About the Scam & Phishing Link Analyzer
This is the “is this text message real?” tool. Paste the link and it runs the checks a security analyst would run, from our server rather than your device, so the suspicious site never touches your browser.
The centrepiece is domain age, read live from the registry over RDAP. It is the strongest single phishing signal in existence, because the economics are unavoidable: a campaign needs a domain for a handful of days before it is reported and killed, so it registers a fresh one every time. A domain born nine days ago that says it is your bank is not your bank. Around that sit punycode and homograph detection, typosquat distance from a bundled list of the brands scams actually impersonate, the full redirect chain including where a shortener lands, certificate age and issuer from a real TLS handshake, and an inspection of the destination page for the thing that gives the game away — a login form that posts your password to somebody else’s domain.
Every hop is re-validated against private and reserved address ranges before it is requested, so pointing this at an arbitrary URL is safe for us as well as for you. Links are cached for fifteen minutes and nothing is tied to your account.
Paste up to 15 links, one per line — the ones you pulled out of an inbox in a single sitting. Each is analysed in turn and ranked worst first.
Generates the typo variants squatters actually register — omissions, transpositions, doubled letters, adjacent-key slips, digit homoglyphs and TLD swaps — then checks which are already taken and when they were registered.
How to Use the Scam & Phishing Link Analyzer
Copy the link without opening it — long-press on a phone, or right-click and choose “Copy link address” on a computer — then paste it above and press Analyse. Our server makes the request, so the site never sees your device, your IP address or your browser fingerprint. Read the verdict first, then the signal list underneath it, which explains every factor that fed into the score. Start with domain age: if that number is small and the message claimed to be from a company you have dealt with for years, you already have your answer.
Read the Domain From Right to Left
This is the one skill worth learning, and it takes thirty seconds. In a web address, ownership is
decided by the registrable domain — the last two labels before the first
single slash. Everything to the left of that is a subdomain, which the owner of the domain can set
to absolutely anything. So in
https://apple.com.account-verify.info/login, the site is
account-verify.info. The apple.com at the front is decoration,
positioned exactly where a hurried eye reads first.
Two more variants of the same trick. The @ symbol: everything before an
@ in a URL is a username, not a destination, so
https://paypal.com@203.0.113.9/ goes to the IP address. And the
hyphen-stuffed domain: netflix-billing-update.com is one registration
that anybody could have bought, related to Netflix only in wording. Real brands almost never
hyphenate; scam registrations do it constantly because the clean version was taken twenty years
ago.
Why Domain Age Beats Every Other Check
Phishing is a volume business with a brutal clock. A campaign domain gets reported, blocklisted and suspended within days, so operators register fresh ones continuously and burn them just as fast. Industry takedown reporting consistently finds that the large majority of phishing domains are used within the first month of registration, and a substantial share within the first week. Legitimate businesses sit at the opposite end of that distribution: paypal.com was registered in 1999, google.com in 1997.
That gap is why this tool leads with the registry record rather than a reputation blocklist. A blocklist can only tell you about a domain someone has already reported, which by definition means other people were caught first. Registration date is available the moment the domain exists, and it is read here straight from RDAP — the structured JSON successor to WHOIS that registries are now required to run. There is one honest limitation: many country-code registries decline to publish creation dates over RDAP, so a blank age is a genuine unknown rather than a clean bill of health.
The Padlock Stopped Meaning Anything in About 2016
“Look for the padlock” is the most persistent piece of outdated safety advice in circulation. HTTPS proves the connection is encrypted between you and whoever is at the other end. It says nothing whatsoever about who that is. Since free automated certificate authorities made domain-validated certificates instant and costless, essentially every phishing site has a valid certificate, because getting one only requires controlling the scam domain — which the scammer does.
What a certificate can tell you is when it was issued, which this tool reports. A certificate created hours ago, on a domain created days ago, is a campaign being stood up. It is also worth knowing what the certificate covers: a certificate whose names do not include the hostname you visited means something is badly misconfigured, or the page is being served from infrastructure that was never meant to answer for it.
What Actually Happens If You Click
Clicking a phishing link is not usually the moment you are compromised — that comes a step later, and knowing the sequence helps you stop at the right point.
- Credential harvesting. A copy of a login page, often pixel-perfect, that posts your username and password to the attacker. The tool flags when the destination page contains a password field, and especially when that form submits to a different domain from the page you are on. Damage happens when you type, not when you land.
- Payment capture. A small, plausible fee — a redelivery charge, an unpaid toll, a customs handling cost. The amount is deliberately trivial so it clears without scrutiny; the card details are the real product.
- Multi-factor relay. The modern version. The fake page forwards your login to the real site in real time, prompts you for the code that arrives, and relays that too. This is why phishing-resistant factors — passkeys and hardware security keys, which are bound to the real domain and simply refuse to work on a lookalike — matter far more than SMS codes.
- Tracking and confirmation. Even with nothing typed, a click confirms the address is live and attended, which raises its value on the lists these campaigns are run from.
If You Already Entered Something
Move fast, and in this order. Change the password on the real site, reaching it by typing the address yourself or opening the app — never through the message. Change it everywhere else you used the same one, which is the step people skip and the one that turns a single mistake into six compromised accounts. Sign out all active sessions in the account’s security settings, because a stolen session cookie survives a password change. Turn on a phishing-resistant second factor. If card details went in, call the number on the back of the card and have it reissued. And check the account’s forwarding and recovery settings: quietly adding a forwarding rule or a recovery address is how an attacker keeps access after you have locked the front door.
Worried a password you used has already leaked somewhere? Run it through the Password Strength & Crack-Time Estimator, which checks it against 900 million breached passwords without ever transmitting it, and see what a given company’s breach actually exposed in the Breach Directory & Exposure Timeline. Browse every Security & Privacy tool for more.
Frequently Asked Questions
What is the single biggest sign a link is a phishing scam?
Domain age. Phishing infrastructure is disposable — campaigns register a domain, run it for a few days and abandon it before the takedown lands. A domain that is under a month old and claims to be a bank, a courier or a streaming service is almost never genuine. Real companies have held their domains for a decade or more, and this tool shows you the exact registration date from the registry itself.
Does the padlock mean a site is safe?
No, and it has not for years. The padlock means the connection is encrypted, not that the other end is honest. Free domain-validated certificates are issued automatically to anyone who proves they control a domain, which a scammer does by owning the scam domain. Most phishing pages have a valid padlock. What matters is who owns the domain and how long they have owned it.
Is it safe to paste a link here?
Yes. Our server makes the request, from a hardened fetcher that refuses private and internal addresses and re-validates every redirect hop rather than blindly following it, and nothing is rendered or executed. Your browser never contacts the suspicious site. Do not paste links that contain a password-reset token or a one-time login code, though: those are single-use secrets, and loading one may burn it.
What is a homograph or punycode attack?
Domain names can contain non-Latin characters, and several Cyrillic and Greek letters are visually identical to Latin ones — the Cyrillic а, е, о, р and с in particular. A domain spelled with one of those looks exactly like the real thing in a message but is a completely different registration. Behind the scenes it is encoded starting with xn--, which this tool detects and shows you.
The link looks fine but the message felt wrong. What now?
Trust that instinct and ignore the link entirely. Open the company's app, or type the address you already know into your browser, and check your account there. Legitimate organisations never lose anything by you reaching them the long way round. If the message created urgency — an account closing, a parcel held, a fine due — treat the urgency itself as the warning sign, because manufactured time pressure is the core technique of every social engineering script.