Skip to main content

Phishing URL Checker

Check any URL against 3 threat intelligence sources in seconds

Received a suspicious link via email or text? Instantly check if it's flagged as phishing, malware, or a threat. Our tool queries Google Web Risk, VirusTotal, and URLhaus in parallel to give you a clear verdict with a risk score.

Enter a URL, domain name, or IP address to check if it's flagged as phishing or malware.

Monitor your URLs around the clock

Get an alert the moment an endpoint goes down. Scheduled HTTP checks, latency history and email notifications included.

Set up an uptime monitor

Key features

3 threat intelligence sources

Simultaneous queries to Google Web Risk, VirusTotal, and URLhaus (abuse.ch). Each source covers a different angle: Web Risk and VirusTotal for phishing, URLhaus for malware distribution.

Risk score 0-100

A confidence score, not a sum of points. One authoritative source that confirms the threat is enough for a high score; agreement between sources pushes it to critical. Risk level ranges from None to Critical.

URL, domain, or IP address

Check a full URL, bare domain name, or IP address. The tool automatically normalizes the input and queries compatible sources.

Detailed results per source

View each source's verdict individually: status, threat types, response time, and reference link. Identify which database flagged the URL.

Diagnostics and coverage

Precise diagnostics inform you if a source is unavailable, timed out, or if coverage is limited. Full transparency on result reliability.

Why check suspicious URLs?

Phishing is the top cyber attack vector worldwide. In 2024, the Anti-Phishing Working Group (APWG) recorded over 4.7 million phishing attacks, a record. Each attack starts the same way: a link that looks legitimate but leads to a credential-harvesting page.

One click is enough. The FBI's IC3 estimates phishing caused over $2.9 billion in losses in 2023 alone. Attackers clone bank login pages, cloud service portals, and delivery tracking sites with pixel-perfect accuracy.

Three reasons to check a link before clicking:

  • Personal protection: A single phishing link can expose passwords, credit card numbers, and two-factor codes in seconds
  • Organizational protection: 74% of data breaches involve a human element, often a clicked phishing link (Verizon DBIR 2024)
  • Proactive verification: Site owners should regularly verify their domain isn't falsely flagged, which blocks visitors and damages reputation

How to use the phishing URL checker in 3 steps

Step 1: enter the suspicious URL

Paste the suspicious link into the input field. The tool accepts three formats:

  • Full URL: https://suspicious-site.com/login
  • Bare domain: suspicious-site.com
  • IP address: 192.168.1.1

The input is normalized automatically: whitespace stripped, converted to lowercase, URL fragments removed. No data is stored after the check.

Step 2: launch the check

Click Check. The tool queries 3 threat intelligence sources simultaneously, each with its own timeout. Results typically return in under 3 seconds.

Step 3: review the report

The report displays:

  • Global verdict: Safe, Suspicious, or Malicious
  • Risk score: From 0 (no risk) to 100 (critical)
  • Per-source details: Status, threat types, response time
  • Diagnostics: Errors, warnings, and coverage information

How do threat intelligence databases work?

Threat intelligence databases collect and classify malicious URLs through four channels: user reports, automated sandbox analysis, honeypot networks, and partnerships with security vendors. No single database catches everything. Combining multiple sources dramatically increases detection rates.

SourceWhat it coversAccepted inputStrength
Google Web RiskSocial engineering (phishing), malware, unwanted softwareURL, domainThe very lists that trigger Chrome, Firefox, and Safari warnings
VirusTotalAggregate of 70+ engines and URL reputation servicesURL, domainA multi-engine consensus rather than one vendor's opinion
URLhaus (abuse.ch)Malware distribution only, never phishingURL, domain, IP addressThe only source that accepts an IP address. Local index refreshed every 10 minutes

The three sources do not look at the same thing, which is exactly why they are queried together. Google Web Risk and VirusTotal cover phishing; URLhaus only lists URLs that serve a malicious file. Practical consequence: a "clean" from URLhaus says nothing about phishing, only that the URL is not known for distributing malware.

PhishTank, long cited as the community reference for phishing (human review through the OpenDNS community), has closed its submissions. Analysis now focuses on the three most reliable, actively maintained feeds.

How the risk score is calculated

The risk score is not a sum of points. It is a confidence level anchored by the verdict, then refined by how many sources agree. A single authoritative source is enough for a high score; we do not dilute confidence by adding up partial weights.

