Skip to main content

Link Safety Checker

Paste any URL and instantly check if a link is safe: phishing signals, suspicious TLDs, homograph attacks, shorteners, redirects, HTTPS and hosting reputation.

Runs locally in your browser · 20+ heuristics · free and unlimited

How the checker works

Every URL is scored against a curated set of phishing and malware signals used by security teams: protocol strength, suspicious top-level domains, homograph and punycode attacks, embedded credentials, IP-address hosts, excessive subdomains, known URL shorteners, sensitive keywords in the path, and more. All checks run in your browser — nothing is uploaded.

For a definitive answer, click Run full scan to combine these heuristics with our server-side reputation, SSL, DNS and blacklist checks.

Signs a link is unsafe

  • The URL uses http:// instead of https://.
  • The domain contains non-ASCII characters that look like Latin letters (homograph attack).
  • The URL includes a username or password (e.g. https://user:pass@host).
  • The host is a raw IP address instead of a domain name.
  • The domain uses a spam-heavy TLD such as .zip, .mov, .top or .xyz.
  • The link is a shortener (bit.ly, tinyurl, t.co) hiding the real destination.
  • The path contains urgent or sensitive keywords like verify, login, reset paired with a brand name.

Frequently asked questions

We run 20+ heuristic checks locally in your browser (protocol, TLD, homograph/punycode, shorteners, credentials, IP hosts, suspicious keywords) and combine them with a full remote reputation and SSL scan for a verdict.
Yes — the full scan traces the redirect chain and flags any hop that downgrades HTTPS, hides the destination, or lands on a low-reputation host.
We match against OpenPhish feeds, look for brand-impersonation patterns (login pages on look-alike domains, punycode) and flag mismatched TLS certificates.
Local heuristic checks never leave your browser. The optional deep scan is edge-cached and never tied to your identity.
IP-address hosts, credentials in the URL (user:pass@), excessive subdomains, non-ASCII look-alike characters, hyphen-heavy brand names, obscure TLDs (.zip, .mov, .top, .xyz used for spam), and known URL shorteners.
Not inherently unsafe, but shorteners hide the destination. Always expand a short URL before clicking one from an unknown sender.
No. HTTPS only means the connection is encrypted, not that the site is trustworthy. Attackers use free TLS certificates too.
Long-press the link to preview the full URL, then paste it into this checker instead of tapping it.

Not sure about a whole website? Run a full website audit instead.