Free Link Checker:

Check if it’s safe to click

Instantly verify if a link is safe with our free URL checker. You can check a URL and our tool will detect if there is a security issue like phishing, malware, and scams before you click. Simply paste your link below.

cartoon woman holding laptop

This link appears safe to click

Keep in mind, new scam links appear every day. Consider using Avast One to protect yourself from these types of online scams.

{URL} appears unsafe to click

Keep in mind, new scam links appear every day. Consider using Avast One to protect yourself from these types of online scams.

Why use the Avast Link Checker

If you're wondering "Is this link safe?", fear not. Our free Avast Link Checker combines our cybersecurity expertise with advanced AI-powered scanning to detect phishing, scareware, malware, and threats instantly, no installation needed.

key and checkmark
Proven expertise
Avast blocks over 2.6 billion phishing and scam attempts on average.
padlock
Advanced AI technology
Our scanning engines use real-time threat intelligence and AI-powered detection.
sheet and fingerprint
Robust
Avast blocks over 7.1 billion web-based threats on average. 

How to use the Avast Link Checker

Our free link safety and URL checker checks for security issues like phishing links, malware, scams, and suspicious sites. It will help you stay safe online and protect your personal data.

Step 1: Copy your link

Simply, copy and paste your link into our tool. Our multiple scanning engines check the URL against real-time threat intelligence. It looks for security issues like sites, phishing attempts, credential theft schemes, and other malicious content.

animated dog winking and holding items

Step 2: Verify your link

After a quick check, you can decide confidently whether to visit the site or avoid it entirely. If it's unsafe, add it to your blocklist. Think we got this wrong? You can submit a link or file to us for review.

animated woman under an umbrella holding laptop with suspicious character behind her
Avast One logo

Checked your link? Now improve your online security...

Go beyond one-off link checks and protect yourself from online fraud, fake e-shops, and malicious websites in real-time. Get continuous phishing protection and suspicious link blocking with Avast One.

Also available for Mac, Android, and iOS

Also available for PC, Android, and iOS

Also available for PC, Mac and iOS

Link Checker FAQ

Got questions about sketchy links? Here's what people ask most about using a link checker and how it keeps you safe.

To tell if a website is safe, start by running the URL through a scanner like Avast Link Checker. Always manually inspect the address bar for HTTPS encryption and carefully check the domain for "typosquatting" (like goog1e.com instead of google.com).

Legitimate sites should feature clear contact information and a privacy policy, whereas red flags include aggressive countdown timers, amateurish grammar, or "too-good-to-be-true" pricing. When in doubt, a quick search for the site name plus the word "scam" or "phishing" on third-party review platforms will usually reveal the truth. Avast One can also help you stay safe online.

Look for social engineering red flags such as broken links, low-resolution logos, and egregious spelling or grammatical errors, which are common in offshore scam operations. A secure connection is indicated by HTTPS, but encryption only protects the data path, not the intent of the site owner.

Be especially wary of social engineering tactics, such as countdown timers creating artificial urgency, or intrusive pop-ups demanding sensitive data like your banking credentials for a "limited-time prize." You can also use a scam detector tool to check a website.

Start by using a dedicated link safety checker (like Google Transparency Report or Avast Link Checker) to scan the URL for hidden malware or phishing before you even click. Once on the site, check the browser's address bar. Ensure the connection is secured with HTTPS (look for the padlock icon), and click the padlock to view the SSL certificate. If it's issued to a completely different company or has expired, leave immediately.

Next, perform a "transparency audit" by hunting for a physical office address and a verified phone number; scammers rarely provide a traceable paper trail. Cross-reference the site's reputation on independent platforms like Trustpilot or the Better Business Bureau if you're in the US or Canada. Pay close attention to "too-good-to-be-true" pricing and suspicious "urgent" pop-ups and malvertising that pressure you to share sensitive data.

Finally, keep an eye out for typosquatting, subtle misspellings in the URL like amozon.com instead of amazon.com, which is a classic hallmark of a cloned site designed to harvest your credentials.

To check if a website has been reported for fraud, you can use a combination of technical scanners and community-driven review platforms. Start by pasting the URL into a link checker from a reputable company like Avast. These tools aggregate reports from dozens of security engines to identify active phishing, malware, or deceptive site warnings.

For consumer-related fraud and "scam" reports, search the domain on Trustpilot or the Better Business Bureau (in the US and Canada) to see if other users have flagged the business for non-delivery or identity theft.

Additionally, check the Whois database to see if the site was created very recently (a common trait of fraudulent domains) or use the FCA Warning List (in the UK) or FTC (in the US) to see if the site has been officially blacklisted by financial regulators. If you stumble across a bad site, you can block it on Chrome.

