS/TXT records | Whether the domain is DNSSEC-signed |
Paste a suspicious link from an email, text, DM or QR code to see where it really goes and whether it imitates a known brand — before you open it on a device where it would auto-load.
Confirm a banking, wallet or checkout link is the brand’s genuine domain and not a typosquat or homograph look-alike, and that it’s served over a valid TLS certificate, before entering credentials or card details.
Reveal the final destination behind a bit.ly, t.co or tinyurl link, including every redirect hop, so a hidden malicious endpoint can’t surprise you.
Assess a new supplier’s site: domain age and registrar, SSL posture, security headers, hosting country and blacklist status — a quick due-diligence snapshot.
Scan a QR code with the QR Scanner, then run the extracted URL here to screen for “quishing” — QR phishing on parking meters, menus and posters that hides a malicious destination.
Upload or paste hundreds of links from a CSV, a spam batch or a marketing export and triage them by trust score and phishing risk in one table, then export the results.
Use the live verdicts and the education centre to show staff, students or family exactly what phishing, typosquatting and homograph attacks look like and how to spot them.
Call the documented API from a back-end, security pipeline or chatbot to score user-submitted links, moderate content or pre-flight outbound links at scale.