Resources / Phishing Link Checker

Where does this link really go?

Don't click it — check it. Paste a suspicious link below and our servers follow it safely, through every redirect, to reveal the real destination and the tricks used to disguise it. Works on shortened links, QR-code links, and anything from a text or email.

🛡️ Checked from our secure servers — your device never touches the link
Tip: press-and-hold (phone) or hover (computer) to copy a link without opening it. On a QR code, most camera apps let you copy the link instead of opening it.
Paste the link first — it should look like a web address.
Following the link safely from our servers…

This checker follows the link and screens its destination against known phishing patterns — it does not open or scan the page's content, and a clean result does not guarantee a link is safe. Brand-new and highly targeted scam sites can look clean. If the link arrived unexpectedly and wants you to log in, pay, or download something, verify through the company's official app or site instead. Already clicked? Use our what-to-do-now tool.

Got the whole text or email it came from? Check the full message with our free SMS scam checker or email scam checker

The five ways scammers disguise a link

Every phishing link uses at least one of these disguises. Learn to spot them and you’ll catch most scam links before any checker does.

bit.ly/3kQz9xF

🚩 The shortener: the destination is completely hidden until you click. Shorteners are legitimate tools, but in an unexpected text or email they exist to get you past the moment of doubt. This checker expands them for you.

usps-trackhelp.com  ·  chase-verify.info  ·  amaz0n-billing.net

🚩 The lookalike domain: the brand's name is in the address, but it isn’t the brand’s domain. USPS lives at usps.com — anything else wearing its name is a costume.

secure-login.account-update.example-payments.info/verify

🚩 The login-bait address: words like “secure,” “verify,” and “login” stacked into the address itself. Real sign-in pages don’t need to convince you they’re a sign-in page.

A link that bounces: shortener → tracker → redirect → the real scam page

🚩 The redirect chain: each bounce is a chance to dodge a spam filter or swap the destination after the message passed inspection. Three or more redirects on an unexpected link is a serious tell.

A domain registered 6 days ago

🚩 The brand-new site: scam campaigns burn through freshly registered domains faster than blocklists can catch them. A destination registered days or weeks ago is exactly what a “new campaign” looks like — this checker looks up the registration age for you.

Next time, spot it without a checker.

ScamDrill sends safe practice scams to your family so the instinct is there before the real link arrives — with 14 days of Family features free, no card needed. Paid plans add forward-a-message checks with this same link expansion built in.

Start practicing free →
Checking this at work? ScamDrill for organizations tests your whole team with safe phishing drills — before a real link does.

Get a heads-up before the next scam reaches you

Join our free newsletter — monthly scam-trend updates and practical tips to protect yourself and the people you care about. No spam, unsubscribe anytime.

We'll only use your email to send scam alerts. See our privacy policy.

Link safety questions, answered

How can I check if a link is safe without clicking it?
Never open a suspicious link to find out where it goes. Paste it into the checker above instead — our servers follow the full redirect chain, reveal the real destination, and flag lookalike domains, brand-new websites, and login-bait pages. Your device never connects to the site. For the patterns themselves, see how to spot common scams.
Is it safe to paste a link into this checker?
Yes. The link — and nothing else — is sent to ScamDrill's servers, which follow it in a controlled environment so your phone or computer never touches the site. We don't keep a record of the links you check.
Why do scammers use shortened links?
Shorteners like bit.ly hide the real destination, which helps a scam link slip past spam filters and your own judgment. A shortened link isn't automatically a scam — marketers use them too — but an unexpected shortened link deserves a check before you tap. The scam glossary covers the related terms.
What about QR codes?
A QR code is just a link wearing a disguise — "quishing" scams put malicious QR codes on parking meters, restaurant tables, and fake delivery notices. Most phone cameras let you copy the link a QR code contains instead of opening it: do that, then paste it here.
I already clicked a phishing link — what now?
Don't enter anything on the page that opened, and close it. If you typed a password, change it now from a device you trust and turn on two-factor authentication; if you entered card or banking details, call your bank. Then use our what-to-do-now tool for the full step-by-step plan.
Does a clean result mean the link is safe?
No. A clean result means none of the common phishing patterns matched — but brand-new or highly targeted scam sites can look clean. If the link arrived unexpectedly and asks you to log in, pay, or download anything, go to the company's site or app directly instead.