URL Security Checker

Instant URL security, phishing, typosquatting & HTTP headers analysis.

Tool interface

Security Score
-- / 100 点
待機中

Enter a URL and click Run Security Check.

Metrics Breakdown

Encryption & Protocol --%
Domain & File Safety --%
0 正常
0 注意
0 危険

Detailed Security Breakdown

13 Items

セキュリティ診断実行待ち

上の「セキュリティ診断を実行」ボタンを押すと結果が表示されます。

What Risks This Tool Uncovers

URLを入力するだけで、フィッシング詐欺・マルウェア感染・偽装ドメインなどの【具体的な危険性】を以下の16項目で即座に見抜きます。

🌐 DNS実在性 & 名前解決

わかる危険性: 存在しない偽ドメインや、閲覧者のPCを内部ネットワークへ不正接続させる「SSRF攻撃」のリスクがわかります。

📅 ドメイン登録年齢 & WHOIS

わかる危険性: 取得直後(30日未満)の使い捨てドメインかどうか判明。(フィッシング詐欺サイトの8割は取得間もない超新規ドメインです)

📩 メール送信者認証 (SPF / DMARC)

わかる危険性: フィッシングメールの送信元として悪用される「メール成りすまし対策(DMARC/SPFレコード)」の未設定リスクがわかります。

✉️ メールサーバー基盤 (MXレコード)

わかる危険性: 通常の企業で必須となるメール受信用サーバー(MX)が存在しない「Web画面だけの捨て置き詐欺サイト」のリスクがわかります。

🔒 SSL/TLS証明書CTログ

わかる危険性: 無料証明書を悪用して鍵マークを偽装している「オレオレ安全サイト」や、ログに記録のない不審サイトが見抜けます。

📍 サーバー物理位置 & 運営事業者

わかる危険性: 「日本の銀行や大手企業」を名乗っているのに、サーバーが海外のサイバー犯罪多発地域に置かれている「所在地偽装」がわかります。

🎭 偽装ドメイン (タイポスクワッティング)

わかる危険性: `g00gle.com` や `paypa1.com` のように1文字だけ変えてパスワードやクレカ情報を盗む「なりすましフィッシング詐欺」がわかります。

🏷️ 多段サブドメインブランド偽装

わかる危険性: `paypal.com.attacker-site.net` のように無料サーバーのサブドメイン部分に大手ブランド名を埋め込む偽装工作を見抜きます。

🔀 オープンリダイレクト & 転送パラメータ

わかる危険性: URL内の `?redirect=` パラメータを悪用し、アクセス者を裏で別の危険な詐欺ページへ強制連行する脆弱性を検知します。

⚠️ 危険ファイル・マルウェア直リンク

わかる危険性: 開いた瞬間にウイルスやランサムウェア(.exe, .vbs等)が勝手にダウンロードされPCが乗っ取られる危険性がわかります。

🔐 通信暗号化 (HTTPS/SSL)

わかる危険性: 平文HTTP通信により、Wi-Fiなどで入力したパスワードや個人情報が第三者に横から盗聴・盗み見られるリスクがわかります。

🎯 IPアドレス直接指定

わかる危険性: ドメインを取得せず数字のIPアドレス(192.x.x.x)を直打ちしている、足がつきやすい「違法フィッシングサーバー」のリスクがわかります。

👤 資格情報埋め込み (Basic認証詐欺)

わかる危険性: `user:pass@` をURLに忍ばせ、ブラウザの表示を本物のログイン画面に見せかける「URL偽装トラップ」の危険性がわかります。

🔤 Punycode (ホモグラフ文字攻撃)

わかる危険性: 見た目が本物そっくりな海外の似通ったアルファベット(`xn--`)を使って偽サイトへ飛ばす「ホモグラフ騙し攻撃」がわかります。

🔗 短縮URL (転送先隠蔽)

わかる危険性: `bit.ly` などで本物の移動先リンクを隠し、裏でコッソリ危険なウイルスサイトへ強制ジャンプさせる罠が見抜けます。

🔌 非標準ポートの指定

わかる危険性: Web通常の80/443番以外の不審な裏ポート(:8080, :22等)へアクセスさせ、ハッキングされたサーバーへ引きずり込む危険性がわかります。

Usage

  1. Enter the URL you wish to check (e.g. https://example.com)
  2. Click the 'Run Security Check' button
  3. Review the safety score, protocol, domain typosquatting analysis, and HTTP headers

When to use

Checking suspicious links from emails or social media before opening, inspecting site security headers, and detecting typosquatting spoofed domains.

Examples

https://example.com → Score 95 (Rank S/Safe), http://192.168.1.1 → Score 40 (Rank D/Risk)

FAQ

What security risks does this tool check?

Checks HTTPS encryption, direct IP address phishing patterns, typosquatting spoofed domains, embedded user credentials, shortened URL risks, and security headers.

Is my input URL sent to any server?

No. Structural analysis and scoring are processed 100% locally inside your browser.

Is URL Security Checker free?

Free to use, no sign-up required.

Is data sent to a server?

Input is processed locally in your browser—nothing is sent to our servers.

Supported browsers?

Tested on recent Chrome, Edge, Firefox, and Safari.

Offline use?

Core features work offline after the first load.

vs CLI or desktop apps?

URL Security Checker is an install-free online alternative to CLI or desktop apps.

When to use it?

Use it when: Checking suspicious links from emails or social media before opening, inspecting site security headers, and detecting typosquatting spoofed domains.

Usage example?

Example: https://example.com → Score 95 (Rank S/Safe), http://192.168.1.1 → Score 40 (Rank D/Risk)

Main features?

Overall Security Score & Rank, Typosquatting & Homograph detection, HTTPS & raw IP address verification, URL shortener detection, Integrated lookup links for VirusTotal & Safe Browsing

How is this different from similar tools?

URL Security Checker runs in the browser with no install—ideal for quick checks before heavier CLI or IDE workflows.

Search keywords

URL, security, phishing, malware, typosquatting, safe check

Basic workflow

  1. Enter the URL you wish to check (e.g. https://example.com)
  2. Click the 'Run Security Check' button
  3. Review the safety score, protocol, domain typosquatting analysis, and HTTP headers

Practical use cases

  • Checking suspicious links from emails or social media before opening, inspecting site security headers, and detecting typosquatting spoofed domains.
  • An online security analysis tool that multi-dimensionally checks URL protocol encryption, typosquatting spoofed domains, URL shorteners, and HTTP headers in real time. Offers direct integrated lookups with Google Safe Browsing and VirusTotal.
  • Overall Security Score & Rank
  • Typosquatting & Homograph detection

Privacy & data handling

Input is processed locally in your browser—nothing is sent to our servers.

Things to watch out for

  • Treat URL Security Checker as a quick check — re-verify critical values in your editor or CI before shipping.
  • This tool runs locally: closing the tab clears unsaved input. Copy results you need to keep.
  • Very large pastes can freeze a tab briefly — wait for the result before closing the tab.

Related learning content

Related tools