URL Scanner
Check a suspicious link with VirusTotal before opening it • Coverage depends on the available providers
How to Spot a Phishing Link
Check the domain carefully
Phishing attacks rely on URLs that look legitimate at a glance. Attackers register domains like "paypa1.com" (number 1 instead of L), "amazon-support-login.com", or subdomains like "amazon.real-bank.com" — where the real domain is "real-bank.com". Always read the domain from right to left, stopping at the first slash.
HTTPS does not mean safe
A padlock icon only means the connection is encrypted — not that the site is legitimate. Phishing sites routinely use HTTPS and valid SSL certificates. A secure connection to a malicious site is still a malicious site.
Red flags to watch for
- Urgency: "Your account will be suspended", "Verify immediately"
- Shortened URLs (bit.ly, tinyurl) hiding the real destination
- Domains with extra words: "login-paypal-secure.com"
- Typosquatting: "goggle.com", "arnazon.com", "facebok.com"
- Unexpected redirects through multiple domains
- Requests for credentials or payment on unfamiliar pages
What VirusTotal detects
VirusTotal aggregates available results from antivirus engines, URL scanners and domain reputation services. Coverage and response times depend on the providers and the URL being checked. The result shows the engine reports returned by the service; a result with no detections does not prove that a link is safe.
What to do with a suspicious link
- Paste it here before clicking and review the available results
- If it came by email, check the sender's actual address (not just the display name)
- When in doubt, navigate to the site manually by typing the domain directly
- Report phishing: safebrowsing.google.com/safebrowsing/report_phish
Related tools
To analyse the wording of a suspicious message, use the Phishing Explainer. To extract and check a link from a QR code, use the QR Code Reader.