Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Suspicious Link Checker

See where a link really goes, and the tricks it uses, without opening it.

Security Works offline Uses live data Free, no sign-up

The link is only read, never opened or fetched. Defanged links (hxxps://evil[.]example) work too.

Examples:

Next steps

About the Suspicious Link Checker

Phishing links are built to look like somewhere else. This checker takes a link apart the way your browser would, without opening it, and shows where it really goes: the registered domain at the end of the name, worked out with the Public Suffix List. Then it lists the tricks it finds — text before an @ that is not the destination, look-alike letters from other alphabets (Punycode and Unicode confusables), a familiar brand placed in front of a stranger’s domain (paypal.com.example.net), disguised or bare IP addresses, link shorteners, free hosting where anyone can make a site, data: and javascript: links, programs disguised as documents, and heavy %-encoding.

Paste a single link or a whole SMS or email: the links in it are found for you, including defanged ones such as hxxps://evil[.]example and names written without https:// (kyc-update.example), as scam messages often do. If you want, it can also ask the domain’s registry when the domain was registered — very new domains are a common sign of phishing. Nothing is sent unless you press that button.

How to use it

  1. Copy the link without opening it — on a phone, press and hold the link and choose Copy link; in an email, right-click it and copy the link address.
  2. Paste it into the box, or paste the whole message and choose one of the links found in it.
  3. Read the verdict and Where it really goes: the highlighted part is the domain the link opens.
  4. Go through the warning signs. Press Look up domain age to see when the domain was registered.
  5. Copy the report, or the defanged link, to warn others or report it without making it clickable.

Examples

The user-name trick
Input
https://[email protected]/secure
Result
High risk — opens login-check.example

Everything before the @ is only a user name for the site, so “www.paypal.com” is decoration.

A brand in front of another domain
Input
https://www.hdfcbank.com.kyc-update.example/login
Result
High risk — opens kyc-update.example

A domain is read from the end. The owner of kyc-update.example can put anything in front of it.

Look-alike letters
Input
https://аррӏе.com/
Result
High risk — Cyrillic letters that look like “apple” (xn--80ak6aa92e.com)

Every letter is Cyrillic; the ASCII (Punycode) form shows that it is not apple.com.

Common uses

  • Checking a link in an SMS, WhatsApp message or email about a parcel, a bank KYC update, an electricity bill or a prize.
  • Teaching family members, students or staff how to read where a link really goes.
  • Triaging links reported to an IT or security team, and sharing them defanged.
  • Checking your own campaign or redirect links before you send them.

How to read where a link goes

Look at the part between :// and the next /. If it contains an @, only what comes after the @ counts. Read that name from the right: the ending (.com, .co.in, .org) and the label just before it make up the domain someone registered — the highlighted part in the result. Everything further left (www., secure., paypal.com.) is chosen freely by that domain’s owner.

Endings with more than one part, such as .co.uk or .gov.in, and services where anyone can get a subdomain, such as github.io or pages.dev, come from the Public Suffix List, which browsers use for the same purpose. On such services the site belongs to whoever set it up, not to the company that runs the service.

What the checker looks for

  • @ tricks: by RFC 3986, text before an @ is user information, not the destination.
  • Look-alike names: letters from different alphabets mixed in one name, names written entirely in letters that look Latin, and spellings that only resemble a brand (paypa1, rnicrosoft), using Unicode’s confusables data (UTS #39). Internationalised names are shown in both forms, Unicode and Punycode (RFC 3492).
  • Brand imitation: a short list of often-imitated brands — banks, payment apps, couriers, tax and Aadhaar services, big platforms — in the domain (also when it is run together with words such as login, verify or kyc, as in hdfcbankkyc), one letter away from it, in front of another domain, or as the name of a site on a service where anyone can choose the name (paypal.web.app).
  • Addresses instead of names: bare IP addresses, and IP addresses written as one big number, hex or octal so they do not look like one.
  • Hidden destinations: link shorteners, and links that carry another link or your email address in their parameters.
  • Not a web page: javascript:, data:, file: and ms-msdt: links, and links that open apps.
  • Files: programs and disk images (.exe, .apk, .iso …), and double endings such as invoice.pdf.exe.
  • Obfuscation: invisible and right-to-left characters, full-width letters, letters written as %-codes, double encoding, unusual ports and http:// without encryption.

Domain age (RDAP)

Phishing sites often use domains registered days before an attack. Look up domain age asks IANA’s RDAP directory (RFC 9224) which registry runs the domain’s ending, then asks that registry (RFC 9082) for the registration date, registrar and status. Your browser sends these two requests itself, without cookies, and only with the domain name. Some registries do not answer web pages; the result then points you to the WHOIS Lookup, which can ask them through a server.

The lookup is not offered for sites on services such as github.io or pages.dev — the registry knows only when the service registered its own domain, which says nothing about a site someone set up there — nor for reserved endings such as .example, .local and .internal, which have no registry.

What it cannot tell you

The checker reads the link, not the page behind it. A link with no warning signs can still lead to a scam — for example a real domain that was hacked, or a form on a big platform that anyone can create. It does not follow redirects, so it cannot see where a shortened link leads, and it does not consult blocklists. When a message pushes you to act fast, do not use its link at all: open the bank’s or company’s app, or type its address yourself.

Limitations

  • Brand checks cover a short list of well-known names and domains. A domain that is not on the list is not called fake — and one that looks like no brand can still be a scam.
  • Shortened links are not expanded: the destination is only known to the shortening service.
  • Domain age needs the registry’s RDAP service and depends on what it publishes; some country registries have none or do not answer browsers.
  • Look-alike detection covers characters that Unicode lists as confusable with Latin letters and digits; images, fonts and spacing can create look-alikes that no text check can see.

Privacy

The link is analysed in your browser and is never opened or fetched. Only if you press Look up domain age is the domain name (not the link) sent from your browser to IANA’s RDAP directory and to that domain’s registry.

Frequently asked questions

Is it safe to paste a suspicious link here?

Yes. The link is only read as text in your browser: it is never opened, fetched or sent anywhere, so the scammer’s site never learns about it. Only the optional domain-age lookup sends something — the bare domain name, to the registry.

Can it tell me whether a website is safe?

Not with certainty. It shows the tricks that are visible in the link itself, which catches most phishing links, but it cannot look inside the page. “No warning signs found” means the link looks ordinary, not that the site is trustworthy.

What is a look-alike (homograph) domain?

A name that uses letters from another alphabet that look identical to Latin ones, such as Cyrillic “а” and “р” in “аррӏе.com”. Computers see a completely different name (xn--80ak6aa92e.com); people see apple.com. The checker shows both forms and names the alphabets.

Why is a shortened link a warning sign?

Because nobody can see where it goes until it is opened, and anyone can create one that points anywhere. Companies you deal with rarely need them in account messages: ask the sender for the full link, or go to the company’s site or app yourself.

What does “defanged” mean?

A link written so it cannot be clicked by accident, such as hxxps://evil[.]example. Security teams share bad links this way. The checker reads defanged links, and Copy defanged link gives you one to share.

I already opened a phishing link. What should I do?

If you entered nothing, close the page. If you typed a password, change it at once on the real site and wherever you reuse it, and turn on two-factor sign-in. If you shared card, bank or UPI details or an OTP, call your bank immediately; in India, report financial cyber fraud on the helpline 1930 or at cybercrime.gov.in.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.