Services AI Systems & Intelligent Automation Cloud Platforms & Enterprise Architecture Cybersecurity, Identity & Governance Systems Integration & Business Automation Intelligent Web Platforms Infrastructure & Networking Managed Technology Services Case Study Industries Free tools About Contact Talk to an Architect
  1. Home
  2. Free tools
  3. Link safety check
Tool 07 · Phishing

Where does this link really go?

Paste a link from an email or message. The check follows every redirect on our servers, so your device never touches it, then looks for the things phishing links have in common: look-alike domains, a brand name in the wrong place, a domain registered last week, a page asking for a password where it should not.

The link is fetched from our servers with a read-only request and nothing is executed. A clear result is not a guarantee of safety. See the terms.

Reading the result

What the check looks for, and what it cannot tell you.

The destination, not the link

Shortened and tracked links hide where they go. The check follows up to six redirects and judges the final page. If the link changes domains along the way, that is called out, because the sender can control the first hop and hand you off anywhere.

Signs of phishing

  • Brand in the wrong place: a host that mentions Microsoft, PayPal, Australia Post, the ATO, myGov or a bank while the registered domain is something else. This is the most common pattern and the check knows the real domains for each brand.
  • Look-alike characters: punycode hosts that display as a familiar name using letters from another alphabet.
  • Bare IP addresses, credentials before an @ sign, deeply nested subdomains, risky top-level domains such as .top, .xyz or .zip.
  • A very new domain: phishing domains are usually registered days before use. Registration dates come from the registry (not available for .au).
  • A password field on a domain that does not belong to the brand it imitates, or a form that posts your details to a third domain.
  • Plain HTTP or an untrusted certificate at the destination.

Threat lists

Every URL in the chain is checked against Google Safe Browsing, the same lists Chrome and Firefox use, when that lookup is enabled. Being absent from the list means only that nobody has reported it yet; new campaigns take hours to appear.

What it cannot do

It cannot run the page, open attachments, or see content shown only after you sign in. A link can pass every check and still be a fraud, especially a genuine file-sharing link containing a malicious document. If a message asks you to sign in, pay, or change bank details, confirm it with the sender on a number you already have.

Next step

Someone clicked it?

Reset the password, revoke sessions, check sign-in logs and mail rules, and find out what else the account touched. We handle the response and then close the gap that let it through.