
Not sure about a link? See where it really leads and whether it's pretending to be a site you trust, without clicking it.
Paste a link from an email, text or DM. It's checked for common phishing tricks, and its redirects are followed on this server so you can see where it really goes without opening it.
Check the real domain, the part just before the first single slash. Watch for misspellings or swapped characters (paypa1.com), a brand name used as a subdomain of another domain (paypal.com.secure-login.xyz), raw IP addresses, and text before an @ sign, which browsers ignore.
Yes. The link is never opened in your browser. This site's server follows its redirects and reads only the response headers, then shows you where it leads. Redirects done by scripts inside the page can't be seen without opening it.
A domain registered to imitate a real one by swapping similar characters, such as 0 for o, 1 for l or rn for m, or by adding words like 'secure' or 'login'. They're used to trick people into entering passwords on fake sites.
No. It means none of the common phishing patterns were spotted. New scam sites can look clean, so never enter passwords or payment details on a page you reached from an unexpected message.