Safety checks · free tool

Phishing link checker: check the link and the message

Paste a suspicious link, or the message it came in, to see which phishing habits show up in the link and in the words, with the exact words marked.

Tool · runs in your browserNothing is uploaded

An invented example message is loaded. Paste your own over it. Leave out names and numbers you would rather not type: the checker works on the wording. Nothing you paste leaves your device.

Try an example:
Highlevel for this invented example message
3warning signs matched
a threat to block your accountthe strongest sign
3stretches of words behind them
1link found in it

The invented example message “Your bank KYC has expired and your account will be blocked within 2…” reads High: a threat to block your account, a link that hides or imitates its address and a KYC or SIM update pretext. This is a reading of the words only; it cannot see who sent a message, so a Low reading never means a message is from who it says.

What matched in this invented example message
Warning signThe words it matchedPoints
Threatens to block or close something“KYC has expired and your account will be blocked within 24 hours”+30
Holds a link that hides or imitates its address“http://bank-kyc-update.top/verify”+25
Says your KYC, PAN or SIM needs updating“KYC has expired”+22

A link can look plain and still lead to a copy of a login page, so a link rating alone proves little. What a phishing message cannot hide is its wording. Paste the whole message above and the checker marks the link and the words that pressure you, with the exact words listed.

In the example above, the threat and the link are both marked, and the rating reads High. Swap in your own message to see which signs it shows.

Nothing you paste leaves your device. Leave out names and numbers if you like, because the wording is what it reads.

Common questions

Can a checker prove a link is phishing?

No. It can show that an address has the habits of a trick, such as a shortened link, a borrowed name or a throw-away ending, and that the words around it pressure you. It cannot see the page behind the link, so a Low result never means the link is fine.

Why paste the whole message and not only the link?

The words around a link carry most of the evidence. A hurry, a threat, a fee or a request for a code is easier to spot in the message than in the address. The checker reads both and marks the link and the words in your message.

Can the checker tell who is behind a Telegram account?

No. It reads the words of a message and the links inside it, and cannot see who sent them, how old the account is or whether a number is spoofed. That is why a Low reading never means a message is from who it says.

Does the checker send my message anywhere?

No. It is code running in your browser, and the message you paste is read on your device and sent nowhere. Nothing is stored, logged or looked up, so you can paste any message without it leaving your phone.

What if I have already paid or shared a code?

Call your bank straight away to block the card or UPI ID, then call 1930, the national cyber-fraud helpline, and report it at cybercrime.gov.in. Save the chat and the payment details first. The after-a-scam guide on this site lists the steps in order.

More on the scam message checker

The full tool