Is This Link Safe? Phishing Link Checker

Paste a suspicious link and see where it really goes, which tricks it uses, and what to do, before you click.

The link is analysed in your browser and never opened. Only the host name is sent, and only if you run the domain check.

Phishing works because a link can say one thing and go somewhere else. The text in an email, a text message or a social media post can show your bank's name while the address underneath points to a site registered last week. On a phone, where the full address is often hidden, the difference is almost impossible to see.

This checker takes the address apart the way a security analyst would. It finds the website you would really land on, then looks for the tricks phishing links depend on: lookalike spellings, brand names buried in a subdomain, characters from other alphabets that look identical to Latin letters, shortened links that hide the destination, and downloads disguised as documents. Every warning comes with a plain explanation.

How it works

  1. Paste the link. Defanged links such as hxxps://example[.]com are converted back automatically.
  2. The address is parsed in your browser to find the scheme, the full host name, the path and any parameters. The link is never loaded, so nothing on the page can run.
  3. The real registrable domain is worked out, correctly handling country endings such as .com.au and .co.uk. This is the part that decides who actually owns the site.
  4. International characters are decoded from their punycode form so lookalike domains using Cyrillic or Greek letters are shown as they would appear on screen.
  5. About twenty checks run against the address, each weighted by how strongly it points to phishing, and combined into a risk score from 0 to 100.
  6. If you choose, the host name alone is sent to our server to confirm the domain is live in DNS. The server never visits the link.

Reading your results

  • No obvious warning signs: the structure of the address looks normal. A clean looking link can still lead to a scam, so this is not permission to enter a password.
  • Be careful: minor warning signs such as an unencrypted connection or a cheap domain ending. Often harmless on their own, so check who sent it.
  • Suspicious: several signs that commonly appear together in phishing. Do not sign in, pay, or download through this link.
  • Phishing or malware: the address uses deliberate deception, such as a brand lookalike, a brand name placed in front of a different domain, or a disguised executable. Do not open it.
  • Where this link actually goes names the real website. If it is not the company the message claimed to be from, that alone is enough to walk away.
  • Serious warning signs are the individual techniques that pushed the score up, each with an explanation of how the trick works.
  • The domain check confirms whether the site currently exists. A live domain means a page can load, not that it is safe. A dead domain often means a scam site already taken down.

How this fits into the real world

The most common scam texts in Australia, the UK and the US impersonate delivery companies, toll roads, tax offices and banks. The message creates urgency, a missed parcel, an unpaid fine, a locked account, and the link leads to a copy of the real login page. Whatever you type goes straight to the criminal, who often logs in to your real account within minutes.

Lookalike domains are cheap and quick to register. Attackers swap a letter for a similar one, add a word like secure or verify, or register the brand under an unusual ending. Another common trick puts the real brand at the front of a long address, such as a bank name followed by a dot and an unrelated domain, relying on the reader stopping before the part that matters.

HTTPS and the padlock no longer signal a trustworthy site. Encryption certificates are free and automatic, and most phishing sites use them. The padlock only means the connection is private, including your connection to the criminal.

Links are also used to deliver malware. A file that appears to be an invoice or a voice message but ends in an executable extension will install software rather than open a document. Checking the link first catches this before anything downloads.

Who this is for

  • Anyone who received an unexpected text, email or direct message with a link.
  • People checking a link a relative forwarded to ask whether it is real.
  • Small business staff handling invoices, delivery notices and payment requests.
  • Anyone who wants to learn what phishing links look like so they can spot them without a tool.

What this tool cannot tell you

  • This is a heuristic check of the address, not a live blocklist. A brand new phishing site with an ordinary looking address can score low.
  • It does not open the page, so it cannot see what the page shows, what it asks for, or whether it tries to download anything.
  • It cannot follow a shortened link to its destination, because doing so would mean visiting the link. Shortened links are flagged as hiding their destination instead.
  • A legitimate site can trigger warnings, for example a genuine company using a marketing redirect. Treat warnings as a reason to check independently, not as a verdict on the company.
  • The safest test is always the same: do not use the link at all. Go to the company's website or app yourself.

Frequently asked questions

How can I tell if a link is safe without clicking it?

Copy the link rather than opening it, then look at the real domain, which is the part just before the first single slash. On a phone, press and hold the link to see or copy it. Paste it into this checker to find the real website and any lookalike tricks. If the domain is not exactly the company you expected, do not use it.

What happens if I click on a phishing link?

Usually nothing happens just by opening the page. The damage comes from what you do next: typing a password, a card number or a one time code, or downloading a file. If you only opened it, close the page. If you entered anything, change that password immediately, contact your bank if you gave card details, and turn on two factor authentication.

Can I get a virus just by opening a link?

On an up to date phone or computer it is rare. Most attacks need you to download and open a file, grant a permission, or enter details. Keeping your browser and operating system updated closes the flaws that drive by attacks rely on.

Are shortened links like bit.ly safe?

The shortener is not dangerous, but it hides where you are going, which is why scammers like it. Be especially wary of shortened links in unexpected texts. Legitimate companies rarely send shortened links for logins or payments.

Does HTTPS mean a website is safe?

No. HTTPS means the connection is encrypted, not that the site is honest. Certificates are free and phishing sites routinely have them. Check the domain name, not the padlock.

What should I do if I clicked a suspicious link?

If you entered a password, change it on that site and anywhere you reused it, starting with your email. If you entered card or bank details, call your bank on the number on your card. If you downloaded a file, do not open it, delete it and run a malware scan. Then report the message so others are warned.

Related tools

Guides that go with this tool