Free & Instant

Detect phishing before it catches you

Paste a suspicious URL or email headers for instant analysis. 7+ security checks, zero sign-up, completely free.

Paste any URL. We analyze it in real-time without visiting from your device.
Enter the fields from your email client's "Show Original" / "View Headers" view.
We send a k-anonymity hash prefix to HIBP. Your full email never leaves this page.
Scans 8 brokers (~20 seconds). We don't store any personal information.

How It Works

Comprehensive phishing detection in seconds

Step 1
🔍

Paste It

Enter a suspicious URL or email header details. Nothing is sent from your device to the target.

Step 2
🔬

We Analyze

Our servers run 7+ checks: DNS, TLS certificates, content scanning, domain age, threat intel, and more.

Step 3
🛡

Get Results

See a clear 0-100 risk score with a detailed breakdown of every signal we found.

What We Check

Every scan runs these security checks automatically

🔗

URL Decomposition

Scheme, domain, path, params. Flags suspicious TLDs, IP addresses, and homograph attacks.

🌐

DNS Resolution

Resolves A/AAAA records, identifies hosting providers, checks reverse DNS.

🔒

TLS Certificate

Validates certificates. Flags expired, self-signed, and mismatched certs.

🔁

HTTP Response

Follows redirect chains, audits 7 security headers, captures status codes.

📄

Content Scan

Regex scan for password fields, external forms, executable links, obfuscated JS, urgency language.

📋

Domain Registration

RDAP lookup for registrar, creation date, and domain age. New domains are high risk.

🚨

Threat Intelligence

Cross-references VirusTotal and Google Safe Browsing databases.

Email Authentication

SPF, DMARC, and MX record validation. Header consistency and spoofing detection.

🔒

Breach Check (Pwned)

Checks emails against Have I Been Pwned for data breaches and paste exposures. See exactly what was leaked.

👁

Data Broker Opt-Out

Scans 8 data broker sites for your personal info. Step-by-step removal instructions with direct opt-out links.