Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

Phishing Link Checker

Learn exactly why a link is suspicious. The phishing checker breaks a URL down the way security analysts do — the real registrable domain, brand impersonation, typosquatting, punycode look-alikes, deceptive subdomains, @ and redirect tricks, lure words, and how recently the domain was registered.

Paste the link. The analyzer identifies the real domain (not the one it pretends to be), compares it with commonly impersonated brands for look-alike spellings, follows any redirects safely to the final destination, and checks the domain's age via RDAP. Each warning sign is explained so you can recognise the trick next time.

We never open the page in a browser: our server only follows redirects to see where the link leads, safely.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for Phishing Link Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use Phishing Link Checker

  1. 1Paste the suspicious link — don't open it.
  2. 2Click Analyze link.
  3. 3Check the real domain and each warning sign.
  4. 4Report phishing to the impersonated company and delete the message.

How to read a URL

The part that matters is the registrable domain: the last two labels before the first single slash (or three for domains like .co.uk). In https://login.paypal.com.verify-account.top/, the real site is verify-account.top — everything before it is decoration the attacker controls.

Other classic tricks: https://[email protected] (everything before @ is ignored), look-alike characters from other alphabets (punycode xn-- domains), and shortened links hiding the destination.

Staying safe

Type the address of important sites yourself or use a bookmark, use a password manager (it won't autofill on a fake domain), and enable two-factor authentication. For an overall verdict including Safe Browsing, use the URL Safety Checker.

Frequently Asked Questions

Is a link safe if no warning signs are found?

Not necessarily — some phishing sites use clean-looking domains. Be cautious with any unexpected message asking you to log in, pay or share codes.

How should I report phishing?

Forward phishing emails to the impersonated company (many have a phishing@ address) and to your national reporting service, and use your email client's Report phishing button.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Guides & Tutorials

Related Tools