Phishing URL Detector
Analyze any URL for phishing indicators including homoglyph characters, suspicious subdomains, typosquatting, path obfuscation, encoding abuse, and open redirects. Get a detailed breakdown of the URL components, a comprehensive list of findings with severity ratings, and a 0-100 risk score. Free, private, and no signup required.
Analyze URLs for phishing indicators including homoglyph characters, suspicious subdomains, path obfuscation, encoding abuse, suspicious TLDs, typosquatting, and open redirects. Paste any URL to get a comprehensive security analysis with risk scoring.
Paste a URL above and click Analyze URL to check for phishing indicators. The tool checks for homoglyph characters, suspicious subdomains, typosquatting, path obfuscation, open redirects, and more. Try one of the example URLs to see how it works!
Features
Complete URL Parsing & Breakdown
Parses every component of the URL including protocol, subdomain, domain, TLD, port, path, query parameters, and fragment. See a visual breakdown of the URL structure with each part clearly labeled for easy analysis.
9 Security Check Categories
Tests URLs across 9 analysis categories: protocol security, homoglyph detection, domain analysis, subdomain nesting, path keyword scanning, encoding abuse, query parameter analysis, fragment inspection, and typosquatting detection.
Numerical Risk Scoring (0-100)
Each finding is weighted by severity (critical, high, medium, low, info) and aggregated into a 0-100 risk score with clear risk levels: Safe, Low, Medium, High, and Critical. Critical findings include bonus weighting for maximum visibility.
Brand Lookalike & Typosquatting Detection
Automatically detects homoglyph characters (Cyrillic lookalikes, Unicode tricks), brand impersonation attempts, and typosquatting via Levenshtein distance comparison against 30+ well-known domains.
Use Cases
Email Link Safety Verification
Paste suspicious links from emails before clicking. Many phishing attacks use obfuscated URLs that look legitimate at first glance but redirect to malicious sites. Verify link safety before interacting with any email link.
Security Awareness Training
Use real-world examples to teach users how to identify phishing URLs. Demonstrate homoglyph attacks, typosquatting, and URL obfuscation techniques in security training sessions. Show the risk score in action.
Bug Bounty & Pentesting
Quickly analyze URLs discovered during security assessments. Identify open redirects, URL-based vulnerabilities, and obfuscation techniques used by attackers. Document findings with the detailed analysis report.
Social Media Link Screening
Check shortened and obfuscated URLs shared on social media platforms before visiting. Phishers often use URL shorteners combined with redirect chains to hide the true destination from casual inspection.
Website Security Monitoring
Regularly scan your own website URLs for indicators that might be abused by attackers. Check for suspicious parameters, open redirect vulnerabilities, and encoded paths that could be exploited in phishing campaigns.
Incident Response Investigation
Analyze suspicious URLs found in security logs, DNS queries, and proxy logs during incident response. Quickly assess whether a URL is malicious and document the technical indicators for threat intelligence sharing.
About Phishing URL Detection
What Is a Phishing URL?
A phishing URL is a web address designed to deceive users into believing they are visiting a legitimate website when they are actually being directed to a malicious one. Phishers use various techniques including homoglyph characters (using lookalike Unicode characters from different scripts), typosquatting(registering domains with common misspellings like "gooogle.com"), subdomain deception(using subdomains to impersonate brands like "login.apple.com.evil.com"), and encoding abuse (using percent- encoding and double encoding to hide the true path or parameters). Phishing URLs are the primary delivery mechanism for credential theft, malware distribution, and financial fraud.
How Our Detector Works
The detector parses the URL into individual components and runs each component through specialized analysis modules. The domain analysis module checks for homoglyph characters, punycode domains, IP address usage, and suspicious TLDs. Thesubdomain analysis module evaluates nesting depth and detects misleading brand-related subdomain names. The path analysis module scans for suspicious keywords and encoded patterns. The query analysis module identifies potential open redirects. Each finding is assigned a severity level and contributes to the overall risk score, which is calculated using weighted severity values and capped at 100 for consistent rating.
Common Phishing Techniques Detected
The tool detects: Homoglyph attackswhere Cyrillic, Greek, or other Unicode characters visually resemble ASCII letters (e.g., Cyrillic "а" instead of Latin "a"). IDN homograph attacks using Punycode-encoded internationalized domain names. URL-based obfuscation including credential embedding (user@host), excessive encoding, and double encoding. Redirect-based phishing using open redirect parameters to bounce victims to malicious sites. Brand impersonation via typosquatting and lookalike domains. Suspicious TLD abuse using high-risk TLDs commonly associated with spam and phishing.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. The URLs you analyze, the parsing results, and the risk scores are never uploaded to any server, stored in any database, or transmitted over the network. All analysis, homoglyph detection, domain comparison, and risk calculation happens locally on your device. There are no API calls, no remote lookups, no analytics tracking, and no data collection of any kind. This makes it completely safe for analyzing suspicious or sensitive URLs without exposing them to any third party.