URL scanner: open a suspicious link safely

Scan a URL without visiting it. The page is fetched through an egress-locked scanner and rendered in a disposable browser, so you see the redirect chain, what it loads, what it asks for and what it serves, without any of it reaching your machine.

What a scan captures

Brands most impersonated in scanned URLs

Domains pretending to be these brands, observed across public scans. None of the listed domains belong to the brand. The full ranking lives on the brands-under-attack directory.

Recently scanned URLs

Common questions

Will the site know I scanned it?
The scan runs from our infrastructure rather than your address, so the target sees our scanner. Scans are not anonymised beyond that: a determined operator can identify scanner traffic.
What if the link contains a token or password?
Sensitive values in a URL are detected and redacted before anything is stored, and the scan is forced private so it can never become publicly readable.
Can a clean result be wrong?
A scan is one fetch from one vantage point. Hostile pages commonly serve different content by geography, device or referrer, or only once per visitor, so a benign observation is evidence about that fetch rather than proof about the page.

Related