url threat scanner

PhishFlag

Detect phishing, malware, and unsafe links before you click.

›

6 threat feeds · 20+ heuristics · certificate + redirect analysis · nothing executed

How a scan works

Every link runs through the same six-stage pipeline. The order matters: nothing reaches the network until the URL has been validated and guarded.

01

Validate

The link is normalized and strictly validated. Dangerous schemes and internal addresses are rejected before anything touches the network.

02

Dissect

20+ structure heuristics inspect the URL itself: punycode homographs, brand misspellings, shorteners, IP hosts, credential-bait keywords.

03

Probe

DNS, MX and nameserver records, the TLS certificate, HTTP headers, and the full redirect chain are checked — each hop re-guarded against SSRF.

04

Read

Up to 200 KB of raw HTML is read for login forms, cross-domain form actions, iframes and obfuscated script patterns. No JavaScript is ever executed.

05

Cross-check

Six independent threat intelligence feeds are queried in parallel and their verdicts normalized.

06

Score

Every signal feeds a weighted model that produces a 0–100 risk score, a verdict, and a plain-English explanation of why.

Cross-checked against six threat feeds

No single source is trusted alone. Each feed is queried independently; missing or rate-limited sources are reported as such, never faked.

Google Safe Browsing

Phishing & malware URL blocklist

VirusTotal

70+ antivirus engine verdicts

PhishTank

Community-verified phishing reports

URLhaus

abuse.ch malware distribution URLs

urlscan.io

Sandboxed page scan verdicts

AbuseIPDB

Hosting IP abuse reputation

Field notes: spotting phish yourself

Scanners help, but the last line of defense is the person holding the mouse.

Check the domain, not the page

A perfect copy of a login page proves nothing. paypal.com-secure-login.top is not PayPal — read the domain right-to-left.

Urgency is the tell

“Your account will be suspended in 24 hours” exists to stop you from thinking. Slow down exactly when a message tells you to hurry.

Go direct instead of clicking

If your bank emails you a link, don't use it. Type the address yourself or use your bookmark — it costs ten seconds.

A padlock only means encryption

HTTPS proves the connection is private, not that the site is honest. Most phishing sites use valid certificates now.

Unexpected attachment? Verify out-of-band

Confirm through a second channel (a phone call, a known-good address) before opening files or entering credentials.

Use a password manager

It will refuse to autofill your real credentials on a look-alike domain — an automatic homograph detector you already own.