Take a link apart before you trust it.
Paste any web address. It is parsed as plain text, never visited, and the tricks phishers rely on are pointed out one by one.
Phishing links work because most people read a web address left to right, and the part that matters is on the right. Paste a link and the inspector splits it into scheme, subdomains, registered domain and path, highlights the site you would actually reach, and flags the classic disguises: an @ sign, a bare IP address, punycode, lookalike names, reassurance words and unusual endings. It analyses text only and never opens the address.
Waiting for an address
Paste a link from an email or message, or pick an example above.
You never have to judge a link at all if you do not use it. Open the site from your own bookmark or its official app, sign in there, and look for the problem. If it is real, it will be waiting. If it is not, the scam just failed.
A web address is read from the right-hand end of the host: the part just before the first single slash is the site you reach, and everything to its left is a subdomain the owner of that site can name however they like. Phishers put the brand you expect on the left, or before an @ sign, or in the path, and count on you reading left to right. Once you know where the real domain sits, most tricks stop working on you.
Common questions
Does the inspector open or visit the link?
No. The address is parsed as plain text in your browser. It is never fetched, loaded or sent anywhere, so pasting a malicious link here is safe.
Which part of a web address is the real site?
Read the host from the right-hand end: the part just before the first single slash is the site you reach, and everything to its left is a subdomain that the owner of that site can name however they like. Phishers put the brand you expect on the left, before an @ sign, or in the path, and count on you reading left to right.
What does a clean result mean?
Only that none of the common disguises appear in the text. A genuine-looking address can still belong to a site you should not trust. When in doubt, ignore the link and open the site from your own bookmark or its official app.
Does https or a padlock mean a link is safe?
No. Phishing sites obtain https certificates too. The padlock means the connection is encrypted, not that the site is honest.