Phishing Link Checker

Someone sent you a link? Paste it here and find out if it's safe to click — a free scan for phishing, malware, and scam flags.

How to spot a phishing link before you click

Phishing links succeed by looking one glance away from legitimate. These are the six tricks behind most of them — if the link in front of you matches any of these patterns, scan it first.

The domain is almost right

paypa1.com

A digit for a letter, a doubled character, rn instead of m. Typosquatters count on you skimming — read the domain character by character.

The real domain hides at the end

paypal.com.secure-check.xyz

Only the domain just before the first slash identifies the owner. Here that's secure-check.xyz — everything in front is stage dressing.

The link is shortened

bit.ly/3xK9…

Shorteners hide the destination completely. Fine in a newsletter you trust; a red flag in an unexpected text about a package or a toll.

The message wants panic, not thought

“Your account will be closed in 24 hours”

Urgency is the engine of every phish. Deadlines, threats, and jackpot prizes all serve one purpose: making you click before you check.

The text and the URL disagree

“Visit chase.com” → hover shows another site

Link text is just text. Hover on desktop or press and hold on mobile to reveal the real destination before you commit a click.

A login page you didn't navigate to

Email → “Sign in to continue”

Credential harvesting needs you to type your password on their page. When an email leads to a login form, close it and sign in from your bookmark instead.

What the scan checks

The checker evaluates the link the way mailbox providers and security filters do — against reputation data, not appearances.

Phishing & malware blocklists

The URL and its domain are checked against major threat-intelligence databases that track live phishing campaigns and malware hosts.

Domain reputation signals

The domain behind the link is scored on its history — spam associations, abuse reports, and how mailbox providers and filters treat it.

The true destination

Shorteners and redirect chains are resolved so the verdict applies to the page you'd actually land on, not the wrapper you were shown.

A verdict you can act on

Instead of a wall of raw data, you get a clear read: flagged as dangerous, suspicious, or clean — before the link is ever opened.

Clicked a phishing link? Do this now

A click alone is rarely a catastrophe. Work through these four steps calmly, in order.

1

Stop and enter nothing

Close the page. Clicking is rarely the damage — typing your password or card number is. If you entered nothing, you're most likely fine.

2

Change any password you typed

Do it from a device you trust, starting with the affected account and anywhere that password is reused. Turn on two-factor authentication while you're there.

3

Scan the device

If you downloaded a file or the site tried to install something, run a full antivirus scan before you keep working.

4

Warn and watch

Report the message to your IT team or mail provider, and keep an eye on bank statements and login alerts over the following weeks.

Want the full walkthrough? What to do if you clicked on a phishing link covers each step in detail, and What is phishing? explains how these attacks work.

Checking your own links instead? If you're a sender auditing how spam filters see the URLs in your emails and pages, run a URL reputation check on your domain.

Check URL reputation →

Phishing link safety knowledge base