Phishing

Phishing Detection Tool

Paste a suspicious link to see common phishing signals — reputation, HTTPS, weak headers, and lookalike traits — before you ever click.

How to read the results

Safe

No issues detected across the checks we ran. You can typically proceed normally.

Warning

Something looks off. Verify additional details before sharing data or making payments.

Flagged

Strong signals of risk. Avoid interacting until the issue is investigated and resolved.

What this tool does

We combine reputation feeds with live host inspection: HTTPS enforcement, security headers, and certificate signals. No single signal is conclusive, so we show all of them.

For maximum confidence, follow with WHOIS and DNS checks to verify when and how the domain was set up.

When to use it

  • An email asks you to log in via an unfamiliar URL
  • A short link hides the destination
  • A 'support' page asks for credentials or seed phrases
  • Verifying a payment or shipping confirmation page

Protect your brand from lookalikes

Check your own domains and watch for impersonators.

Set up monitoring

Continuous monitoring keeps results accurate over time. Track multiple domains and get alerts on changes.

Key terms, defined

Phishing
Fraudulent impersonation of a trusted entity, typically via email or a lookalike website, designed to capture credentials or payment data.
Spear phishing
Targeted phishing tailored to a specific person or organization using prior research (job title, vendor names, recent transactions).
Smishing
Phishing delivered over SMS or messaging apps, often combined with urgent payment or shipping pretexts.
Homograph attack
Domain abuse that swaps visually similar characters — including Unicode lookalikes — to impersonate a brand name in the URL bar.
Typosquatting
Registering misspellings of popular domains to intercept mistyped traffic.
Phishing kit
Pre-built bundle of HTML, scripts, and credential-exfiltration logic that lets low-skill attackers spin up convincing fake login pages in minutes.
Credential harvesting
The end goal of most phishing pages: capturing username, password, and any second factor for resale or direct account takeover.
Two-factor authentication (2FA)
Defense layer that requires a second proof of identity (TOTP app, security key) beyond the password. Phishing kits increasingly proxy 2FA in real time, so phishing-resistant factors (passkeys, WebAuthn) are preferred.

Frequently asked questions

Phishing, lookalike domains, and credential harvesting — the cybersecurity vocabulary search engines and answer engines use to classify this topic.

What is phishing?+

Phishing is a social-engineering attack where an attacker impersonates a trusted brand — usually over email, SMS, or a fake website — to trick victims into entering credentials, payment data, or one-time passcodes. The lure looks legitimate; the destination is attacker-controlled.

What is a lookalike domain?+

A lookalike (or homograph) domain is a registered name visually similar to a legitimate one: paypa1.com vs paypal.com, micros0ft.com, or Cyrillic-letter swaps like раypal.com. Lookalikes are the backbone of phishing campaigns and brand impersonation.

How does HTTPS relate to phishing?+

HTTPS proves the connection is encrypted, not that the site is honest. Modern phishing kits ship with free TLS certificates from Let's Encrypt by default. Treat the padlock as table stakes, not proof of safety — always verify the registered domain.

What is typosquatting?+

Typosquatting registers domains that exploit common typos of well-known brands (e.g. gogle.com, amazom.com). When a user mis-types, traffic lands on the squatter's page, which may serve malware, scams, or affiliate-stuffed redirects.

How can I verify a suspicious link without clicking?+

Hover to inspect the real URL, expand short links with a previewer, run the destination through a phishing checker, then verify the domain's WHOIS age and SSL issuer. Brand-new domains, generic-rDNS hosts, and missing security headers are strong negative signals.

What signals does this tool combine?+

Reputation feeds (DNSBLs and security vendors), HTTPS enforcement, security-header posture (HSTS, CSP, X-Frame-Options), certificate issuer, and domain-trust signals. No single signal is conclusive — the tool shows all of them so you can decide transparently.