Free tool · website & link safety
Scam URL Checker
Unsure about a website or a link you were sent? Scammers hide phishing pages, fake shops, and lookalike domains behind ordinary-looking addresses. Learn how to spot a scam site — and paste any suspicious link below to check its structure for the tricks scammers use.
100% private. The link is analyzed entirely in your browser. We never open it, send it anywhere, or store it.
What Is a Scam URL?
A scam URL is a web address built to take your money or your details while looking legitimate. The link might arrive in a text, an email, an ad, or a QR code — and the page it opens is designed to feel familiar so you don’t look too closely at the address.
It usually takes one of three forms: a phishing page that copies a real login or bank site to harvest your password; a fake shop that takes payment for goods that never arrive; or a lookalike or typo-squat domain — an address one or two characters off a brand you trust (“amaz0n.com”, “paypa1-secure.xyz”) that hopes you won’t notice the difference.
How to Spot a Scam Website
No single sign is proof on its own, but the more of these that stack up, the more careful you should be:
A misspelled or lookalike domain
The web address is almost right but not quite — “amaz0n.com”, “paypa1.com”, or a familiar brand name buried in a longer address. Read the domain letter by letter.
http instead of https
A page asking for a login or payment over plain “http” isn’t encrypted. Real checkout and sign-in pages use “https”.
An odd domain ending
Endings like .xyz, .top, .click, or .zip are cheap and disproportionately used for throwaway scam sites. A big brand won’t ask you to log in on one.
The “@” trick
Anything before an “@” in a link is ignored by your browser — the real destination is the part after it. Scammers use this to make a link look like it points somewhere trusted.
Pressure to log in or pay right now
“Your account will be closed”, “confirm your details to avoid a fine”. Urgency is designed to stop you checking the address.
Deals that are too good to be true
A luxury item at 80% off, or a “giveaway” that only needs your card for “shipping”. Fake shops rely on a bargain overriding your caution.
No real contact details
No phone number, no physical address, no company registration — or a contact page that only leads to a web form. Genuine sellers are easy to reach.
Check a URL
Paste a website address or any suspicious link and we’ll check its structure for the tricks scammers use.
Analyzed in your browser. We never open, send, or store the link — the check happens entirely on your device.
Paste a link above to check it
This checks the link's structure for common scam tricks — it isn't a live malware database, so a clean result isn't a guarantee. When in doubt, don't open it.
If You Already Entered Details
If you typed a password, card number, or personal details into a page you now suspect, move fast — the sooner you act, the better your chance of limiting the damage.
- 1
Contact your bank or card issuer immediately and ask them to freeze, dispute, or recall the payment. Paid by card? Request a chargeback. In India, call 1930 and tell your bank and UPI app to block further transactions.
- 2
If you entered a password or login, change it now — and anywhere you reused it — and turn on two-factor authentication. If you shared card details, have the card blocked and reissued.
- 3
Report it — here’s who to contact wherever you live.
- 4
Ignore anyone who offers to “recover” your money for a fee — that’s a second scam. See how to get your money back after a scam.
Frequently Asked Questions
What does this URL checker actually check?
It inspects the structure of a web address for the tricks scammers use — lookalike and typo-squat domains, brand names hidden in subdomains, the “@” credential trick, punycode characters that imitate real letters, raw IP-address hosts, unencrypted “http”, unusual domain endings, and URL shorteners that hide the true destination.
Is the link I paste sent anywhere?
No. The checks run entirely in your browser using built-in heuristics. The link is never opened, transmitted, stored, or logged.
It says “looks ordinary” — is the site definitely safe?
No. This tool catches common structural tricks, but it isn’t a live malware or reputation database, so a clean result isn’t a guarantee. Treat any link that arrived unexpectedly with caution, and reach websites by typing the address yourself.
What makes a URL look like a scam?
The most common signs are a misspelled or lookalike domain, a brand name that appears in the address but isn’t the registered domain, plain “http” on a login or payment page, an unusual ending like .xyz or .top, the “@” trick, and shorteners that hide where the link really goes.
What should I do if I already entered card or login details?
Act fast. Contact your bank or card issuer to freeze or dispute the payment, change any password you entered and turn on two-factor authentication, and report it. See our guide on getting your money back after a scam, and who to report to wherever you live.
Last reviewed: August 2026
Keep Going
Checking a QR code instead, or want the rest of our free tools?