Link Safety Checker
Paste any URL and instantly check if a link is safe: phishing signals, suspicious TLDs, homograph attacks, shorteners, redirects, HTTPS and hosting reputation.
How the checker works
Every URL is scored against a curated set of phishing and malware signals used by security teams: protocol strength, suspicious top-level domains, homograph and punycode attacks, embedded credentials, IP-address hosts, excessive subdomains, known URL shorteners, sensitive keywords in the path, and more. All checks run in your browser — nothing is uploaded.
For a definitive answer, click Run full scan to combine these heuristics with our server-side reputation, SSL, DNS and blacklist checks.
Signs a link is unsafe
- The URL uses
http://instead ofhttps://. - The domain contains non-ASCII characters that look like Latin letters (homograph attack).
- The URL includes a username or password (e.g.
https://user:pass@host). - The host is a raw IP address instead of a domain name.
- The domain uses a spam-heavy TLD such as
.zip,.mov,.topor.xyz. - The link is a shortener (bit.ly, tinyurl, t.co) hiding the real destination.
- The path contains urgent or sensitive keywords like verify, login, reset paired with a brand name.
Frequently asked questions
- We run 20+ heuristic checks locally in your browser (protocol, TLD, homograph/punycode, shorteners, credentials, IP hosts, suspicious keywords) and combine them with a full remote reputation and SSL scan for a verdict.
- Yes — the full scan traces the redirect chain and flags any hop that downgrades HTTPS, hides the destination, or lands on a low-reputation host.
- We match against OpenPhish feeds, look for brand-impersonation patterns (login pages on look-alike domains, punycode) and flag mismatched TLS certificates.
- Local heuristic checks never leave your browser. The optional deep scan is edge-cached and never tied to your identity.
- IP-address hosts, credentials in the URL (user:pass@), excessive subdomains, non-ASCII look-alike characters, hyphen-heavy brand names, obscure TLDs (.zip, .mov, .top, .xyz used for spam), and known URL shorteners.
- Not inherently unsafe, but shorteners hide the destination. Always expand a short URL before clicking one from an unknown sender.
- No. HTTPS only means the connection is encrypted, not that the site is trustworthy. Attackers use free TLS certificates too.
- Long-press the link to preview the full URL, then paste it into this checker instead of tapping it.
Not sure about a whole website? Run a full website audit instead.