Free online website safety checkers from the likes of Avast and Norton are reputable and safe. They are easy and quick to use. Copy and paste the URL into a free link checker to see if it's flagged in threat databases. You can also check Google Safe Browsing and report suspicious sites to authorities.

When shopping online, the credit card remains the premier choice for security due to robust legal frameworks, generally allowing you to dispute charges or "billing errors". Debit cards, by contrast, draw funds directly from your checking account; while they have protections, the recovery process may be slower and your actual cash is missing from your account while the bank investigates."

Additionally, use digital wallets (Apple Pay, Google Pay, PayPal) and virtual card numbers. These services send a one-time encrypted code to the merchant instead of your actual 16-digit card number. This ensures that even if the website suffers a data breach later, the hackers only get a useless, expired token rather than your permanent financial data. These steps are excellent for mitigating the impact of merchant data breaches. Finally, be careful of smishing, which relies on tricking you into bypassing these protections and handing over your details directly.

Hovering over a link is one of the most effective low-tech ways to unmask a phishing attempt before it begins. By resting your cursor over a hyperlinked word or button without clicking, your browser will reveal the actual destination URL in the bottom-left corner of the window. If the popup shows a string of random characters or a domain that slightly misspells the brand name (like micros0ft.com instead of microsoft.com), the site is almost certainly employing domain spoofing to harvest your credentials.

Shortened URLs can pose a unique risk because they intentionally hide the final destination, making it impossible to "read" the link by hovering. For these, or any link that feels suspicious, use a URL expander or a link safety checker from Avast or the Google Transparency Report. These tools act as a digital "blast shield", visiting the site on your behalf to scan for malware, phishing scripts, and deceptive redirects before you ever expose your own browser to the threat. You may find this additional resource helpful if you’d also like to learn how to spot fake apps.

No, HTTPS (Hypertext Transfer Protocol Secure) does not guarantee that a website is trustworthy or legitimate; it only guarantees that the "pipe" between your browser and the server is encrypted. While this prevents third parties from "eavesdropping" on your data, it says nothing about the intentions of the person on the other end.

Most modern phishing and scam sites now use HTTPS and display the padlock icon to create a false sense of security. A site can be perfectly encrypted while simultaneously being a fraudulent clone designed to steal your credit card information. To truly verify a site, you must look beyond the padlock and check for "typosquatted" URLs (like g00gle.com), verified contact information, and a long-standing domain reputation. You also still need a reliable antivirus tool like Avast One.

Browser "unsafe site" warnings are your browser's digital tripwire, alerting you when a website is flagged for dangerous behavior or technical insecurity. The most severe is the "red screen" warning (labeled as "Deceptive site ahead" or "Dangerous site"), which is triggered by services like Google Safe Browsing or Microsoft SmartScreen. This means the site has been actively identified as hosting malware, phishing scripts designed to steal passwords, or social engineering traps. These warnings have become even more sophisticated, often flagging "AI-engineered" phishing pages or malicious browser extensions that attempt to hijack your session.

If you see a "Not Secure" alert or a "Your connection is not private" message, it means the site is using outdated HTTP instead of encrypted HTTPS, or its security certificate is expired or invalid. Browsers like Chrome and Safari have moved to an "HTTPS-First" standard, where even simple public HTTP sites trigger a bypassable warning. While this doesn't always mean the site is "evil," it does mean that any data you enter, like a login or credit card number, can be easily intercepted by hackers on the same network.

If you've entered information on a scam site, cut the connection between the attacker and your accounts. Immediately change the password on the legitimate version of that website, and if you reuse that password elsewhere, especially for your email or banking, update those accounts as well. Enable Two-Factor Authentication (2FA) immediately.

If you shared financial details like a credit card number or CVV, use your banking app to freeze the card and contact your bank's fraud department to report the compromise and request a new card.

If you shared highly sensitive data, such as a tax number or home address, place a credit freeze with the major credit bureaus to prevent scammers from opening new accounts in your name. Additionally, run a comprehensive malware scan on your device using a trusted free antivirus tool to ensure no keyloggers or tracking scripts were silently installed while you were on the site.

Finally, keep a close eye on your inbox and statements for the next few weeks, as your information may be sold to other scammers, leading to an uptick in targeted phishing attempts.

Adopt a zero-trust approach to links. Always hover over URLs to reveal their true destination and use a sandboxed link checker to scan suspicious addresses before clicking. You can also protect yourself with a virus removal tool like Avast One.

When setting up a site login, consider implementing phishing-resistant Multi-Factor Authentication (MFA), such as FIDO2 hardware keys or biometric passkeys (FaceID/TouchID). Unlike traditional SMS codes, which can be intercepted or tricked, these physical and biometric credentials only authenticate with the genuine, registered domain.

Visit our Support Center for more FAQs.

Get advice about URL checks and web tracking alongside other privacy tips