Check if a link is phishing
Start with the complete URL and the message that delivered it. CheckLink helps review suspicious links by surfacing visible risk signals, while you compare the final domain with the official organization or service.
Paste a suspicious URL to check visible phishing signals, fake-login patterns, redirects, and domain context before you click, sign in, or share information.
CheckLink provides risk signals and review context, not a guarantee. Verify sensitive links through official channels before acting.
Start with the complete URL and the message that delivered it. CheckLink helps review suspicious links by surfacing visible risk signals, while you compare the final domain with the official organization or service.
The scanner reviews URL structure, redirects, final-domain changes, encoded hosts, raw IP addresses, and other visible indicators. These signals help prioritize caution but do not prove every safe or malicious outcome.
Warning signs include a misspelled brand domain, an unrelated base domain, urgent account language, a shortened link, a long redirect chain, or a path designed to resemble a familiar login page.
A polished page can still be fake. Before entering credentials, read the base domain from right to left, open the official service independently, and be cautious when a message creates urgency or asks for recovery codes.
Redirects can be normal, but an unexpected domain change deserves context. Review each hop, the final registrable domain, lookalike spelling, punycode, and whether the destination matches the sender's claim.
Do not open the link merely to test it. Copy it into the scanner, verify the request through an official website or separate channel, and request professional or manual review when money, credentials, work, or customers are involved.
Next step: use the related tool that matches your situation, or request manual review when the link affects money, credentials, accounts, work, or customers.
Copy the complete URL without opening it, scan it, review the final domain and visible warning signals, and verify the request through an official channel.
Yes. A phishing page can use HTTPS, familiar branding, and polished design. The domain and request context still need review.
Look for misspellings, misleading subdomains, raw IP addresses, unusual encoding, unrelated final domains, short links, and unexpected redirect chains.
No. Copy the URL into a link checker instead, and use an official website or separate communication channel to verify sensitive requests.
No. CheckLink checks visible risk signals and helps review suspicious links, but it does not replace professional security tools or guarantee detection.
Open the current page, inspect links from the browser menu, and jump into CheckLink faster without an account.
Works with Chrome and compatible Chromium-based desktop browsers. Firefox and Safari versions are not currently available.

The extension sends a URL only when you choose a scan action. It does not store scan history.