By Moti Shay · updated July 25, 2026
Almost every digital scam runs through a single vector: a link. The text, email or WhatsApp message is just the wrapper — the theft happens on the site the link takes you to. Knowing how to read a link and spot a trap domain is therefore the number-one protection skill today. Here's how to do it — and how to check any link for free, in seconds, without ever clicking it.
What matters in a URL is the domain — the part between "//" and the first "/" after it. In https://secure.paypal.com/login, the domain is paypal.com: legitimate. But in https://paypal.secure-verify.com/login, the real domain is secure-verify.com — "paypal" is just a prefix meant to fool you. Scammers bank on the fact that most people only read the start of the address.
• A deliberate typo in the domain: paypa1.com (a 1 instead of the L), amaz0n-support.com, netflix-billing.xyz • A long domain with the brand name as a prefix: post.tracking-secure.xyz • A shortened link (bit.ly, tinyurl, cutt.ly…) in a message that asks for payment or details — the shortener hides the destination • An unusual extension for a known company: .xyz, .top, .icu • http:// without the "s" — an unencrypted connection. But note: the https padlock doesn't guarantee a site is honest, only that the connection is encrypted. Most phishing sites today use https.
Many people click "to see where it goes." That's a mistake: simply visiting a malicious page can be enough to fingerprint your device, show a fake login page tailored to your bank, or trigger a download. Checking must be done from the outside: the Phishy checker follows the shortened link in an isolated environment, on our side, and reveals the final destination — without your phone ever touching it.
1. Long-press the message or link → Copy (don't open it!) 2. Paste it into the free Phishy checker on this page 3. In seconds: safe / suspicious / phishing — with the explanation The tool checks the link against global fraud databases (Google Safe Browsing, VirusTotal and others), follows redirects and disguises, and also analyses the message text around the link. No signup, no install.
A careful scammer can register an innocent-looking domain. So always cross-check with context: who sent it? Were you expecting this message? Is there time pressure or a request for payment? Unexpected message + link + urgency = mandatory check. And if the message claims to be from an official body (bank, post office, tax office), go there yourself by typing the official address — never through the link.
• Entered nothing: close the page. The risk is low in most cases; watch for any odd device behaviour. • Password entered: change it immediately on the real service — and anywhere you used the same one. Turn on two-step verification. • Card entered: block it immediately and dispute the charges with your bank. • File or app downloaded: delete without opening, run a security scan. • Report the site to your national cybercrime portal.
Yes: paste the link into the free checker on this page — no signup or install, answer in seconds.
No. The padlock means the connection is encrypted, not that the site is honest. Most phishing sites today use a perfectly valid https.
Paste it into Phishy: the tool follows the shortener in an isolated environment and shows the final destination, plus how dangerous it is.
In most cases, no. The real danger comes from entering details or downloading a file. As a precaution, check the link in the tool to learn what you were dealing with.
Not necessarily: hijacked accounts send links to all their contacts. If the link is unexpected or the style is unusual, check it and confirm with the sender through another channel.