Paste a suspicious link and see where it really goes, which tricks it uses, and what to do, before you click.
The link is analysed in your browser and never opened. Only the host name is sent, and only if you run the domain check.
Phishing works because a link can say one thing and go somewhere else. The text in an email, a text message or a social media post can show your bank's name while the address underneath points to a site registered last week. On a phone, where the full address is often hidden, the difference is almost impossible to see.
This checker takes the address apart the way a security analyst would. It finds the website you would really land on, then looks for the tricks phishing links depend on: lookalike spellings, brand names buried in a subdomain, characters from other alphabets that look identical to Latin letters, shortened links that hide the destination, and downloads disguised as documents. Every warning comes with a plain explanation.
The most common scam texts in Australia, the UK and the US impersonate delivery companies, toll roads, tax offices and banks. The message creates urgency, a missed parcel, an unpaid fine, a locked account, and the link leads to a copy of the real login page. Whatever you type goes straight to the criminal, who often logs in to your real account within minutes.
Lookalike domains are cheap and quick to register. Attackers swap a letter for a similar one, add a word like secure or verify, or register the brand under an unusual ending. Another common trick puts the real brand at the front of a long address, such as a bank name followed by a dot and an unrelated domain, relying on the reader stopping before the part that matters.
HTTPS and the padlock no longer signal a trustworthy site. Encryption certificates are free and automatic, and most phishing sites use them. The padlock only means the connection is private, including your connection to the criminal.
Links are also used to deliver malware. A file that appears to be an invoice or a voice message but ends in an executable extension will install software rather than open a document. Checking the link first catches this before anything downloads.
Copy the link rather than opening it, then look at the real domain, which is the part just before the first single slash. On a phone, press and hold the link to see or copy it. Paste it into this checker to find the real website and any lookalike tricks. If the domain is not exactly the company you expected, do not use it.
Usually nothing happens just by opening the page. The damage comes from what you do next: typing a password, a card number or a one time code, or downloading a file. If you only opened it, close the page. If you entered anything, change that password immediately, contact your bank if you gave card details, and turn on two factor authentication.
On an up to date phone or computer it is rare. Most attacks need you to download and open a file, grant a permission, or enter details. Keeping your browser and operating system updated closes the flaws that drive by attacks rely on.
The shortener is not dangerous, but it hides where you are going, which is why scammers like it. Be especially wary of shortened links in unexpected texts. Legitimate companies rarely send shortened links for logins or payments.
No. HTTPS means the connection is encrypted, not that the site is honest. Certificates are free and phishing sites routinely have them. Check the domain name, not the padlock.
If you entered a password, change it on that site and anywhere you reused it, starting with your email. If you entered card or bank details, call your bank on the number on your card. If you downloaded a file, do not open it, delete it and run a malware scan. Then report the message so others are warned.