Phishing URL Checker
Paste any link before you click it. Scans for IP-literal hosts, punycode lookalikes, brand impersonation, link shorteners, and other common phishing patterns.
How to Spot a Phishing Link Yourself
The single most reliable check: hover over (don't click) any link and look at the actual destination shown in your browser or email client's status bar. Phishing links almost always reveal themselves here — a domain that doesn't match the company it claims to be from, an IP address, or a string of random characters before the real domain.
Attackers exploit the fact that most people read a URL left to right and stop at the first familiar word. paypal.com.security-verify.xyz is not a PayPal domain — the part that matters is the last two segments before the path (security-verify.xyz), not whatever comes before it.
If You Already Clicked
Don't enter any credentials on the page. If you already did, change that password immediately (use our Password Generator for the replacement) and check whether it's appeared in a breach with our Leaked Password Checker. If it was a work account, report it to your IT/security contact right away — early reporting is what limits the damage.