Website Safety Checker
Wondering, is this website safe? Paste the URL to check the website for malware and blacklist listings, sneaky redirects, lookalike domains and missing HTTPS, in seconds.
Free, no signup. Limited to 20 checks per minute.
What this website safety check actually looks at
A URL safety checker is only as honest as its sources, so here is exactly what runs when you press the button:
- URLhaus malware database: a live lookup against abuse.ch's list of URLs observed distributing malware. A listing here means the URL has actively served malicious files.
- On-page heuristics: the server fetches the page and looks for traps a blacklist cannot see yet, such as sneaky redirects that send you somewhere other than the address you typed, and connections without TLS.
- Google Safe Browsing: the phishing and malware list Chrome uses, consulted when it is enabled server-side. When it is off, the row honestly says "not checked" rather than implying a pass.
- Instant browser checks: computed on your device without any request: HTTPS on the URL, punycode and mixed-script lookalike domains, TLDs with high abuse rates, and URL shorteners that hide the real destination.
One thing no tool can do, this one included: prove a site is safe. A clean verdict means the checked sources know nothing bad about the URL right now. Brand-new scam sites start with a clean record everywhere, which is why the red flags below matter just as much.
Is this site legit? The red flags that give scam sites away
Blacklists catch known threats. You catch the new ones, by reading the signals scam sites cannot easily fake. These are the ones worth memorizing.
| Red flag | What it looks like | Why it matters |
|---|---|---|
| Too-new domain | Domain registered days or weeks ago | Scam sites burn through fresh domains because old ones get blacklisted. Check the registration date with a WHOIS lookup before you buy. |
| No HTTPS | Address starts with http:// or the browser shows Not Secure | Anything you type travels unencrypted. Legit sites have used HTTPS by default for years, so its absence is a loud warning. |
| Lookalike domain | paypa1.com, amaz0n-support.net, or accented letters in the name | Phishers register domains one character away from the brand they impersonate. Read the domain right to left: the part before the TLD is who you are really talking to. |
| Fake urgency | Countdown timers, "only 2 left", "your account will be closed today" | Manufactured pressure exists to stop you from checking. Real companies do not threaten you into a purchase or a login. |
| No contact page | No physical address, no phone, no legal pages, contact form only | A business you cannot reach is a business you cannot get a refund from. Missing imprint and policy pages are typical of throwaway scam sites. |
| Too-good prices | Brand products at 80 percent off, everything permanently on sale | Fake shops list dream prices to harvest card numbers. If every item undercuts every real retailer, the product does not exist. |
| Odd payment methods | Wire transfer, gift cards or crypto as the only options | These payments cannot be reversed, which is exactly why fraudsters insist on them. Card and PayPal payments give you dispute rights. |
Two of these you can verify with our other free tools right now: check the domain age with the DNS & WHOIS Lookup and expand any shortened or suspicious link with the Redirect Checker before you visit it.
Site owners: how your own site ends up on a blacklist
Most blacklisted sites belong to honest owners who got hacked. The typical story: a WordPress plugin with a known vulnerability goes unpatched, an automated bot exploits it within days, and the site quietly starts hosting phishing pages, spam injections or malware downloads. The owner finds out weeks later, when Google flags the site.
The cost is brutal. Browsers show a full-page red warning to every visitor, search rankings collapse, ad accounts get suspended and emails from your domain go to spam. Recovery means cleaning the infection, requesting reviews from every blacklist, and waiting. Prevention is far cheaper: block the malicious bots probing your site for holes, and monitor your site's health so an infection or an expiring certificate is caught in hours, not weeks.
Website safety check FAQ
How do I check if a website is safe?
Paste the URL above and run the check. The tool queries the URLhaus malware database, runs on-page heuristics that catch sneaky redirects and missing TLS, and, when enabled, Google Safe Browsing. Your browser also checks the URL itself instantly: HTTPS, lookalike punycode domains, high-risk TLDs and URL shorteners. Combine the verdict with the red-flag checklist on this page before you trust a site with money or passwords.
Can a website safety checker prove a site is safe?
No, and any tool that claims it can is overselling. A clean result means none of the checked sources currently know anything bad about the URL. Brand-new scam sites have not been reported anywhere yet, so they pass every blacklist check on day one. Treat a green verdict as "no known threats", not as a guarantee, and keep applying common sense.
What is URLhaus and what does it check for?
URLhaus is a free malware database run by abuse.ch, a respected non-profit security project. Researchers and automated systems submit URLs that actively distribute malware, and the list feeds many antivirus products and firewalls. If a URL you check is listed there, it has been observed serving malicious files and you should not open it.
What does a website blacklist check mean for site owners?
It tells you whether security vendors have flagged your own site. Sites usually land on blacklists after being hacked: a vulnerable plugin gets exploited and the site starts hosting phishing pages or malware without the owner noticing. Once listed, browsers show warning pages, search traffic collapses and email deliverability drops. Run your own domain through this checker regularly, or automate the monitoring.
How can I tell if a shopping site is legit?
Run the safety check, then verify three things: the domain age via a WHOIS lookup, since fake shops are almost always weeks old; a real contact page with an address and working policies; and payment methods with buyer protection. Reverse-search a few product photos too. If prices are far below every established retailer, walk away.
What is a lookalike or punycode domain?
Punycode lets domains contain non-Latin characters, encoded with an xn-- prefix. Attackers abuse it to register domains that render almost identically to a brand, like apple.com written with a Cyrillic letter a. This checker flags punycode and mixed-script hostnames instantly in your browser, so a URL that looks familiar but is technically a different domain gets caught before you click.
Why does Google Safe Browsing show as "not checked"?
Google Safe Browsing requires a server-side API key and is an optional source on this tool. When it is not enabled, the result row says "not checked" instead of pretending the source was consulted. The URLhaus lookup and the on-page heuristics always run, and your browser itself already uses Safe Browsing when you actually visit a page in Chrome.
More free tools: SSL Checker · Redirect Checker · DNS & WHOIS Lookup · Security Headers Checker · DMARC, SPF & DKIM Checker