URL Safety Checker
Not sure about a link in an email, text or DM? Paste it here instead of clicking. The checker safely follows redirects to reveal the real destination, looks up how old the domain is, and checks for the warning signs of phishing and malware sites — without opening the page in your browser.
Paste the link and our server resolves its redirect chain (without rendering the page), finds the real domain, looks up the domain's registration date via RDAP, and scores it against dozens of risk signals: look-alike and typosquatted brand domains, raw IP addresses, @ tricks, punycode, abused TLDs, lure words and direct file downloads. When configured, Google Safe Browsing is checked too.
We never open the page in a browser: our server only follows redirects to see where the link leads, safely.
Instant Results
Live checks in seconds
Nothing Stored
No logs of what you check
No Sign-Up
Free, no credits or email
Suggest a Feature or Improvement for URL Safety Checker
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use URL Safety Checker
- 1Copy the suspicious link (long-press or right-click → Copy link).
- 2Paste it and click Check URL.
- 3Read the verdict, the real destination and the warning signs.
- 4If in doubt, don't click — go to the company's website directly.
What makes a link suspicious
Most phishing links use a domain registered days earlier, a brand name inside a different domain (paypal.com.secure-login.xyz), a look-alike spelling (paypa1.com), or a URL shortener to hide the destination. Legitimate companies almost never ask you to log in via a link in a text message.
No automated check is perfect: new phishing sites appear every minute, and some legitimate sites trip a heuristic. Treat a clean result as “no known red flags”, not a guarantee.
If you already clicked
Don't enter anything. If you entered a password, change it immediately on the real site and turn on two-factor authentication; if you entered card details, call your bank. For a structured breakdown of a URL's phishing tricks, use the Phishing Link Checker.
Frequently Asked Questions
Does checking the link alert the sender?
Our server requests the URL to follow redirects, which the site may log, but it comes from our server, not your device or IP address.
Does it scan for viruses?
It doesn't download or execute files. It flags links that point directly to executables and archives, and uses Google Safe Browsing when enabled.
What do you do with the domains and URLs I check?
Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.
Guides & Tutorials
Related Tools
Phishing Link Checker
Analyse a suspicious link for phishing tricks: look-alike domains, hidden destinations and new domains.
SSL Checker
Check a site's SSL/TLS certificate, chain, expiry, TLS versions, HTTPS redirect and HSTS.
Domain Security Checker
Scan a domain's email, DNS and HTTPS security: SPF, DMARC, DNSSEC, CAA, SSL, HSTS and headers.