Paste any link from an SMS, WhatsApp, email or post. We analyse the address, follow its redirects safely, look up the domain's age and check open threat feeds.
Long links, shortened links (bit.ly, t.co) and links hidden behind "click here" all work. We never open it on your device.
Brand names in the wrong place, look-alike spellings, punycode, an "@" before the real host, raw IP addresses, risky endings such as .xyz or .top, and pressure words like "verify" or "KYC".
Shortened and bounced links are followed up to five hops from our network, so the destination never learns anything about you. You see every hop and the final page.
When was the domain registered (phishing domains are usually days old), does it appear on abuse.ch URLhaus, and — where enabled — Google Safe Browsing.
No. Nothing is opened in your browser. Our server makes a single request, reads only the response headers, and discards the page.
It means none of the checks we run found a problem. New scam sites appear every hour, so treat a clean result as "not known to be bad", not as a guarantee.
Yes. Copy the link (long-press, then copy) and paste it here. If the message also asks you to pay, run the UPI checker as well.
Most phishing domains are registered a few days before the campaign and abandoned after it. A bank, college or government site has a domain that is years old.
Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.