Paste a link and find out what it actually is before you click it — how old the domain is, who issued the certificate, what the mail records say, which technologies the server runs, and whether the risk signals corroborate each other or just look scary on their own.
You've used your free checks for today. Create a free account to keep going — it takes about thirty seconds.
The checker gathers each tier independently. A failure in one degrades to honest evidence rather than sinking the whole check.
Lookalike characters, deceptive subdomains, a brand name in the path instead of the host, punycode, embedded credentials, raw IP addresses, and the free-hosting patterns phishing kits reuse.
When the domain was created and when it expires, who registered it, which statuses the registry has applied, and whether DNSSEC is on. Age is the single most useful number on this page.
A and MX records, nameservers, and whether the domain publishes SPF, DMARC and CAA. A business domain with no mail policy at all is telling you something about who runs it.
We complete a TLS handshake and read what the server actually presents — issuer, validation level, hostname match, alternate names, protocol version, and how many days are left.
Status codes and the full redirect chain, security headers, cookie flags, compression and caching, and the technologies fingerprinted from headers and markup — including end-of-life ones.
Title, description, canonical, language, structured data, image alt coverage, contact and policy pages, the copyright year, and how much of the page is script.
Most URL scanners fail in one of two directions. Either they flag every young domain and every self-signed certificate, so people stop reading them — or they only recognise links already on a blocklist, which means they are always a day late to a campaign that lives for six hours.
This one requires corroboration. To reach MALICIOUS, risk signals have to fire in at least two independent evidence tiers and across at least three categories. A new domain on its own is a note. A new domain, with a certificate issued this morning, resolving to a host in a network full of throwaway sites, serving a login form that posts somewhere else — that is a cluster, and clusters are what the verdict is built on.
The four outcomes are deliberately blunt:
Alongside safety you get a six-dimension A–F scorecard — setup and security, SSL/TLS, optimization, content, SEO, and performance signals — with a ranked list of what to fix first and how many points each fix is worth. It is a different question from “is this dangerous”, and useful for a completely different reason: a site that scores badly on maintenance is often a site nobody is watching.
It cannot tell you a site is safe. It can tell you that no evidence of danger surfaced from the signals it can reach, which is a much smaller claim. A well-funded phishing operation with an aged domain, a real certificate and clean headers will read as unremarkable here, because it is unremarkable — the deception is in the content and the context, not the infrastructure.
It also sees one moment. A link that is clean when you check it can be compromised an hour later, and a compromised page on an otherwise legitimate site is the hardest case in the whole discipline. Treat the result as one input to a decision, not the decision.
Nothing is saved. The free tools hold your input for the length of the request and drop it with the response — no stored report, no archived file, no record of the URL, the message or the filename. The only thing we keep is an anonymous count so the daily allowance means something, and it is a number, not an identity.
Everything you see comes from deterministic analysis: public registration records, live DNS and TLS handshakes, header parsing and PDF structure. The same engines answer the same way whether or not you have an account.
Paste the raw headers. Read SPF, DKIM and DMARC, walk the relay chain, and see the display-name and reply-to tricks behind most invoice fraud.
Read a headerUpload a PDF. See saved revisions, values an earlier version carried, hidden layers, and the structural traces an edit leaves behind.
X-ray a PDFThe field checks that survive contact with a convincing website.
Where a lookalike domain fits in the chain, and which control actually stops it.
Know Your Business, and why a convincing website is not evidence of one.
No single signal decides it. Look at how long the domain has been registered, whether the certificate matches the hostname and comes from a real issuer, whether the site publishes SPF and DMARC records, and whether the content matches the claimed business. This tool gathers all of those and only reports a malicious verdict when independent categories agree — one bad signal is never enough.
It means caution, not guilt. Phishing infrastructure is usually days or weeks old because it gets burned quickly, so registration age is one of the strongest single predictors. But every legitimate business also had a first week. Age is corroborating evidence, not a verdict.
No, and this is the most common misunderstanding in web safety. A padlock means the connection is encrypted, and free certificates are issued to anyone who controls a domain — including the person running the fake login page. What matters is who the certificate was issued to, when, and whether it matches the site's claims.
Yes — the checker fetches the page from our servers, never from your browser, and every request is guarded so it can only reach public internet addresses. You do not load the page yourself, which is the point.
Because the input could not be gathered — a registry that did not answer, a server that refused the connection. An unknown check drops out of the score entirely rather than being guessed at. A missing answer is never quietly treated as a pass.
The same account that lifts the daily limit gives you full forensic document scans.