Check if a Link Is Safe
Examine a link before opening it: homographs, literal IPs, odd schemes and tracking.
Analysis happens entirely in your browser using local heuristics — no cloud blocklists, the link is never sent to any server.
No signals found doesn't mean the link is safe — it only means it doesn't match the patterns this tool knows how to recognize. It doesn't replace your own judgment.
The link analysis will appear here
How to check if a link is safe before you click it
To check whether a link is safe before you click it, paste it here: the tool breaks it into scheme, host and path, then runs local heuristics —literal IP addresses, punycode homographs, deceptive credentials before the "@", known shorteners, high-abuse TLDs, suspicious entropy, and tracking parameters— without ever uploading or opening the link. It's free, no signup required, and every check runs inside your browser. There's no cloud blocklist or phishing database behind it — that's what keeps your input private, but it's also an honest limit, since a brand-new malicious domain nobody has reported yet won't trigger anything here. Use it to vet a suspicious link from an email, text message or DM before clicking, or to strip tracking parameters (utm_source, fbclid, gclid…) from a URL before you share it with someone else.
How to use Check if a Link Is Safe
- Paste the full URL, or just the domain (e.g. example.com/path), into the input field.
- Click "Analyze link". The tool breaks the URL into scheme, host and path, and runs the local heuristics — it never opens the link or sends it to any server.
- Review the list of signals found, each with a risk level (high, medium, info) and a plain explanation of what it means and why it matters.
- If the link carries tracking parameters (utm_source, fbclid, gclid…), copy the clean version generated automatically below it.
- If the domain uses punycode, check the highlighted Unicode form — mixed alphabets (Latin, Cyrillic, Greek) are the strongest sign of domain spoofing.
Common use cases
Checking a link from a text message or WhatsApp
Before tapping a link from an unknown sender — a delivery notice, a bank, a prize — paste it here to see the real domain and whether it uses tricks like a literal IP or deceptive credentials.
Verifying an email that claims to be from your bank
Copy the link behind the "Verify account" button without clicking it, and analyze it here — if the host doesn't match your bank's real domain, that's conclusive proof of spoofing.
Cleaning links before sharing them
Strip utm_source, fbclid, gclid and other tracking parameters from a link before posting it in a group chat or on social media, without changing where it leads.
Auditing shortened links in marketing campaigns
Check whether a bit.ly or similar link in an ad or campaign email hides an unexpected domain before you approve it for publication.
Teaching phishing awareness with real examples
Use the tool in a security training session to show what a homograph or a deceptive "@" URL actually looks like, without opening anything dangerous.
Frequently asked questions
Does this tool catch every phishing link?
No. It uses local heuristics — known patterns like literal IPs, homographs, shorteners or high entropy — not a cloud threat database. A brand-new phishing domain that doesn't match any of these patterns may trigger no signals at all, which is why "no signals" never means "safe," only "no known pattern matched."
Does the link I paste ever leave my browser?
No. Every step — URL parsing, punycode decoding, entropy calculation — runs in JavaScript inside your browser. There's no network call at all, not even to check whether the domain exists.
What's a homograph attack?
It's using letters from another alphabet — Cyrillic, Greek — that look almost identical to Latin ones to register a domain that resembles a trusted one, for example swapping the Latin "a" for a Cyrillic "а". The tool decodes punycode and flags this mix when it finds it.
Why is it warning me about an "@" in the URL when I've never seen one before?
The trick "https://your-bank.com@evil-domain.net/" makes the browser connect to "evil-domain.net", not to whatever the text before the "@" looks like. It's rare in legitimate links and very common in phishing.
What's the difference between the three signal severities?
High covers patterns almost always tied to fraud — dangerous schemes, homographs, literal IPs, deceptive credentials. Medium covers indicators that need context — shorteners, excessive subdomains, high entropy. Info is neutral context — a high-abuse TLD, tracking params — that isn't risky on its own.
Can I use this for a QR code too?
Yes — /qr-scan-safe decodes the QR code from your camera or an image and runs the resulting link through this exact same analysis engine, without ever opening it.