CanITrustThis

Link check

Is this link safe?

Paste a link from an SMS, email or chat. Trusti unwraps shorteners, follows every redirect, checks Google's threat lists and flags addresses that imitate well-known brands — in a couple of seconds.

This check looks at the address, its redirects and public threat lists. It does not open the page or judge its content, and it cannot prove a link is safe.

Where the link really goes
Shortened links (bit.ly, t.co, cutt.ly and hundreds of others) hide the destination on purpose. The check unwraps the shortener and follows every redirect in the chain, so you see the final address before your browser does. Each hop is listed with its status, because a chain that passes through three unrelated domains is itself a warning sign.
Lookalike brands
Fraudulent links imitate names you trust: a parcel-service brand with an extra word in the address, or a letter swapped for a look-alike character. The check compares every hostname in the chain against well-known brands and flags imitations, including internationalised domain names that render like the real thing.
Threat lists and domain age
Every hostname is checked against Google Safe Browsing, which lists pages reported for phishing and malware. The check also reads the registration date of the final domain. A link that lands on a domain registered last week deserves more suspicion than one that has existed for a decade, even if neither is on a threat list yet.
What the three verdicts mean
Dangerous means at least one hop is on a threat list or the address is a clear brand imitation: do not open it. Suspicious means something needs a second look, such as a very new domain or a long redirect chain. No red flags means the address checks we can run found nothing, which is not the same as safe: a brand-new phishing page can look clean for hours before anyone reports it.
Messages people typically check here
Parcel notifications asking for a customs fee, emails saying an account will be closed, chats that start with a new phone number, prize notifications, and links sent in marketplace conversations. If a message pressures you to act within minutes, that pressure is the first finding, whatever the link says.
When to run a full website check instead
The link check never opens the page. If the link leads to a shop or a login page and you are about to pay or sign in, run the full website check: it reads the pages, looks up the operator in the commercial register, checks policies and reputation, and gives a trust score with the evidence behind it.
Privacy and limits
The link is used for the check, and the result is kept only for you under the order that paid for it, never as a public report. No account is needed.