URL Security Checker

Instant URL security, phishing, typosquatting & HTTP headers analysis.

Data is never sent to the server. Everything runs locally in your browser. Safe for sensitive information.

About this tool

An online security analysis tool that multi-dimensionally checks URL protocol encryption, typosquatting spoofed domains, URL shorteners, and HTTP headers in real time. Offers direct integrated lookups with Google Safe Browsing and VirusTotal.

Before clicking a suspicious link from email or social media, paste the URL here. The tool scans 16 security signals—HTTPS, typosquatting, shorteners, headers—and returns a 0–100 score with rank, all processed locally in your browser.

Tool interface

Security Score
-- / 100 pts
Waiting

Enter a URL and click Run Security Check.

Metrics Breakdown

Encryption & Protocol --%
Domain & File Safety --%
0 OK
0 Caution
0 Danger

Detailed Security Breakdown

13 Items

Waiting for security scan

Press the Run Security Check button above to see the results.

What Risks This Tool Uncovers

Paste a URL and the tool instantly flags 16 concrete risks—phishing, malware, fake domains and more.

⚠️ Phishing, Malware & Virus Sites

Cross-checks against Google's public threat feed to confirm whether a site is dangerous or safe.

🌐 DNS Validity & Name Resolution

Risk detected: spoofed non-existent domains or SSRF attempts that try to route your PC to internal networks.

📅 Domain Registration Age & WHOIS

Risk detected: disposable domains registered within the last 30 days. ~80% of phishing sites are freshly registered.

📩 Sender Authentication (SPF / DMARC)

Risk detected: missing DMARC/SPF records that let attackers spoof legitimate-looking phishing emails.

✉️ Mail Server Infrastructure (MX)

Risk detected: no MX record means a throwaway 'web-page-only' scam site with no real business behind it.

🔒 SSL/TLS Certificate CT Logs

Risk detected: self-signed 'fake padlock' sites abusing free certificates, or domains absent from public CT logs.

📍 Server Location & Hosting Operator

Risk detected: sites posing as Japanese banks or major companies while hosted in high-crime hosting regions.

🎭 Spoofed Domains (Typosquatting)

Risk detected: one-character tricks like `g00gle.com` or `paypa1.com` that steal passwords and card data.

🏷️ Multi-Level Subdomain Brand Spoofing

Risk detected: brand names embedded in free-server subdomains, e.g. `paypal.com.attacker-site.net`.

🔀 Open Redirect & Transfer Parameters

Risk detected: `?redirect=` parameters that silently forward victims to dangerous scam pages.

🔐 Connection Encryption (HTTPS/SSL)

Risk detected: plaintext HTTP lets third parties eavesdrop on passwords and personal data over Wi-Fi.

🎯 Direct IP Address

Risk detected: raw numeric IPs (192.x.x.x) instead of a domain—a common pattern for disposable phishing servers.

👤 Embedded Credentials (Basic Auth Scams)

Risk detected: hidden `user:pass@` in URLs that make the browser look like a real login page.

🔤 Punycode (Homograph Attacks)

Risk detected: lookalike international characters (`xn--`) that trick users into fake sites.

🔗 Shortened URLs (Hidden Destination)

Risk detected: `bit.ly` and similar services that hide the real destination and force-jump to malicious sites.

🔌 Non-Standard Ports

Risk detected: suspicious backdoor ports (:8080, :22) that drag users into hacked servers.

Usage

  1. Enter the URL you wish to check (e.g. https://example.com)
  2. Click the 'Run Security Check' button
  3. Review the safety score, protocol, domain typosquatting analysis, and HTTP headers

When to use

Checking suspicious links from emails or social media before opening, inspecting site security headers, and detecting typosquatting spoofed domains.

Examples

https://example.com → Score 95 (Rank S/Safe), http://192.168.1.1 → Score 40 (Rank D/Risk)

FAQ

What security risks does this tool check?

Checks HTTPS encryption, direct IP address phishing patterns, typosquatting spoofed domains, embedded user credentials, shortened URL risks, and security headers.

Is my input URL sent to any server?

No. Structural analysis and scoring are processed 100% locally inside your browser.

What is typosquatting?

A phishing technique that registers fake domains that look almost identical to well-known services (e.g. g00gle.com) to deceive users.

Is it guaranteed to be absolutely safe?

This tool makes instant judgments based on mechanical structural analysis and known threat models, but it does not guarantee 100% of all threats, including new zero-day attacks. For deeper analysis, use VirusTotal or urlscan.io via the links.

Is URL Security Checker free?

Free to use, no sign-up required.

Is data sent to a server?

Input is processed locally in your browser—nothing is sent to our servers.

Supported browsers?

Tested on recent Chrome, Edge, Firefox, and Safari.

Offline use?

Core features work offline after the first load.

vs CLI or desktop apps?

URL Security Checker is an install-free online alternative to CLI or desktop apps.

When to use it?

Use it when: Checking suspicious links from emails or social media before opening, inspecting site security headers, and detecting typosquatting spoofed domains.

Usage example?

Example: https://example.com → Score 95 (Rank S/Safe), http://192.168.1.1 → Score 40 (Rank D/Risk)

Main features?

Overall Security Score & Rank, Typosquatting & Homograph detection, HTTPS & raw IP address verification, URL shortener detection, Integrated lookup links for VirusTotal & Safe Browsing

How is this different from similar tools?

URL Security Checker runs in the browser with no install—ideal for quick checks before heavier CLI or IDE workflows.

Search keywords

URL, security, phishing, malware, typosquatting, safe check, url safety, is this link safe, phishing checker, suspicious link, malicious url, safe browsing, check url safety, url safety check, phishing link checker, typosquatting detector, malicious url scan

Basic workflow

  1. Enter the URL you wish to check (e.g. https://example.com)
  2. Click the 'Run Security Check' button
  3. Review the safety score, protocol, domain typosquatting analysis, and HTTP headers

Practical use cases

  • Checking suspicious links from emails or social media before opening, inspecting site security headers, and detecting typosquatting spoofed domains.
  • An online security analysis tool that multi-dimensionally checks URL protocol encryption, typosquatting spoofed domains, URL shorteners, and HTTP headers in real time. Offers direct integrated lookups with Google Safe Browsing and VirusTotal.
  • Overall Security Score & Rank
  • Typosquatting & Homograph detection

Privacy & data handling

Input is processed locally in your browser—nothing is sent to our servers.

Things to watch out for

  • Treat URL Security Checker as a quick check — re-verify critical values in your editor or CI before shipping.
  • This tool runs locally: closing the tab clears unsaved input. Copy results you need to keep.
  • Very large pastes can freeze a tab briefly — wait for the result before closing the tab.

Related learning content

Related tools

Tool set