url threat scanner
PhishFlag
Detect phishing, malware, and unsafe links before you click.
6 threat feeds · 20+ heuristics · certificate + redirect analysis · nothing executed
How a scan works
Every link runs through the same six-stage pipeline. The order matters: nothing reaches the network until the URL has been validated and guarded.
Validate
The link is normalized and strictly validated. Dangerous schemes and internal addresses are rejected before anything touches the network.
Dissect
20+ structure heuristics inspect the URL itself: punycode homographs, brand misspellings, shorteners, IP hosts, credential-bait keywords.
Probe
DNS, MX and nameserver records, the TLS certificate, HTTP headers, and the full redirect chain are checked — each hop re-guarded against SSRF.
Read
Up to 200 KB of raw HTML is read for login forms, cross-domain form actions, iframes and obfuscated script patterns. No JavaScript is ever executed.
Cross-check
Six independent threat intelligence feeds are queried in parallel and their verdicts normalized.
Score
Every signal feeds a weighted model that produces a 0–100 risk score, a verdict, and a plain-English explanation of why.
Cross-checked against six threat feeds
No single source is trusted alone. Each feed is queried independently; missing or rate-limited sources are reported as such, never faked.
Google Safe Browsing
Phishing & malware URL blocklist
VirusTotal
70+ antivirus engine verdicts
PhishTank
Community-verified phishing reports
URLhaus
abuse.ch malware distribution URLs
urlscan.io
Sandboxed page scan verdicts
AbuseIPDB
Hosting IP abuse reputation
Field notes: spotting phish yourself
Scanners help, but the last line of defense is the person holding the mouse.
Check the domain, not the page
A perfect copy of a login page proves nothing. paypal.com-secure-login.top is not PayPal — read the domain right-to-left.
Urgency is the tell
“Your account will be suspended in 24 hours” exists to stop you from thinking. Slow down exactly when a message tells you to hurry.
Go direct instead of clicking
If your bank emails you a link, don't use it. Type the address yourself or use your bookmark — it costs ten seconds.
A padlock only means encryption
HTTPS proves the connection is private, not that the site is honest. Most phishing sites use valid certificates now.
Unexpected attachment? Verify out-of-band
Confirm through a second channel (a phone call, a known-good address) before opening files or entering credentials.
Use a password manager
It will refuse to autofill your real credentials on a look-alike domain — an automatic homograph detector you already own.