VerdictSources reactingRisk scoreLevel
SafeNone flags the target0None
SuspiciousOne weak signal (VirusTotal below the threshold, or Google Web Risk extended coverage)~35Medium
MaliciousOne authoritative source confirms (Google Web Risk, URLhaus, or VirusTotal with several engines)~75High
MaliciousTwo sources agree~90Critical
MaliciousAll three sources agree100Critical

The key idea: one authoritative source, such as Google Web Risk, is enough to reach a high score on its own. Adding a second concordant source raises confidence to critical. A lone VirusTotal detection with only one or two engines is treated as a likely false positive (Suspicious, around 35), not a confirmed threat.

Real-world use cases

Case 1: banking phishing email

Scenario: An email arrives from "your bank" with urgent language, "Verify your account immediately or it will be suspended." The sender address looks almost right.

What the tool reveals: Paste the URL into the checker. Google Web Risk confirming on its own is enough to reach a high score (around 75). With VirusTotal also flagging it, two sources agree and the score climbs to critical (around 90). Threat types display as "phishing" and "social_engineering."

What to do: Do not click the link. Report the email as phishing to your provider. Navigate to your bank's website by typing the address directly in your browser. Banks never ask for credentials via email. If you already clicked, change your password immediately.

Scenario: You receive an SMS: "Your package could not be delivered. Update your information: bit.ly/xyz." Package delivery scams are among the fastest-growing phishing categories. APWG reports a 40% increase since 2022.

What the tool reveals: First, expand the shortened URL using an unshortener service to reveal the final destination. Then paste that destination into the checker.

What to do: If the final URL is flagged, delete the text immediately. Legitimate delivery services never request payment or personal data via SMS links.

Case 3: false positive on your domain

Scenario: Visitors report that their browser warns them your site is dangerous. You've checked your code, and nothing malicious exists. False positives happen: Google Web Risk flags roughly 0.1% of safe sites at any given time.

What the tool reveals: Enter your domain to identify exactly which source flags it. Click the source's reference link to see the specific reason.

What to do: Submit a delisting request to the flagging source (Google has a dedicated review form). Also run a security scan on your server to rule out injected scripts, hidden redirects, or compromised plugins.

FAQ - Frequently asked questions

Q: How do I check if a link is phishing?

A: Paste the URL into the input field and click Check. The tool queries Google Web Risk, VirusTotal, and URLhaus simultaneously. Within seconds, you get a verdict (Safe, Suspicious, Malicious) and a risk score from 0 to 100.

Q: What data sources power this tool?

A: Three complementary threat intelligence feeds. Google Web Risk covers social engineering, malware and unwanted software, from the lists that trigger browser warnings. VirusTotal aggregates results from 70+ antivirus engines into a single scan. URLhaus (abuse.ch) covers malware distribution only, never phishing, and is the only source that accepts an IP address. PhishTank, once a community-verified phishing source, has closed its submissions and is no longer among the queried feeds.

Q: Is the result 100% reliable?

A: No phishing detection tool achieves 100% accuracy. A "Safe" verdict means no source currently flags the URL. It does not guarantee safety. Newly created phishing pages take minutes to hours before any database detects them. Always combine tool results with common sense: check the sender, inspect the domain spelling, and avoid entering credentials on unfamiliar pages.

Q: Can I check a domain without a full URL?

A: Yes. Enter a bare domain (e.g., captaindns.com) or an IP address (e.g., 203.0.113.34). The tool detects the input type automatically and queries every compatible source.

Q: What does the risk score mean?

A: The score is a confidence level, not a sum of points. Safe is 0. A single weak signal (Suspicious) sits around 35. One authoritative source confirming a threat scores around 75 (high), two agreeing sources reach 90, and all three reach 100 (critical). A score above 85 means several sources agree.

Protect yourself now

Received a suspicious link? Paste it above and get a verdict in seconds. Bookmark this page for quick access the next time an email or text message looks off. Share it with colleagues. Most phishing succeeds because the recipient had no easy way to verify the link before clicking.

ToolPurpose
IP Blacklist CheckerCheck if your IP is listed on email blacklists
Domain Blacklist CheckerCheck if your domain is blacklisted
Mail Header AnalysisAnalyze headers of a suspicious email to trace its origin
Redirect CheckerAnalyze redirect chains and unshorten links
Page Crawl CheckerAnalyze crawl behavior of a web page
HTTP Headers CheckerAudit security headers (CSP, HSTS, X-Frame-Options) with an A to F grade

Useful resources