CHECKLINK AI
Phishing link review

Phishing Link Checker

Paste the URL from an unexpected login, payment, or account message below, then confirm the scan. Review domain and redirect warning signals, their reasons, and what could not be verified before you act.

Use the official scanner

Start with the link you received

The address is placed in the scanner for you. The check starts only after you confirm it there.

What it checks

Final domain changes
Misleading hostname patterns
Deep subdomains
Raw IP hosts
Observed redirect chains
Basic brand lookalike patterns
Punycode or unusual encoding
Suspicious URL structure

Limitations

CheckLink provides risk signals and review context, not a guarantee. Verify sensitive links through official channels before acting.

Check if a link is phishing

Start with the complete URL and the message that delivered it. CheckLink helps review suspicious links by surfacing visible risk signals, while you compare the final domain with the official organization or service.

Copy the URL without opening it
Compare the registrable domain
Verify unexpected requests through an official channel

URL signals and message context answer different questions

The scanner reviews URL structure, redirects, domain changes, encoded hosts, and raw IP addresses. It does not read the surrounding email or inspect the destination's rendered login form. Use Phishing Message Analyzer for message wording and identity clues, then verify the request through a known official channel.

Common signs of a phishing link

A misspelled brand domain or misleading subdomain can imitate a trusted service. Urgent account language is a clue in the message for you to assess separately. Short URLs and redirect chains also occur in ordinary marketing, so consider the evidence together with what the sender asks you to do.

Fake login page warning signs

A polished page can still be fake. Before entering credentials, read the base domain from right to left, open the official service independently, and be cautious when a message creates urgency or asks for recovery codes.

Suspicious domain and redirect checks

Redirects can be normal, but an unexpected domain change deserves context. Review each hop, the final registrable domain, lookalike spelling, punycode, and whether the destination matches the sender's claim.

What to do if you already used the link

If you entered a password, shared a code, granted account access, or opened a file, follow the response for that action. The Phishing First Aid tool and linked virus guide explain the next steps. A URL check cannot tell you whether your device or account was compromised.

How to use this tool

1. Paste the suspicious URL below and confirm the check in the scanner.
2. Compare the final domain with the claimed sender or brand.
3. Read the warning reasons and checks that could not finish.
4. Use a known official website or contact to verify login and payment requests.

What results mean

Suspicious does not always mean malicious.
A phishing-like pattern is a caution signal.
A new phishing page may not show every signal.
Manual review helps reduce false confidence.

Related tools

Next step: use the related tool that matches your situation, or request manual review when the link affects money, credentials, accounts, work, or customers.

Phishing link checker FAQ

How do I check if a link is phishing?

Copy the complete URL without opening it, scan it, review the final domain and visible warning signals, and verify the request through an official channel.

Can a phishing link look safe?

Yes. A phishing page can use HTTPS, familiar branding, and polished design. The domain and request context still need review.

What are signs of a suspicious URL?

Look for misspellings, misleading subdomains, raw IP addresses, unusual encoding, unrelated final domains, short links, and unexpected redirect chains.

Should I open a link to test it?

No. Copy the URL into a link checker instead, and use an official website or separate communication channel to verify sensitive requests.

Can CheckLink detect every phishing link?

No. CheckLink checks visible risk signals and helps review suspicious links, but it does not replace professional security tools or guarantee detection.