How the checker works
No black box. Here's exactly what happens when you paste a link — and, just as importantly, what the checker can't do.
We read the address, we never open the link
The checker analyzes the text of the web address — it does not visit the page, load its content, or follow any redirects. That keeps you safe (we never touch a live malicious page) and keeps it fast.
Three layers of analysis
1. Look-alike & trick detection
We break the address into its parts and flag the tricks scammers use: the @ redirect trick, raw IP addresses instead of domains, punycode look-alikes, brand names on the wrong domain, suspicious domain endings, and more. This is why every result shows you the address taken apart, not just a score.
2. Google Safe Browsing
We check the address against Google Safe Browsing — the same database that powers the “Deceptive site ahead” warning in Chrome — for known phishing and malware.
3. Known-bad URL lists
We cross-reference public malicious-URL databases (such as URLhaus) that catch freshly-reported threats, often faster than the big lists.
What the result means
- Looks clean — no obvious red flags. Not a guarantee (see below).
- Be careful — one or more warning signs; slow down and verify.
- Likely dangerous — strong signals of a scam, or a known-bad listing.
What it can't catch — read this
No checker is perfect. A brand-newscam site can look clean for a few hours before it's reported. A legitimate-looking address can still lead to a scam page. Treat “Looks clean” as “no obvious red flags,” not “safe to trust.” When money, passwords, or one-time codes are involved, verify through a channel you already trust.
Stay a step ahead
Get a short weekly email on the scams going around right now.