Why check suspicious URLs?
Phishing is the top cyber attack vector worldwide. In 2024, the Anti-Phishing Working Group (APWG) recorded over 4.7 million phishing attacks, a record. Each attack starts the same way: a link that looks legitimate but leads to a credential-harvesting page.
One click is enough. The FBI's IC3 estimates phishing caused over $2.9 billion in losses in 2023 alone. Attackers clone bank login pages, cloud service portals, and delivery tracking sites with pixel-perfect accuracy.
Three reasons to check a link before clicking:
- Personal protection: A single phishing link can expose passwords, credit card numbers, and two-factor codes in seconds
- Organizational protection: 74% of data breaches involve a human element, often a clicked phishing link (Verizon DBIR 2024)
- Proactive verification: Site owners should regularly verify their domain isn't falsely flagged, which blocks visitors and damages reputation
How to use the phishing URL checker in 3 steps
Step 1: enter the suspicious URL
Paste the suspicious link into the input field. The tool accepts three formats:
- Full URL:
https://suspicious-site.com/login - Bare domain:
suspicious-site.com - IP address:
192.168.1.1
The input is normalized automatically: whitespace stripped, converted to lowercase, URL fragments removed. No data is stored after the check.
Step 2: launch the check
Click Check. The tool queries 3 threat intelligence sources simultaneously, each with its own timeout. Results typically return in under 3 seconds.
Step 3: review the report
The report displays:
- Global verdict: Safe, Suspicious, or Malicious
- Risk score: From 0 (no risk) to 100 (critical)
- Per-source details: Status, threat types, response time
- Diagnostics: Errors, warnings, and coverage information
How do threat intelligence databases work?
Threat intelligence databases collect and classify malicious URLs through four channels: user reports, automated sandbox analysis, honeypot networks, and partnerships with security vendors. No single database catches everything. Combining multiple sources dramatically increases detection rates.
| Source | What it covers | Accepted input | Strength |
|---|---|---|---|
| Google Web Risk | Social engineering (phishing), malware, unwanted software | URL, domain | The very lists that trigger Chrome, Firefox, and Safari warnings |
| VirusTotal | Aggregate of 70+ engines and URL reputation services | URL, domain | A multi-engine consensus rather than one vendor's opinion |
| URLhaus (abuse.ch) | Malware distribution only, never phishing | URL, domain, IP address | The only source that accepts an IP address. Local index refreshed every 10 minutes |
The three sources do not look at the same thing, which is exactly why they are queried together. Google Web Risk and VirusTotal cover phishing; URLhaus only lists URLs that serve a malicious file. Practical consequence: a "clean" from URLhaus says nothing about phishing, only that the URL is not known for distributing malware.
PhishTank, long cited as the community reference for phishing (human review through the OpenDNS community), has closed its submissions. Analysis now focuses on the three most reliable, actively maintained feeds.
How the risk score is calculated
The risk score is not a sum of points. It is a confidence level anchored by the verdict, then refined by how many sources agree. A single authoritative source is enough for a high score; we do not dilute confidence by adding up partial weights.
| Verdict | Sources reacting | Risk score | Level |
|---|---|---|---|
| Safe | None flags the target | 0 | None |
| Suspicious | One weak signal (VirusTotal below the threshold, or Google Web Risk extended coverage) | ~35 | Medium |
| Malicious | One authoritative source confirms (Google Web Risk, URLhaus, or VirusTotal with several engines) | ~75 | High |
| Malicious | Two sources agree | ~90 | Critical |
| Malicious | All three sources agree | 100 | Critical |
The key idea: one authoritative source, such as Google Web Risk, is enough to reach a high score on its own. Adding a second concordant source raises confidence to critical. A lone VirusTotal detection with only one or two engines is treated as a likely false positive (Suspicious, around 35), not a confirmed threat.
Real-world use cases
Case 1: banking phishing email
Scenario: An email arrives from "your bank" with urgent language, "Verify your account immediately or it will be suspended." The sender address looks almost right.
