Home / Free tools / URL checker
Free · no account

Is this website safe?

Paste a link and find out what it actually is before you click it — how old the domain is, who issued the certificate, what the mail records say, which technologies the server runs, and whether the risk signals corroborate each other or just look scary on their own.

Live check

Check a link

Free checks available today

Works with a bare domain or a full link. We fetch it from our servers, not from your browser — you never load the page.

§01 / WHAT IT READS
Five evidence tiers

Everything a link will tell you if you ask properly.

The checker gathers each tier independently. A failure in one degrades to honest evidence rather than sinking the whole check.

The string itself

Offline

Lookalike characters, deceptive subdomains, a brand name in the path instead of the host, punycode, embedded credentials, raw IP addresses, and the free-hosting patterns phishing kits reuse.

Registration

RDAP

When the domain was created and when it expires, who registered it, which statuses the registry has applied, and whether DNSSEC is on. Age is the single most useful number on this page.

DNS and mail

Live lookups

A and MX records, nameservers, and whether the domain publishes SPF, DMARC and CAA. A business domain with no mail policy at all is telling you something about who runs it.

The certificate

Real handshake

We complete a TLS handshake and read what the server actually presents — issuer, validation level, hostname match, alternate names, protocol version, and how many days are left.

The response

Guarded fetch

Status codes and the full redirect chain, security headers, cookie flags, compression and caching, and the technologies fingerprinted from headers and markup — including end-of-life ones.

The page

Content

Title, description, canonical, language, structured data, image alt coverage, contact and policy pages, the copyright year, and how much of the page is script.

§02 / THE VERDICT
How it decides

One scary signal never convicts.

Most URL scanners fail in one of two directions. Either they flag every young domain and every self-signed certificate, so people stop reading them — or they only recognise links already on a blocklist, which means they are always a day late to a campaign that lives for six hours.

This one requires corroboration. To reach MALICIOUS, risk signals have to fire in at least two independent evidence tiers and across at least three categories. A new domain on its own is a note. A new domain, with a certificate issued this morning, resolving to a host in a network full of throwaway sites, serving a login form that posts somewhere else — that is a cluster, and clusters are what the verdict is built on.

The four outcomes are deliberately blunt:

  • MALICIOUS — corroborated across tiers and categories. Do not click.
  • SUSPICIOUS — a strong gate fired, or several categories did, without enough independent support to convict. Verify by another route.
  • TRUSTED — aged registration, a verified certificate, hardened headers, and no strong risk gates.
  • SAFE-ISH / UNRATED — nothing malicious surfaced, but the positive evidence is thin. This is the honest answer for most small sites, and it is not the same as a clean bill of health.

And a separate quality grade

Alongside safety you get a six-dimension A–F scorecard — setup and security, SSL/TLS, optimization, content, SEO, and performance signals — with a ranked list of what to fix first and how many points each fix is worth. It is a different question from “is this dangerous”, and useful for a completely different reason: a site that scores badly on maintenance is often a site nobody is watching.

§03 / READING IT

How far the result goes

It cannot tell you a site is safe. It can tell you that no evidence of danger surfaced from the signals it can reach, which is a much smaller claim. A well-funded phishing operation with an aged domain, a real certificate and clean headers will read as unremarkable here, because it is unremarkable — the deception is in the content and the context, not the infrastructure.

It also sees one moment. A link that is clean when you check it can be compromised an hour later, and a compromised page on an otherwise legitimate site is the hardest case in the whole discipline. Treat the result as one input to a decision, not the decision.

What we do with what you paste

Nothing is saved. The free tools hold your input for the length of the request and drop it with the response — no stored report, no archived file, no record of the URL, the message or the filename. The only thing we keep is an anonymous count so the daily allowance means something, and it is a number, not an identity.

Everything you see comes from deterministic analysis: public registration records, live DNS and TLS handshakes, header parsing and PDF structure. The same engines answer the same way whether or not you have an account.

§ MORE FREE TOOLS
No account needed

Two more you can use right now.

Related reading

From Field Notes.

§ QUESTIONS
FAQ

Questions people actually ask.

How do I know if a website is safe?

No single signal decides it. Look at how long the domain has been registered, whether the certificate matches the hostname and comes from a real issuer, whether the site publishes SPF and DMARC records, and whether the content matches the claimed business. This tool gathers all of those and only reports a malicious verdict when independent categories agree — one bad signal is never enough.

What does a brand-new domain actually mean?

It means caution, not guilt. Phishing infrastructure is usually days or weeks old because it gets burned quickly, so registration age is one of the strongest single predictors. But every legitimate business also had a first week. Age is corroborating evidence, not a verdict.

Is a padlock in the address bar proof a site is legitimate?

No, and this is the most common misunderstanding in web safety. A padlock means the connection is encrypted, and free certificates are issued to anyone who controls a domain — including the person running the fake login page. What matters is who the certificate was issued to, when, and whether it matches the site's claims.

Does checking a URL here visit the site?

Yes — the checker fetches the page from our servers, never from your browser, and every request is guarded so it can only reach public internet addresses. You do not load the page yourself, which is the point.

Why do some checks say “unknown”?

Because the input could not be gathered — a registry that did not answer, a server that refused the connection. An unknown check drops out of the score entirely rather than being guessed at. A missing answer is never quietly treated as a pass.

Check the document, not just the link.

The same account that lifts the daily limit gives you full forensic document scans.