Website Safety Checker
Wondering, is this website safe? Get a transparent risk report: per-source threat results with coverage counts and a timestamp, page-behavior evidence, and instant lookalike-domain checks. No site is ever called safe on missing coverage.
Free, no signup. Do not submit private, password-reset or signed URLs to any online scanner.
What this check actually consults, and what it refuses to claim
A URL safety report is only as honest as its coverage, so this tool separates its evidence into three classes and shows the state of each:
- Threat intelligence: the URLhaus malware-distribution database (exact URL and host history) and Google Safe Browsing, when configured server-side. Each row reports match, no match, or unavailable, and the headline counts how many of these sources actually ran. URLhaus is malware-scoped; it is not a phishing feed and is labeled accordingly.
- Page behavior: a guarded server-side fetch that inspects transport security, the redirect chain, and meta-refresh tricks that send you somewhere other than the address you typed. The fetcher only speaks HTTP and HTTPS, revalidates every redirect hop, and enforces size and time limits.
- Instant browser checks: computed on your device without any request: HTTPS, the registrable domain that actually identifies the site, punycode and mixed-script lookalike labels, frequently abused TLDs, and URL shorteners.
The verdict is a fixed policy over those states, not an average: a confirmed threat match overrides everything, and a source that was unavailable is never counted as a pass. If no threat database could be consulted, the headline says coverage incomplete, because a reassuring result built on sources that did not answer would be worthless. No result from this tool ever declares a site safe.
Is this site legit? The red flags that give scam sites away
Databases catch known threats. You catch the new ones, by reading the signals scam sites cannot easily fake. These are the ones worth memorizing.
| Red flag | What it looks like | Why it matters |
|---|---|---|
| Too-new domain | Domain registered days or weeks ago | Scam sites burn through fresh domains because old ones get blacklisted. Check the registration date with a WHOIS lookup before you buy. |
| No HTTPS | Address starts with http:// or the browser shows Not Secure | Anything you type travels unencrypted. Legit sites have used HTTPS by default for years, so its absence is a loud warning. |
| Lookalike domain | paypa1.com, amaz0n-support.net, or accented letters in the name | Phishers register domains one character away from the brand they impersonate. Read the domain right to left: the part before the TLD is who you are really talking to. |
| Fake urgency | Countdown timers, "only 2 left", "your account will be closed today" | Manufactured pressure exists to stop you from checking. Real companies do not threaten you into a purchase or a login. |
| No contact page | No physical address, no phone, no legal pages, contact form only | A business you cannot reach is a business you cannot get a refund from. Missing imprint and policy pages are typical of throwaway scam sites. |
| Too-good prices | Brand products at 80 percent off, everything permanently on sale | Fake shops list dream prices to harvest card numbers. If every item undercuts every real retailer, the product does not exist. |
| Odd payment methods | Wire transfer, gift cards or crypto as the only options | These payments cannot be reversed, which is exactly why fraudsters insist on them. Card and PayPal payments give you dispute rights. |
Two of these you can verify with our other free tools right now: check the domain age with the DNS & WHOIS Lookup and expand any shortened or suspicious link with the Redirect Checker before you visit it.
Site owners: flagged somewhere? The delisting routes
Most blacklisted sites belong to honest owners who got hacked: a vulnerable plugin goes unpatched, a bot exploits it within days, and the site quietly starts hosting phishing pages or malware until Google flags it. If that is you, the order of operations matters: clean the infection first, then request review. Google warnings are handled through Search Console's Security Issues report, which includes a review-request button once the site is clean. URLhaus listings are removed via the takedown/removal process on urlhaus.abuse.ch. Re-run this check afterwards to confirm each source has cleared, and keep in mind that delisting takes hours to days after the request.
Prevention is far cheaper than delisting. Block the malicious bots probing your site for holes, and monitor your site's health so an infection or an expiring certificate is caught in hours, not weeks.
Website safety check FAQ
How do I check if a website is safe to open?
Paste the URL above and run the check. The report shows each source separately: threat databases when they are available on the server, a page-behavior fetch that inspects transport and redirects, and instant checks your own browser computes, like lookalike characters in the domain. The headline always states how many threat sources actually ran and when, so you can judge how much the result covers. Combine it with the red-flag checklist on this page before trusting a site with money or passwords.
Can a website safety checker prove a site is safe?
No, and any tool that claims it can is overselling. This checker never uses the word safe in a verdict. The best possible result reads "no known threats, with full configured coverage", which means every configured threat source ran and none had anything on the URL at that moment. Brand-new scam sites have not been reported anywhere yet, so they pass every database on day one. Treat results as observations with a timestamp, not a guarantee.
What does "coverage incomplete" mean?
It means one or more threat databases could not be consulted for your check, because a source was unavailable, timed out, or is not configured on the server right now. The tool refuses to show a clear result built on missing coverage: a source that did not run can never count as a pass. The per-source rows show exactly which databases answered and which were unavailable.
What happens to the URL I paste? Is it private?
By default the query string and fragment are removed before the URL leaves your browser, and any embedded credentials are always stripped. The preview under the input shows the exact address that will be sent. This matters because full URLs can carry password-reset tokens, signed download links or session identifiers; never submit a private or authenticated URL to any online scanner, this one included. Checked URLs are not logged into analytics and results have no public permalink.
What is URLhaus and what does it check for?
URLhaus is a free database run by abuse.ch, a respected non-profit security project, tracking URLs observed actively distributing malware. It is deliberately scoped: it is a malware-distribution feed, not a general phishing list, which is why this tool labels it that way and never converts a URLhaus miss into an overall clearance. If a URL you check is listed there, do not open it.
What does a blacklist check mean for site owners?
It tells you whether security vendors have flagged your own site. Sites usually land on blocklists after being hacked: a vulnerable plugin gets exploited and the site starts hosting phishing pages or malware without the owner noticing. Once listed, browsers show warning pages, search traffic collapses and email deliverability drops. The site-owner section below lists the delisting routes; run your own domain through this checker regularly, or automate the monitoring.
What is a lookalike or punycode domain?
Punycode lets domains contain non-Latin characters, encoded with an xn-- prefix. Attackers abuse it to register domains that render almost identically to a brand, like apple.com written with a Cyrillic letter a. This checker analyzes each label of the hostname in your browser, flags labels that mix Latin with lookalike scripts, and shows the technical hostname, so a URL that looks familiar but is a different domain gets caught before you click. It also shows the registrable domain, the only part that identifies who you are talking to.
Why do some sources say "unavailable"?
Threat databases require server-side credentials and quotas, and any source can time out or fail. When that happens the row says unavailable and the verdict accounts for it: an unavailable source is never treated as a pass, and if no threat database ran at all the headline says coverage incomplete instead of showing a reassuring result. That is deliberate; a green light built on sources that did not answer would be a lie.
More free tools: SSL Checker · Redirect Checker · DNS & WHOIS Lookup · Security Headers Checker · DMARC, SPF & DKIM Checker