Where does this link really go?
Don't click it — check it. Paste a suspicious link below and our servers follow it safely, through every redirect, to reveal the real destination and the tricks used to disguise it. Works on shortened links, QR-code links, and anything from a text or email.
🛡️ Checked from our secure servers — your device never touches the link- Follows the full redirect chain server-side — you never visit the site
- Reveals the true destination behind shorteners like bit.ly and tinyurl
- Flags lookalike domains, brand-new websites, and login-bait pages
This checker follows the link and screens its destination against known phishing patterns — it does not open or scan the page's content, and a clean result does not guarantee a link is safe. Brand-new and highly targeted scam sites can look clean. If the link arrived unexpectedly and wants you to log in, pay, or download something, verify through the company's official app or site instead. Already clicked? Use our what-to-do-now tool.
Got the whole text or email it came from? Check the full message with our free SMS scam checker or email scam checker →
The five ways scammers disguise a link
Every phishing link uses at least one of these disguises. Learn to spot them and you’ll catch most scam links before any checker does.
bit.ly/3kQz9xF
🚩 The shortener: the destination is completely hidden until you click. Shorteners are legitimate tools, but in an unexpected text or email they exist to get you past the moment of doubt. This checker expands them for you.
usps-trackhelp.com · chase-verify.info · amaz0n-billing.net
🚩 The lookalike domain: the brand's name is in the address, but it isn’t the brand’s domain. USPS lives at usps.com — anything else wearing its name is a costume.
secure-login.account-update.example-payments.info/verify
🚩 The login-bait address: words like “secure,” “verify,” and “login” stacked into the address itself. Real sign-in pages don’t need to convince you they’re a sign-in page.
A link that bounces: shortener → tracker → redirect → the real scam page
🚩 The redirect chain: each bounce is a chance to dodge a spam filter or swap the destination after the message passed inspection. Three or more redirects on an unexpected link is a serious tell.
A domain registered 6 days ago
🚩 The brand-new site: scam campaigns burn through freshly registered domains faster than blocklists can catch them. A destination registered days or weeks ago is exactly what a “new campaign” looks like — this checker looks up the registration age for you.
Next time, spot it without a checker.
ScamDrill sends safe practice scams to your family so the instinct is there before the real link arrives — with 14 days of Family features free, no card needed. Paid plans add forward-a-message checks with this same link expansion built in.
Start practicing free →Get a heads-up before the next scam reaches you
Join our free newsletter — monthly scam-trend updates and practical tips to protect yourself and the people you care about. No spam, unsubscribe anytime.
We'll only use your email to send scam alerts. See our privacy policy.