Website safety check

Is this website safe?

Paste a link. We check the address against millions of known phishing, scam, and malicious domains, and then show you what to look at yourself, because no database catches a scam site on its first day.

Live domain intelligence
<1ms

mailinator.com

This is a throwaway mailbox provider.

It exists to hand out temporary email inboxes. That is not an attack on you, but it is not a real service either, and addresses from it should not be trusted at signup.

Seen this domain used in a scam? Report it and the next person who checks will be warned.

Paste any link, with or without the https and the rest of the address. We only read the website name out of it.

Behind every check

19.8 million

IP addresses profiled

2.4 million

malicious domains tracked

208,000

disposable email domains

1.9 million

networks scored

Counts read live from the engine, not written into the page. The full dataset is published on GitHub under the MIT license and rebuilt every 30 minutes.

What we can tell you

One thing, precisely, and it is worth being clear about the boundary because most tools in this space are not.

Whether the domain is on our malicious list

Millions of domains observed in phishing, malware distribution, and scam infrastructure, assembled from threat feeds, malware-family trackers, and our own sensors, refreshed continuously.

Whether it is a throwaway mailbox service

Not an attack on you, but it tells you the site exists to hand out disposable inboxes rather than to be a real business.

Which name we actually checked

We match the exact hostname. If you paste a link with www and the listing is against the bare domain, we check both and tell you which one matched.

What no checker can tell you

A clean result here means we hold no evidence against that name today. It does not mean the site is safe, and treating those as the same thing is how people get hurt. Scam shops are built, used for a few weeks, and abandoned before any reputation service has heard of them, which means the sites most likely to take your money are exactly the ones least likely to be listed anywhere. We would rather tell you that plainly than hand you a green tick you would be wrong to trust. Nor do we inspect the page itself, read its certificate, or judge the quality of a shop: we answer whether the name has a history, and history is something a brand-new domain does not have.

The checks worth doing yourself

These catch the scams a database misses, and none of them need a tool.

How old is the domain

The single most reliable signal there is. A shop selling well-known brands from a domain registered six weeks ago is almost always a scam, whatever else the site looks like. Registration dates are public and free to look up.

Read the address character by character

Swapped letters, an added hyphen, a plausible but wrong ending. The entire trick is that you glance at the address instead of reading it. Type the brand into a search engine and compare rather than trusting the link you were sent.

Are the prices possible

Nobody sells current-season goods at ninety percent off. An impossible price is not an opportunity you found first, it is the bait.

Is there a real company behind it

A registered company name, a working phone number, a physical address that exists somewhere other than that website. Scam sites copy an About page and forget that everything in it can be checked.

How do they want to be paid

Bank transfer, cryptocurrency, or gift cards means there is no chargeback, and no chargeback is precisely why they asked. A card payment can be reversed, which is why fraudsters steer you away from one.

Pressure and urgency

A countdown, three left in stock, an account that will close today. Manufactured urgency exists to stop you doing any of the checks above.

If you already paid

Contact your bank or card issuer now

Card payments can often be reversed, and the window is measured in days rather than months. This is the single most useful thing you can do, and doing it early matters more than doing it perfectly.

Change any password you reused

If you entered a password on a phishing page, it is now on a list. Change it everywhere you used it, starting with your email account, because that is what everything else resets through.

Report it

To your national fraud reporting body, and here. A domain reported today is a domain the next person gets warned about.

Questions people ask

How can I check if a website is legit?

Start by pasting the address above to see whether it is already known to be malicious. If it comes back unknown, that is not a pass, so check the things a database cannot see: how old the domain is, whether the address matches the brand exactly when you read it character by character, whether the prices are believable, whether a real company is named anywhere you can verify independently, and how they want to be paid. Bank transfer, crypto, or gift cards is the strongest warning sign on that list.

Is this website safe to buy from?

We can tell you whether the domain appears in our malicious-domain dataset, which is a real and useful answer when it comes back positive. When it comes back clean, treat it as an absence of evidence rather than a recommendation. Newly registered shops are the highest-risk category and they are, by definition, the ones no reputation service has caught yet. Pay by card if you proceed, because a card payment can be reversed and a bank transfer cannot.

What does it mean if the site is not on your list?

It means this exact hostname is not in our malicious-domain dataset today. Most of the web is unremarkable and on no list anywhere, and so is every scam site on its first morning. It is a useful signal in combination with domain age and the other checks on this page, and a poor one on its own.

Can I check a link without clicking it?

Yes, and you should. Copy the link rather than opening it, then paste it here. On a phone, press and hold the link to copy it instead of tapping. We only read the website name out of whatever you paste, so the path and any tracking parameters are discarded before anything is checked.

I have been scammed by a website. What should I do?

Contact your bank or card issuer immediately, because card payments can often be reversed and the window is short. Change any password you entered on the site, and change it everywhere else you used it, starting with your email account since that is what other accounts reset through. Then report the domain, both to your national fraud reporting body and here, so the next person who checks it gets a warning instead of a blank.

Do it in code.

The same answer from a free API endpoint, or download the whole database and never call an API at all. No card, no quota, no expiry.