Enter a CVE ID, IP address, Domain, Email, Phone Number, File Hash or URL to analyse.
Nothing searched yet

URL lookup

A malicious website checker for one specific web location. Use it on a suspicious link before deciding whether to block, escalate or investigate further.

What you can paste

These are format examples. Clicking one puts it in the search box — it does not run a search, so you choose when to spend a lookup.

How to run one
  1. 1Paste the URL into the box above. The type is already set to URL on this page.
  2. 2Press Analyze. If the indicator is new to the platform it is queued for enrichment, and the page holds a progress view while that runs rather than telling you to come back later.
  3. 3Read the report top-down. The verdict is the headline; the sections below it are the evidence, and the evidence is the part worth your time.
  4. 4Pivot. Almost every value in the report is itself searchable, which is how one indicator becomes an investigation.
Where to go next
  • Search the final destination host as a domain
  • Search the IP it resolves to
  • Cross-reference to find samples that used the same link
What comes back, and how to read it

These are the sections of the report, in the order you will meet them.

  1. 01Engine Detections

    Which engines flag the URL and as what. Phishing, malware delivery and scam classifications call for different responses, so read the labels, not just the count.

  2. 02Final destination and redirect chain

    Where the link actually lands, after every hop. The whole point of a malicious link is usually that it does not go where it appears to.

  3. 03Lands on a different host

    Flagged explicitly when the final host differs from the one you submitted -- the single most useful line on the page for a phishing triage.

  4. 04HTTP Response

    Status code, content type and content length. A link advertised as a document that returns an executable content type has answered your question already.