MYTHOSCORTEX

🔗 URL Scanner

A free phishing link checker, scam link checker, and link spam checker in one place. Paste any link to see the lookalike domains, hidden redirects, and brand-new registrations it trips, plus an optional Deep Scan that visits the real page in a sandboxed browser.

By default the link itself is never fetched or visited. We only read the text of the URL and look up its bare domain name against public WHOIS/RDAP, DNS, and certificate-transparency records. Deep Scan below is the one opt-in exception.

🔗

Paste a URL above to check it.

How to check if a URL or link is safe

Paste a link into the box above. Whether you call it a phishing link checker, a scam link checker, or a link spam checker, this URL scanner does the same job: it instantly runs the link through 15checks that catch the tricks real scam links use, from lookalike spelling and hidden redirects to brand-new domains, without ever visiting the link unless you explicitly opt into Deep Scan. Here's exactly what each check looks for and why it matters.

  • Uses an IP address instead of a domain name. Legitimate companies use domain names. IP addresses in URLs almost always mean phishing.
  • Hides the real destination behind a fake address before the @. A URL like "[email protected]" actually goes to evil-site.tk — browsers treat everything before the @ as a discarded username, but your eye reads "paypal.com" first.
  • Uses look-alike characters to impersonate a brand name. "paypa1.com" or "rnicrosoft.com" look like the real brand at a glance. Your eye fills in the gap — that's the trick.
  • One or two characters off from a real brand name. A domain that's one letter away from a well-known brand (like an extra, missing, or swapped character) is a classic typosquat — registered to catch people who mistype the real address.
  • Brand name appears as a subdomain, not the real site. "paypal.secure-login.com" is NOT PayPal. Anyone can create a subdomain that includes a brand name.
  • Mixes alphabets to imitate a real domain (homograph attack). A Cyrillic "а" or Greek "ο" looks identical to a Latin letter but is a completely different character — "аpple.com" is not apple.com.
  • Domain itself is stuffed with security/login keywords. Real companies don't need "secure-login-verify-account" in their own domain name. Legitimate brands use short, stable domains.
  • Uses a free, high-abuse domain extension. Domains ending in .tk, .ml, .ga, .cf and similar are free and heavily used for phishing because they cost nothing to create.
  • Uses encoded international characters to impersonate a real site. "xn--" at the start of a domain label means it's an encoded international character set — a common way to disguise a look-alike domain.
  • Domain name is padded with multiple hyphens. Real brand domains are short and simple. "paypal-account-verify-secure.com" is a pattern almost exclusive to phishing.
  • Uses a URL shortener to hide the real destination. Shorteners like bit.ly hide where a link actually goes. Preview it at checkshorturl.com before clicking, or run it through Deep Scan below.
  • Not encrypted (HTTP, not HTTPS). Any legitimate site that handles accounts uses HTTPS. HTTP means your connection isn't encrypted.
  • Path contains /verify, /secure, /confirm or similar. These paths are designed to make fake login pages look official.
  • Unusual number of subdomains. Chains like 'secure.verify.update.malicious.com' are designed to make the real domain hard to spot.
  • How recently the domain was registered. We look up the domain's public WHOIS/RDAP registration date and, as a backup, the earliest publicly-logged TLS certificate for it. Anything under 30 days old is a red flag, under 6 months a caution — brand-new domains are disproportionately used for phishing even when they're not on any blocklist yet.

🔬 What Deep Scan adds

Deep Scan is powered by Cloudflare's URL Scanner and is the only feature on this page that actually visits the link, inside a sandboxed browser Cloudflare controls, never your own device. It shows the real, final destination after any redirects (so a shortened link can't hide where it goes), a screenshot of the live page, the hosting details, and a malicious/benign verdict pulled from threat-intelligence feeds. It's opt-in because it's the one check here that leaves more than a bare domain name: the full link is sent to Cloudflare, and the scan is unlisted but not private.

📷 Got the link from a QR code?

"Quishing," phishing via QR code, is one of the fastest-growing scam formats because a QR code hides the destination completely until your camera app resolves it, and most phones don't show the full URL before opening it. If your phone's camera showed you a link before you tapped it, paste that link here first. Be especially wary of QR codes on parking meters, unexpected packages, or emails claiming a document needs "secure verification."

For example, a link like paypa1-secure-verify.tk/logintrips four checks at once: look-alike character substitution, a domain-keyword stack, a high-abuse free TLD, and a suspicious path. That kind of stacking is what pushes a result from "suspicious" to "dangerous." Got an email instead of just a link? Use the Phishing Detector to scan the full message text, or come back here any time you just need a quick phishing check, scam check, or link spam check on a single URL.

Frequently asked questions

How do I check if a URL is safe?

Paste the link into the box above. The scanner checks the domain itself for lookalike spelling, brand names stuffed into a subdomain, mixed-alphabet homograph tricks, free high-abuse extensions like .tk, and more, all without visiting the link. For more certainty, run Deep Scan, which actually opens the link in a sandboxed browser and shows you a screenshot and verdict.

Is this a link spam checker?

If you mean checking whether a specific link someone sent you is spammy, scammy, or malicious, then yes, paste it above. If you're looking to audit your own website's incoming backlink profile for spam, that's a different kind of tool (an SEO backlink auditor), not what this one does.

How do I check a link that was in an email?

Copy the link out of the email and paste it here for the full domain-age, lookalike-spelling, and hidden-redirect checks. If you want to scan the rest of the email text too, use the Phishing Detector tool instead, or alongside this one.

Does this tool actually visit the link?

Not by default. The base scan only reads the text of the URL and looks up its bare domain name against public WHOIS/RDAP, DNS, and certificate-transparency records. Deep Scan is the one opt-in exception: it sends the full link to Cloudflare, which visits it in a sandboxed browser you never touch, and returns a screenshot and verdict.

What is a URL shortener hiding, and how do I see the real destination?

Shorteners like bit.ly or tinyurl.com replace the real destination with a short code, so you can't tell where a link goes just by looking at it. Run Deep Scan on a shortened link to see the actual final destination after all redirects.

How do you know when a domain was registered?

We query public WHOIS/RDAP registry records for the domain's registration date, and cross-check it against the earliest publicly-logged TLS certificate (via Certificate Transparency logs) as a backup when RDAP has no data. Domains registered in the last 30 days are flagged as a red flag, under 6 months as a caution.

What is Deep Scan and is it private?

Deep Scan is powered by Cloudflare's URL Scanner (built on urlscan.io). It's opt-in because it's the only check on this page that leaves more than a domain name: the full URL is sent to Cloudflare and visited in a real sandboxed browser. The scan is submitted as "Unlisted," meaning it won't show up in Cloudflare Radar's public search, but it isn't fully private either. Anyone with the direct scan link can view it.

What's a homograph or lookalike-character attack?

Scammers register domains using characters from a different alphabet (like a Cyrillic "а" instead of a Latin "a") or visual substitutes ("paypa1" instead of "paypal") that look identical or nearly identical at a glance. This scanner checks for both.

I got this link from a QR code. Can I still check it?

Yes. If your phone's camera app showed you the link before opening it, copy that link and paste it here. QR code phishing ("quishing") is one of the fastest-growing scam formats specifically because it hides the destination until the very last moment.

Can this tool guarantee a link is safe?

No automated tool catches everything. Treat a clean result as one good sign, not a guarantee, and go directly to the official site if you're ever unsure.