🔗 URL / Domain Analyzer
Enter a URL or domain for safe first-level triage: its components, DNS, redirect behavior, HTTP response, and TLS status, plus characteristics that may deserve a closer look. These are investigation indicators — never proof that a URL is malicious.
Input
Results
How It Works
The URL is parsed locally into protocol, hostname, port, path, query parameters, and fragment. The server then resolves its DNS records, requests the URL using safe read-only methods (following redirects one hop at a time and re-validating every destination), and checks TLS using the existing SSL/TLS checker. The page is never rendered or executed.
"Potentially suspicious characteristics" are simple heuristics — for example HTTP instead of HTTPS, an IP address as the hostname, Punycode, an unusual port, a long redirect chain, heavy URL encoding, an embedded username, or many nested subdomains. Plenty of legitimate URLs trigger some of these, so treat them as prompts for further investigation, not verdicts. The domain/subdomain split is approximate because it doesn't embed the full Public Suffix List.
Examples & Common Use Cases
- Triage a link from a reported phishing email without opening it in a browser.
- See where a shortened or redirecting link actually ends up.
- Check whether a URL uses a raw IP, odd port, or Punycode hostname.