Link Safety Checker
Paste any URL and instantly check if a link is safe: phishing signals, suspicious TLDs, homograph attacks, shorteners, redirects, HTTPS and hosting reputation.
How the checker works
Every URL is scored against a curated set of phishing and malware signals used by security teams: protocol strength, suspicious top-level domains, homograph and punycode attacks, embedded credentials, IP-address hosts, excessive subdomains, known URL shorteners, sensitive keywords in the path, and more. All checks run in your browser — nothing is uploaded.
For a definitive answer, click Run full scan to combine these heuristics with our server-side reputation, SSL, DNS and blacklist checks.
Signs a link is unsafe
- The URL uses
http://instead ofhttps://. - The domain contains non-ASCII characters that look like Latin letters (homograph attack).
- The URL includes a username or password (e.g.
https://user:pass@host). - The host is a raw IP address instead of a domain name.
- The domain uses a spam-heavy TLD such as
.zip,.mov,.topor.xyz. - The link is a shortener (bit.ly, tinyurl, t.co) hiding the real destination.
- The path contains urgent or sensitive keywords like verify, login, reset paired with a brand name.
Frequently asked questions
Related guides
More tools
Not sure about a whole website? Run a full website audit instead.