Skip to content

Free tool · Runs in your browser · The link is never opened

Got a link that feels off? Check it before you click.

Paste a suspicious link and we'll pull it apart for the classic phishing tricks — lookalike domains, hidden redirects, character spoofing, and more. It is analyzed as plain text; the link is never opened or sent.

Safe to paste — nothing is clicked, fetched, or stored. Pure text analysis.

Learn the tells

Four tricks that catch people every day.

The name is right, the domain is wrong

paypal.com.secure-login.ru looks like PayPal, but the real domain is the part just before the first single slash — here, secure-login.ru.

Letters that aren't letters

Foreign characters (or "punycode", xn--) can make аpple.com look identical to apple.com while pointing somewhere else entirely.

Urgency baked into the address

Domains built from words like secure-, -verify, account-update, or unlock- are a classic scam tell.

The @ trick

In http://apple.com@evil.site, everything before the @ is ignored. The real destination is evil.site.

Straight answers

Is my link sent anywhere?

No. The entire analysis runs in your browser using only the text of the link — the link is never opened, fetched, or sent to us or anyone else. There is no signup and nothing is stored. It is completely safe to paste a suspicious link here; nothing happens except the text gets examined.

If it finds no red flags, is the link safe?

No — and this is the most important thing to understand. This checks the structure of the link for common tricks. It cannot see the actual website, its reputation, or a brand-new scam that uses a clean-looking address. A "no red flags" result means "none of the usual tells," not "safe." When money or a login is involved and you have any doubt, do not click — go to the site the way you normally do instead.

What should I do with a risky link?

Do not click it, and never enter a password or payment details. If it claims to be from a company you use, open a new tab and go to that company the way you always do (a bookmark or a search), or call them on a number you already have. Report the message as phishing in your email client, and if it targeted your work, tell your IT provider so they can warn the team.

Can a tool like this replace training?

It helps, but the durable protection is a team that recognizes these patterns instinctively and email filtering that stops most of them before they land. That combination — filtering plus recurring awareness training and simulations — is part of our managed security.

The best link checker is a trained team.

Most breaches start with one click. Email filtering that stops the message, plus recurring awareness training and simulations so your team spots the rest — that's the real defense, and it's part of our managed security.