Thursday, October 8, 2026 Breach Index $4.5B lost to breaches in 2026 · 106 breaches made public

Lab tool · Tool

Is this link safe? Free URL checker, Check Texts, Emails Instantly

What does this tool check?

You paste a link, and our server checks it for you. You never have to open it. We look at:

Threat lists

We ask Google Safe Browsing and URLhaus (a malware list run by the security group abuse.ch) whether the link is a known phishing or malware page. Phishing means a fake page that tries to steal your passwords, codes or card details.

Where the link really goes

Short links and redirects can hide the real address. We follow up to five steps and show you each one.

How old the website is

Scam websites are usually only days old. We get the registration date from the official domain registry.

Look-alike names

We spot addresses that copy a known brand, such as amaz0n-support.com or usps.redelivery-track.top.

Risky downloads

We warn you when a link downloads an app or a program, such as an APK file for Android.

The message itself

If you paste the whole message, we also check its wording for the three requests that scammers make: install this app, share this code, or send this payment.

We also look for other warning signs, such as a number instead of a website name, or an "@" that hides the real address.

What do the results mean?

Dangerous

The link, or a page it sends you to, is on a list of known phishing or malware pages. Do not open it.

Suspicious

The link shows a strong warning sign, such as a brand new website or a fake brand name, or two smaller warning signs together.

No known threats found

We did not find the link on any list, and we did not see strong warning signs. This does not mean the link is safe.

Why don't we say a link is safe?

Attackers create new scam pages every day, and a page can go live minutes before the message reaches you. Threat lists cannot add a page until someone reports it. So a link that is on no list may still be a scam, and we will never call a link safe.

The message matters as much as the link. If a message asks you to install an app, share a code or send money, stop and check with the company directly, whatever this tool says.

What should you do if a link is dangerous?

  1. Do not open it. Delete the message and report it as spam or junk.
  2. Check with the company yourself. Use its official app, or a website or phone number you look up yourself.
  3. If you already typed a password, change it on the real website and turn on two-step login.
  4. If you shared card details or sent money, call your bank right away, using the number on the back of your card.
  5. If you installed an app from the link, turn on airplane mode, uninstall the app and call your bank.

What do we never ask for?

We will never ask for your passwords, one-time codes, wallet seed phrases or payment details. This tool only needs the link or the message. Note that no real bank, delivery company or government office will ask for these in a message either.

What happens to what you paste?

Our server sends the link, never the message, to Google Safe Browsing, URLhaus and the domain registry. We keep the result for 10 minutes so repeat checks are fast, without the part of the link after the "?", which can hold personal details. We never save the message, and we do not keep a record of what you checked. To stop abuse, we keep a scrambled code made from your IP address for 10 minutes, and then it is deleted.