Retour aux services

Free tool

Check a Link's Safety Before You Click

Paste a suspicious link and check its safety before you click. From our server — never from your device — the tool follows every redirect to reveal the real destination, then examines the domain's age, its certificate, brand look-alikes and known threat databases. The result is a cautious verdict: a score with its confidence, and plain advice on what to do. It estimates and recommends prudence; it never certifies — calling a phishing site safe would cost far more than a false alarm.

Le lien est ouvert par notre serveur, jamais par votre navigateur : vous ne visitez pas la page, même si elle est piégée.

À savoir d’abord

  • Aucune analyse ne prouve qu’un lien est sûr : l’indice dit « rien de suspect trouvé », jamais « aucun risque ».
  • Le cadenas HTTPS ne dit rien de l’honnêteté d’un site — les pages de hameçonnage en ont presque toutes un.
  • L’adresse est transmise aux bases de menaces configurées ; votre historique, lui, reste dans ce navigateur.
  • Seul le verdict de ces bases est gardé six heures sur notre serveur, sous une empreinte de l’adresse.

How to check a link in 3 steps

  1. Paste the address

    Copy the link from the message or email — without opening it — and paste it into the field. Shortened and redirected links are exactly what the tool is for.

  2. Read the real destination

    The tool follows the redirect chain from our server and shows the arrival address in large type. For a shortened link, that is often the single most useful thing to read.

  3. Follow the advice

    The verdict comes with what it establishes and what it does not, plus a plain instruction. The analyzed address is never clickable here — checking a link should not make you visit it.

Why use this link safety checker

Frequently asked questions

Can this tool guarantee a link is safe?

No — and no tool can. It estimates from technical signals: a brand-new phishing site may not appear in any database yet, and a legitimate site can look unusual. That is why the verdict always carries its confidence level, and why the final prudence remains yours.

Why does it sometimes answer “caution” instead of a clear yes or no?

When too little could be verified, the confidence caps the verdict in both directions: the tool has no right to reassure or to accuse on missing evidence. A held-back verdict is an honest answer, not a malfunction.

Does my device open the link?

No. Redirects are followed from our server; your browser never touches the analyzed address. The results page never makes it clickable either — an accidental click on the very page meant to prevent one would be the worst possible irony.

What exactly does it check?

The destination after all redirects, the domain's age in public registries, its certificate, resemblance to known brand names, structural warning signs in the address itself, and exact matches in threat databases such as Google Safe Browsing and URLhaus.

What if the registry publishes nothing about the domain?

The information is marked unavailable and produces no signal at all. Many registries publish no dates; treating that silence as suspicious would unfairly penalize entire regions' domains. Absence never accuses.

Is the address I analyze stored?

Verdicts are kept for about six hours under a salted fingerprint of the address — never the address itself — so threat databases aren't queried twice for the same link. Failed analyses are never cached.

Can it read pages built with JavaScript?

The tool never executes a site's scripts: running a suspicious site's code on our server, at a stranger's request, would rebuild the very danger it exists to prevent. A page assembled entirely in JavaScript therefore stays partly invisible — and that limit is stated in the report.