What the tool reveals: Paste the URL into the checker. Google Web Risk confirming on its own is enough to reach a high score (around 75). With VirusTotal also flagging it, two sources agree and the score climbs to critical (around 90). Threat types display as "phishing" and "social_engineering."
What to do: Do not click the link. Report the email as phishing to your provider. Navigate to your bank's website by typing the address directly in your browser. Banks never ask for credentials via email. If you already clicked, change your password immediately.
Case 2: shortened link in a text message
Scenario: You receive an SMS: "Your package could not be delivered. Update your information: bit.ly/xyz." Package delivery scams are among the fastest-growing phishing categories. APWG reports a 40% increase since 2022.
What the tool reveals: First, expand the shortened URL using an unshortener service to reveal the final destination. Then paste that destination into the checker.
What to do: If the final URL is flagged, delete the text immediately. Legitimate delivery services never request payment or personal data via SMS links.
Case 3: false positive on your domain
Scenario: Visitors report that their browser warns them your site is dangerous. You've checked your code, and nothing malicious exists. False positives happen: Google Web Risk flags roughly 0.1% of safe sites at any given time.
What the tool reveals: Enter your domain to identify exactly which source flags it. Click the source's reference link to see the specific reason.
What to do: Submit a delisting request to the flagging source (Google has a dedicated review form). Also run a security scan on your server to rule out injected scripts, hidden redirects, or compromised plugins.
FAQ - Frequently asked questions
Q: How do I check if a link is phishing?
A: Paste the URL into the input field and click Check. The tool queries Google Web Risk, VirusTotal, and URLhaus simultaneously. Within seconds, you get a verdict (Safe, Suspicious, Malicious) and a risk score from 0 to 100.
Q: What data sources power this tool?
A: Three complementary threat intelligence feeds. Google Web Risk covers social engineering, malware and unwanted software, from the lists that trigger browser warnings. VirusTotal aggregates results from 70+ antivirus engines into a single scan. URLhaus (abuse.ch) covers malware distribution only, never phishing, and is the only source that accepts an IP address. PhishTank, once a community-verified phishing source, has closed its submissions and is no longer among the queried feeds.
Q: Is the result 100% reliable?
A: No phishing detection tool achieves 100% accuracy. A "Safe" verdict means no source currently flags the URL. It does not guarantee safety. Newly created phishing pages take minutes to hours before any database detects them. Always combine tool results with common sense: check the sender, inspect the domain spelling, and avoid entering credentials on unfamiliar pages.
Q: Can I check a domain without a full URL?
A: Yes. Enter a bare domain (e.g., captaindns.com) or an IP address (e.g., 203.0.113.34). The tool detects the input type automatically and queries every compatible source.
Q: What does the risk score mean?
A: The score is a confidence level, not a sum of points. Safe is 0. A single weak signal (Suspicious) sits around 35. One authoritative source confirming a threat scores around 75 (high), two agreeing sources reach 90, and all three reach 100 (critical). A score above 85 means several sources agree.
Protect yourself now
Received a suspicious link? Paste it above and get a verdict in seconds. Bookmark this page for quick access the next time an email or text message looks off. Share it with colleagues. Most phishing succeeds because the recipient had no easy way to verify the link before clicking.
Related tools
| Tool | Purpose |
|---|---|
| IP Blacklist Checker | Check if your IP is listed on email blacklists |
| Domain Blacklist Checker | Check if your domain is blacklisted |
| Mail Header Analysis | Analyze headers of a suspicious email to trace its origin |
| Redirect Checker | Analyze redirect chains and unshorten links |
| Page Crawl Checker | Analyze crawl behavior of a web page |
| HTTP Headers Checker | Audit security headers (CSP, HSTS, X-Frame-Options) with an A to F grade |
Useful resources
- Google Web Risk - Google's commercial API against dangerous sites, backed by the lists that trigger browser warnings
- VirusTotal - Scans a URL with 70+ antivirus engines and reputation services
- URLhaus by abuse.ch - Malicious URL database
- PhishTank - Collaborative phishing verification (submissions closed)
- Anti-Phishing Working Group (APWG) - International coalition against phishing