Free URL security check

Phishing Link Checker

Paste one suspicious URL. The checker reviews known threat listings, lookalike-domain patterns, public-IP reputation, known domain verdicts, and transport security without opening the destination in your browser.

Check a suspicious link

Do not paste passwords, access tokens, or other secrets that appear inside a URL. Website checks are limited to five per day.

What this phishing URL checker checks

Phishing pages impersonate a trusted service to obtain passwords, payment details, recovery codes, identity documents, or crypto-wallet secrets. This tool evaluates the submitted URL and its infrastructure signals; it does not claim to understand the truth of every message or to replace your browser's built-in protection.

Google Web Risk

Checks the submitted URL against current lists of recognized social-engineering, malware, and unwanted-software resources.

Typosquatting

Looks for domains designed to resemble popular sites through misspellings or impersonation patterns.

Hosting reputation

Resolves the site's public IP when possible and checks whether it has a significant abuse-reputation signal.

Known verdicts and HTTP

Uses prior threat records as evidence and warns when a URL sends data over unencrypted HTTP.

Common phishing-link red flags

The real domain appears after the trusted brand

A URL such as https://paypal.com.account-review.example.org/ is controlled by example.org. An attacker can put almost any trusted name in a subdomain or path. Read the hostname carefully rather than searching the full URL for a familiar word.

A small spelling change creates a different site

Examples include swapped characters, omitted letters, extra hyphens, and number substitutions. Internationalized domain names can also contain characters that look similar on screen. If the identity matters, reach the organization through a bookmark or address you type yourself.

The message manufactures urgency

“Pay now,” “verify immediately,” “your account will be closed,” and “do not contact support” are designed to shorten the time you spend checking. Pause, open the claimed service independently, and look for the same alert inside your account.

The destination is hidden

Short URLs, QR codes, buttons, and linked display text can conceal the final domain. This checker evaluates the URL you submit; it does not promise to expand every redirect chain or render the final page.

What each result means

  • Safe: the required threat-list check completed and no checked signal found a known threat at that moment.
  • Suspicious: a warning signal such as typosquatting, risky infrastructure, or unencrypted HTTP needs further verification.
  • Dangerous: a strong known-threat or abuse-reputation signal was found. Do not visit the link or enter information.
  • Unknown: a required provider did not complete, so the service intentionally refused to issue a Safe verdict.

If a result is Dangerous: do not open the page, download its files, reply to the sender, or use contact information from the same message. Report it through the platform where it arrived and verify the claimed request through an official app, bookmark, or phone number found independently.

What a phishing checker can miss

Brand-new pages may not have accumulated a reputation yet. A legitimate domain can be compromised, a page can change after the scan, and an attacker may show different content based on geography or device. URL-level checks also cannot prove that a business offer, payment request, support agent, or person contacting you is genuine.

This scanner does not execute the destination page, download files, inspect attachment contents, or provide a malware sandbox. Use the result with the manual steps in our link-safety checklist.

What happens to the submitted URL

The service removes the browser-only fragment after #, processes the URL on the islinksafe.com backend, sends it to Google Web Risk's Lookup service, and may send the website's resolved public IP to AbuseIPDB. The domain and verdict may be stored. Read the privacy policy before checking URLs that contain sensitive query parameters.

Independent sources

Google documents that Web Risk checks URLs against updated lists of unsafe web resources while also warning that no list is comprehensive or error-free. See the official Google Web Risk overview. For user guidance, see CISA's phishing guidance.

Want automatic checks while browsing?

The Chrome extension can check the active page and display a warning without requiring you to paste every URL manually.

Add to Chrome — free