CHECKLINK AI
Inspect an unfamiliar URL

Suspicious Link Checker & Link Inspector

Paste the suspicious URL below to prepare a scan. After you confirm the check, review the final domain, observed redirects, warning signals, and anything CheckLink could not verify.

Use the official scanner

Start with the link you received

The address is placed in the scanner for you. The check starts only after you confirm it there.

What it checks

Visible URL structure
Observed redirect chain
Final domain when reachable
Domain changes
HTTPS connection context
Raw IP hosts
Punycode or unusual encoding
Deep subdomains and lookalike patterns

Limitations

CheckLink provides risk signals and review context, not a guarantee. Verify sensitive links through official channels before acting.

Check a suspicious link without opening it yourself

Copy the actual link address rather than its display text. A message can say one company name while linking somewhere else. The scanner requests the public URL to inspect its redirect path; it does not open the destination as a page in your browser.

Paste the complete URL, including its path
Compare the final domain with the organization you expected
Keep passwords and private account links out of public URL checks

What the link inspector result tells you

Read the result state with its explanation, evidence coverage, and recommended action. A lookalike domain or unexpected redirect deserves investigation. A redirect alone can be normal, and HTTPS protects a connection without proving who is behind a site.

Check what was actually observed
Read what could not be verified
Verify login and payment requests through a known official route

What if the destination cannot be checked?

An unreachable domain, blocked request, or incomplete redirect path limits the result. It does not prove that the link is harmless or malicious. Keep the message for context and contact the claimed sender through a channel you already trust.

Already clicked the suspicious link?

Close the page and consider what happened next: did you only view it, enter a password, grant access, or run a download? Those actions call for different responses. Use the linked guide below or Phishing First Aid for next steps.

How to use this tool

1. Copy the URL without opening the destination.
2. Paste it below, continue to the scanner, and choose Check link.
3. Review the final domain, warning signals, and incomplete checks.
4. Verify sensitive requests independently before acting.

What results mean

LOWER CONCERN still is not proof of safety.
NEEDS CONTEXT means the available evidence does not settle legitimacy.
STRONG WARNING SIGNALS explains observed reasons for concern.
CHECK INCOMPLETE means too few checks completed to assess the destination.

Related tools

Next step: use the related tool that matches your situation, or request manual review when the link affects money, credentials, accounts, work, or customers.

Suspicious link inspection questions

How do I check a suspicious link?

Copy its URL, paste it into CheckLink, and confirm the scan. Compare the observed final domain, redirects, warning signals, and unknowns with the message that carried the link.

Does a link inspector visit the destination?

CheckLink makes server-side requests to the public URL and permitted redirect hops. It does not open the destination in your browser. The destination may observe those requests, so do not submit private or one-time account links.

Can CheckLink prove a suspicious link is malicious?

No. CheckLink provides risk signals and context. It does not certify legitimacy or inspect your device for malware.

What if no warning signal is found?

No detected warning does not verify legitimacy. Read the evidence coverage and incomplete checks, and verify sensitive requests through an official channel.

Can I report a suspicious link?

Yes. Use the suspicious link report flow to submit it for manual review.