Paste any suspicious link to check it against live blocklists and 7 structural signals —
domain age, homograph characters, redirect chains, brand spoofing, and more. The link is
fetched server-side and analyzed — your browser never visits the destination.
The page is fetched by our server in an isolated environment — your browser never touches the destination.
Paste a link above to check it
Results appear here once the analysis finishes
--risk / 100
Signal results
Signal
Finding
Status
Blocklist match
Waiting for a link…
Pending
Domain age
Waiting for a link…
Pending
Brand spoofing
Waiting for a link…
Pending
Homograph characters
Waiting for a link…
Pending
Redirect chain
Waiting for a link…
Pending
TLS certificate
Waiting for a link…
Pending
Login form detection
Waiting for a link…
Pending
Fetching and analyzing the link… checking blocklists, domain age, redirects…
Redirect chain trace
What this test checks — 7 signals
Blocklist match
Checked in real time against Google Safe Browsing, PhishTank, and URLhaus — three independently maintained threat-intelligence feeds, not a single cached list. A match on any one of them is treated as confirmed, not just suspected.
Domain age
Looked up via public WHOIS/RDAP records. A domain registered days or weeks ago that imitates an established brand is one of the single strongest phishing signals there is — legitimate companies essentially never rotate their login domain.
Brand spoofing
Checks whether a well-known brand name appears somewhere in the domain without actually being the domain itself — most commonly as a subdomain (paypal.com.example-verify.info) or stuffed directly into an unrelated domain name.
Homograph characters
Detects look-alike characters borrowed from other alphabets — a Cyrillic "а" standing in for a Latin "a," for example — and shows the domain's real punycode form underneath the disguise.
Redirect chain
Every hop is followed server-side — shorteners, tracking links, meta-refreshes — so you see the true final destination before you ever click the original link yourself.
TLS certificate
Notes whether the certificate is valid, and how recently it was issued. A certificate is never treated as a safety signal on its own — free automated certificate authorities issue valid HTTPS certificates to phishing domains just as readily as to real ones — but a certificate issued days ago is corroborating evidence alongside domain age.
Login form detection
Flags whether the destination page contains a password field. A password field sitting on a domain that is also newly registered and imitating a brand name is a combination almost never seen on legitimate sites.
How the verdict is scored
0–29 · Low risk
No blocklist match and no meaningful structural red flags. Shown as "not currently known to be malicious" — this is a statement about what has been checked, not a guarantee.
30–64 · Suspicious
Structural red flags without a confirmed blocklist entry — commonly a very new domain, an unusual redirect chain, or brand-like naming. Worth extra caution before entering any information.
65–100 · High risk
A confirmed blocklist match, or several strong signals combined. Do not enter credentials, payment details, or personal information on this page.
A "low risk" result is never displayed as "verified safe" anywhere on this page. Automated
detection has real, structural limits — the FAQ below covers exactly what those are.
Frequently asked questions
No, and treat any tool that claims otherwise with suspicion. Blocklist-based detection only knows about a URL after it has already been reported or crawled — a phishing page created minutes ago targeting one specific person won't be on any list yet. A "low risk" result here means the link isn't currently known to be malicious and shows no structural red flags, not that it has been independently verified safe. The structural signals — domain age, homograph characters, redirect chains — exist specifically to catch some of what blocklists miss, but no automated check replaces learning to read the domain yourself.
No. The link is fetched by our server, in an isolated environment, to follow redirects and inspect the destination page. Your browser and your IP address never make a request to the URL you paste in — this matters for two reasons: it means the site you're checking can't see or fingerprint you, and it means opening a genuinely malicious link doesn't expose your own device to whatever that page might try to do to a visiting browser.
The most common reason is timing — a phishing campaign that launched in the last few hours may not have been reported to any blocklist yet, and a freshly registered domain won't always trip every structural signal (some attackers deliberately let a domain "age" for a few weeks specifically to defeat domain-age checks like this one). This is a real limitation of automated detection generally, not something specific to this tool, which is why the FAQ above leads with "can this guarantee safety" rather than burying that answer.
No. The URL is used only to run the live checks described above and is not retained afterward, logged against your IP, or shared with any third party beyond the blocklist providers the check itself queries (Google Safe Browsing, PhishTank, and URLhaus), none of which receive any information about you — only the URL being checked.
Don't visit it, and don't enter anything into it if you already have. If it arrived by email, report it through your email provider's built-in phishing-report option or forward it to the Anti-Phishing Working Group. If it impersonates your bank or another service you actually use, it's also worth reporting directly to that company — most have a dedicated abuse or phishing-report address.
Yes — that's the entire point of this tool. Paste the link as text into the field above; nothing is opened or clicked, by you or by us, until you choose to visit it yourself after reading the results.
Community
Get the next leak test before it's news
Tool releases and research notes, sent when there's something worth reading. Nothing else.