Link checker
Paste an address to see where it actually leads. The link is opened by our servers, never by your browser: you get the final destination, the domain age and its certificate without taking any risk.
What this check actually measures
Most link checkers only read the address: they spot a suspicious word, an unusual extension, an imitated brand. That helps, but a fraudster works around those rules in a minute. Here, analysing the shape of the address is only half the job. The other half queries the network for real.
- The redirect chain
- Every hop is followed one by one and displayed. A shortened link is unwrapped down to its real destination, without you ever opening it.
- DNS resolution
- Does the domain still point to a server? Many fraudulent sites are abandoned weeks after their campaign and no longer answer.
- The security certificate
- Its issuer and issue date. A three-day-old certificate on a site claiming to be your bank is a contradiction in itself.
- The domain age
- Read from the official registry (RDAP protocol), not estimated. It is the hardest signal for a fraudster to fake.
Reading a redirect chain
This is what most people are really after when they check a link: where does this actually take me? A URL shortener tells you nothing about its destination, and that is exactly why it appears in fraudulent messages.
The tool shows every step with its response code. If the chain starts on a known shortener and ends on an ordinary site, there is nothing to conclude: redirecting is what a shortener is for. What matters then is the destination, which the tool assesses on its own merits.
A link that looks like it goes to a shop or a public service but lands on a different domain is another matter. That redirect has no reason to be discreet.
What the domain age tells you
A fraud campaign needs a fresh domain name, because the previous ones end up blocked. A domain registered less than a month ago that asks you for a payment or your credentials therefore deserves particular caution, even if everything else looks normal.
The opposite does not hold. An old domain can have been bought or hacked, and used to host a collection page. Age is reassuring, it guarantees nothing.
What this tool cannot do
No automated checker replaces your own judgement, and claiming otherwise would be dishonest. Here are its concrete limits.
- It does not read the page content
- A site can be technically flawless and sell goods that never arrive. The tool measures infrastructure, not commercial honesty.
- It does not see what is reserved for victims
- Some fraudulent pages only appear after a click from a text message, or only for visitors from a given country.
- A reassuring result is not a guarantee
- No signal means nothing measurable was detected, not that the site can be trusted.
If the link looks dangerous
Do not open the page, and never enter credentials on a site reached from a message. If you already have, change the password immediately, along with that of any other account where you reused it. If you entered card details, call your bank to block the card straight away.
Report fraudulent sites to your national cybercrime service. Within the EU, most countries run a free reporting channel, and browser vendors use those reports to block sites for everyone else.
Frequently asked questions about link checking
- How can I tell whether a link is safe?
- Look first at the domain name itself, just before the first slash: it is the only part a fraudster cannot fake. Everything else in the address can contain any reassuring word. Then check where the link really redirects and how long the domain has existed. A recent domain imitating a well-known brand is the most common pattern.
- Is it dangerous to click a link just to check it?
- Yes, and it is unnecessary. Opening the page can confirm your address is active, trigger a download, or expose you to a convincing collection page. That is why this tool opens the link from our servers and reports back: you get the information without exposing your device.
- How do I see where a shortened link goes without opening it?
- Paste it in the field above. Every redirect is followed and displayed down to the final destination, with the response code of each step. You see the exact landing address before deciding anything.
- Is an HTTPS link with a padlock necessarily safe?
- No, and this is a very common misunderstanding. The padlock only means the connection is encrypted between your browser and the server. Certificates are free and issued within minutes, including to fraudulent sites. The padlock protects your data in transit, it says nothing about who receives it.
- Is a .com domain more trustworthy than another extension?
- Not in itself. Some cheap extensions are over-represented in fraud campaigns, which the analysis takes into account, but a .com is just as easy to buy. The extension is a weak clue: the domain age and the real destination carry far more weight.
- What if I already entered my details on a doubtful site?
- Act immediately. Change the password concerned, then that of every account where you reused it. If you shared banking details, contact your bank to block the card. Keep the message and the address you received: they will support your report and any complaint.
Partner links: we may earn a commission, at no extra cost to you.
Scam types
Fake bank email: spotting the booby-trapped security alert
An email imitates your bank and asks you to confirm a transaction or your details. Here is how to spot the forged sender and respond safely.
Fake parcel text scam: how to spot it and what to do
A text says a parcel is stuck and asks for a small fee. Here is how this very common scam works and the right way to respond.
Fake streaming email: the suspended account that steals your card
Payment declined, subscription suspended, card to update: this fake streaming email targets your bank details. Here is how to identify it and respond.
Fake tax refund or fine texts: do not fall for the trap
A text promises a tax refund or warns of an unpaid fine with a payment link. How to spot this scam and reach the genuine service instead.