
Scan any link, QR code or email
Paste a URL, drop a QR-code image, or paste a suspicious email — and get a clear verdict in seconds: safe or scam, explained in plain English.
Trusted for 400+ scans across 17 countries
// How it works
Every URL is checked against curated malware and phishing feeds — URLhaus, OpenPhish and PhishStats — refreshed continuously.
We fingerprint the server's TLS stack (JARM) to spot infrastructure reused across known command-and-control and scam networks.
Certificate validity, issuer and encryption are inspected on every scan.
Public CT logs reveal how new a domain's certificates really are — a classic phishing-kit tell.
The site's resolving IPs are geolocated and mapped to expose fast-flux or freshly-moved infrastructure.
Mobile-vs-desktop cloaking checks plus favicon fingerprinting catch sites impersonating trusted brands.
// Live threat map