Check a link before you click
Paste a suspicious link, or the whole email or text it came in. We check every link against Google's threat list and look for the tricks scammers use.
Every link gets four checks
Matched against Google Safe Browsing, the same list Chrome uses to block known phishing and malware.
Spots fake Microsoft, PayPal, bank and delivery links, including misspellings like "micros0ft" and lookalike characters.
Looks up when the website was registered. Scam sites are often only days old.
Catches hidden destinations: link shorteners, IP addresses, "@" tricks, script links and risky domain endings.
- Dangerous: Google has confirmed it as phishing or malware. Don't open it.
- Likely a scam: strong signs of impersonation or deception. Don't open it or sign in through it.
- Be careful: some warning signs. Only continue if you expected the link and trust the sender.
- No problems found: no known threats or warning signs, but still check who sent it. Scammers also use legitimate sites.
- Couldn't fully check: Google's list couldn't be reached. Treat the link as suspicious and try again shortly.
- Change the password for that account (and anywhere you reuse it), from a device you trust.
- Sign out of all sessions and check your MFA / authenticator settings for anything you didn't add.
- If you entered card or bank details, call your bank now.
- If a file downloaded or ran, disconnect that device from the internet.