π£ Phishing Detector
Paste a suspicious email or URL. We scan it for the tricks scammers actually use β and explain each one so you can spot them yourself next time.
Analysis runs as you type. Nothing is sent anywhere.
π£
Paste any suspicious email above to scan it.
How to check if an email or link is phishing
Paste the email text or link into the box above. This phishing checker instantly scans it against 17patterns real scammers actually use, split into email and URL modes. Here's exactly what each mode checks for and why it matters β no need to paste anything to read these.
π§ What the email phishing checker looks for
- Urgency / pressure language. Scammers create fake emergencies to stop you thinking clearly.
- Threatens account suspension or closure. Real companies don't threaten to close accounts over email without prior notice.
- Asks for passwords, card numbers, or personal info. No legitimate company emails you asking for your password or financial details.
- Too-good-to-be-true offer. You didn't enter a competition. You didn't win anything. This is bait.
- Generic greeting instead of your name. Your bank knows your name. 'Dear Customer' means they got your email from a breach, not from your account.
- Impersonates a well-known brand. Fake emails copy logos and wording from PayPal, Amazon, Netflix etc. to look real.
- Suspicious links or 'click here' with no visible URL. Real links show you where they go. Phishing links hide behind 'Click Here' buttons.
- Mentions unusual login or suspicious activity. This is designed to panic you. If you're worried, go directly to the app β don't click the email link.
π What the phishing link / URL checker looks for
- Uses an IP address instead of a domain name. Legitimate companies use domain names. IP addresses in URLs almost always mean phishing.
- Uses numbers to impersonate a brand name. "paypa1.com" looks like PayPal at a glance. Your eye fills in the gap β that's the trick.
- Brand name appears as a subdomain, not the real site. "paypal.secure-login.com" is NOT PayPal. Anyone can create a subdomain that includes a brand name.
- Uses a free, high-abuse domain extension. Domains ending in .tk, .ml, .ga, .cf and similar are free and heavily used for phishing because they cost nothing to create.
- Uses international characters to impersonate a real site. "Π°pple.com" with a Cyrillic 'Π°' looks identical to apple.com but is a completely different site.
- Uses a URL shortener to hide the real destination. Shorteners like bit.ly hide where a link actually goes. Preview it at checkshorturl.com before clicking.
- Not encrypted (HTTP, not HTTPS). Any legitimate site that handles accounts uses HTTPS. HTTP means your connection isn't encrypted.
- Path contains /verify, /secure, /confirm or similar. These paths are designed to make fake login pages look official.
- Unusual number of subdomains. Chains like 'secure.verify.update.malicious.com' are designed to make the real domain hard to spot.
For example, an email reading "Your account will be suspended within 24 hours β click here to verify"trips both the urgency-language and account-threat checks above before you've even looked at the link itself. A link like paypa1-secure.tk/logintrips three URL checks at once: number substitution, a high-abuse free TLD, and a suspicious path β which is exactly the kind of stacking that pushes a result from "suspicious" to "dangerous."
Frequently asked questions
How do I check if an email is phishing?βΌ
Paste the full email text into the box above and switch to Email mode. The checker scans it for the patterns real phishing emails use β urgency language, account-suspension threats, requests for passwords or card details, and more β and explains why each one matters.
How can I tell if a link is a scam?βΌ
Switch to URL mode and paste the link in. The checker looks at the domain itself (lookalike spelling, brand names stuffed into a subdomain, free high-abuse extensions like .tk, IP addresses instead of a domain) without ever visiting the link.
Can I check a link without clicking it?βΌ
Yes. Paste it into the URL box β this tool only reads the text of the link itself. It never fetches, loads, or visits the destination, so it's safe to check a link you'd never actually click.
Is my email or URL sent anywhere when I use this tool?βΌ
No. Everything runs in your browser with plain pattern matching. Nothing you paste is transmitted, logged, or stored.
Can this tool guarantee an email or link is safe?βΌ
No automated tool catches everything. Treat a clean result as one good sign, not a guarantee, and go directly to the official site or app if you're ever unsure.
What's the difference between a red flag and a warning sign?βΌ
Red flags are patterns almost always tied to scams, like urgency language or requests for a password. Warning signs show up in real messages too, so a couple together should raise caution rather than certainty.
Is this a spam filter or an antivirus scanner?βΌ
No β it's a plain-English education tool, not a mail-server spam filter or malware scanner. It won't block or quarantine anything; it explains the tricks in whatever you paste so you can learn to spot them yourself next time.