Check if a link is phishing
Start with the complete URL and the message that delivered it. CheckLink helps review suspicious links by surfacing visible risk signals, while you compare the final domain with the official organization or service.
Paste the URL from an unexpected login, payment, or account message below, then confirm the scan. Review domain and redirect warning signals, their reasons, and what could not be verified before you act.
The address is placed in the scanner for you. The check starts only after you confirm it there.
CheckLink provides risk signals and review context, not a guarantee. Verify sensitive links through official channels before acting.
Start with the complete URL and the message that delivered it. CheckLink helps review suspicious links by surfacing visible risk signals, while you compare the final domain with the official organization or service.
The scanner reviews URL structure, redirects, domain changes, encoded hosts, and raw IP addresses. It does not read the surrounding email or inspect the destination's rendered login form. Use Phishing Message Analyzer for message wording and identity clues, then verify the request through a known official channel.
A misspelled brand domain or misleading subdomain can imitate a trusted service. Urgent account language is a clue in the message for you to assess separately. Short URLs and redirect chains also occur in ordinary marketing, so consider the evidence together with what the sender asks you to do.
A polished page can still be fake. Before entering credentials, read the base domain from right to left, open the official service independently, and be cautious when a message creates urgency or asks for recovery codes.
Redirects can be normal, but an unexpected domain change deserves context. Review each hop, the final registrable domain, lookalike spelling, punycode, and whether the destination matches the sender's claim.
If you entered a password, shared a code, granted account access, or opened a file, follow the response for that action. The Phishing First Aid tool and linked virus guide explain the next steps. A URL check cannot tell you whether your device or account was compromised.
Next step: use the related tool that matches your situation, or request manual review when the link affects money, credentials, accounts, work, or customers.
Copy the complete URL without opening it, scan it, review the final domain and visible warning signals, and verify the request through an official channel.
Yes. A phishing page can use HTTPS, familiar branding, and polished design. The domain and request context still need review.
Look for misspellings, misleading subdomains, raw IP addresses, unusual encoding, unrelated final domains, short links, and unexpected redirect chains.
No. Copy the URL into a link checker instead, and use an official website or separate communication channel to verify sensitive requests.
No. CheckLink checks visible risk signals and helps review suspicious links, but it does not replace professional security tools or guarantee detection.