Free tool · Runs in your browser · The link is never opened
Got a link that feels off? Check it before you click.
Paste a suspicious link and we'll pull it apart for the classic phishing tricks — lookalike domains, hidden redirects, character spoofing, and more. It is analyzed as plain text; the link is never opened or sent.
Learn the tells
Four tricks that catch people every day.
The name is right, the domain is wrong
paypal.com.secure-login.ru looks like PayPal, but the real domain is the part just before the first single slash — here, secure-login.ru.
Letters that aren't letters
Foreign characters (or "punycode", xn--) can make аpple.com look identical to apple.com while pointing somewhere else entirely.
Urgency baked into the address
Domains built from words like secure-, -verify, account-update, or unlock- are a classic scam tell.
The @ trick
In http://apple.com@evil.site, everything before the @ is ignored. The real destination is evil.site.
Straight answers
Is my link sent anywhere?
No. The entire analysis runs in your browser using only the text of the link — the link is never opened, fetched, or sent to us or anyone else. There is no signup and nothing is stored. It is completely safe to paste a suspicious link here; nothing happens except the text gets examined.
If it finds no red flags, is the link safe?
No — and this is the most important thing to understand. This checks the structure of the link for common tricks. It cannot see the actual website, its reputation, or a brand-new scam that uses a clean-looking address. A "no red flags" result means "none of the usual tells," not "safe." When money or a login is involved and you have any doubt, do not click — go to the site the way you normally do instead.
What should I do with a risky link?
Do not click it, and never enter a password or payment details. If it claims to be from a company you use, open a new tab and go to that company the way you always do (a bookmark or a search), or call them on a number you already have. Report the message as phishing in your email client, and if it targeted your work, tell your IT provider so they can warn the team.
Can a tool like this replace training?
It helps, but the durable protection is a team that recognizes these patterns instinctively and email filtering that stops most of them before they land. That combination — filtering plus recurring awareness training and simulations — is part of our managed security.
The best link checker is a trained team.
Most breaches start with one click. Email filtering that stops the message, plus recurring awareness training and simulations so your team spots the rest — that's the real defense, and it's part of our managed security.