Skip to content
SecAIQ

Link & Phishing Checker

Phishing links rely on you not looking closely, a domain that's one character off, a redirect chain that ends up somewhere else entirely, or a file extension disguised to look safe. Paste any link here and this tool breaks down its real structure: the actual destination domain, lookalike-brand detection, hidden redirects, and risky extensions, all analyzed locally without visiting the site.

Phishing links rely on you not looking closely, a domain that's one character off from the real thing, a redirect chain that ends up somewhere else entirely, or a file extension disguised to look safe. Paste any link below and this tool breaks down its real structure: the actual destination domain, lookalike-brand detection, hidden redirects, and risky file extensions, all analyzed locally without ever visiting the site.

Frequently Asked Questions

How do I know if a link is phishing?

Look at the actual domain right before the first single slash, not the subdomain or path text around it, check for lookalike spelling of a real brand, and be wary of shortened or redirect-heavy links. This tool automates that check for you.

Does this tool visit the link?

No, the link's structure is analyzed locally in your browser. The destination site is never actually loaded or visited.

What should I do if a link looks suspicious?

Don't click it. If it claims to be from a company or person you know, contact them directly through a channel you already trust (not one provided in the suspicious message) to verify.

Related: Recognizing phishing in the age of AI-generated scams · Phishing Recognition Quiz

Press and hold the link in the message and choose "copy link", you don't need to tap it.

Try an example

These examples aren't real addresses, no request is ever sent.

Your link stays here

The link you paste is never sent to a server or saved. Analysis looks only at the address's own structure, entirely in your browser.

This tool does not visit the site: no DNS, WHOIS, or reputation lookup is made, and the link is never opened. So a "no red flags" result doesn't prove the site is safe.

How to read an address

The name right before the extension determines who owns the address. Read right to left:

https://login.example-bank.com/account

  • Registrable domain: example-bank.com, the address's actual owner.
  • Subdomain: the "login." part can be set to anything by whoever owns the domain. That's why yourbank.com.badsite.xyz is really badsite.xyz.
  • Path and parameters: the "/account?..." part is also entirely under the site owner's control.

Good to know

  • The padlock icon (https) doesn't mean an address is safe, it only means the traffic is encrypted. Nearly all phishing sites use https too.
  • Shortened links hide their real destination. If you don't recognize the sender, don't open it, type the organization's address yourself instead.
  • Letter tricks: the pair "rn" placed together can read as "m" in small fonts. rnicrosoft.com is easily mistaken for microsoft.com at a glance; the same trick works with "vv" (w) and "cl" (d).
  • Cyrillic lookalikes: domain names can mix characters from different alphabets (IDN). Cyrillic "о" looks pixel-identical to Latin "o" on screen; micrоsоft.com is technically xn--micrsft-90aa.com. This tool decodes that, your eyes can't.
  • A "no obvious red flags" result doesn't guarantee safety: a newly registered or compromised site can still be malicious. The address's structure alone isn't proof either way.