IsMyUrlSafe

FAQ

Frequently asked questions

How the checkers work, what the verdicts mean, and what happens to what you paste in. For step-by-step walkthroughs, see the Guide.

About IsMyUrlSafe

What is IsMyUrlSafe?

A free set of safety checkers for everyday situations. Paste a web link, a suspicious message, or a photo of a QR code and get a plain-language reading of whether it looks safe to trust. It is built for people who are not security experts and want a quick second opinion before they click, reply or pay.

Is it free, and do I need an account?

It is completely free, with no account to create, nothing to install and no adverts. You can run as many checks as you reasonably need to, on a phone or a computer.

What can I check here?

Three things — a URL or web address, the text of a message you were not expecting (SMS, WhatsApp, email and similar), and a QR code image. Each has its own checker, and the QR checker reads the address inside the code and then checks that address.

Does IsMyUrlSafe replace antivirus software or a password manager?

No. It is a lightweight second opinion you use in the moment, before acting on a link or a message. Keep using up-to-date security software, a password manager and two-step verification — this sits alongside those habits, not in place of them.

Which browsers and devices does it work on?

Any modern browser on a phone, tablet or computer. There is no app to install and nothing to configure, and every checker works the same on mobile and desktop.

Checking links

Does checking a link open it or tell the sender I looked?

No. Checking a link here does not visit the page, load its content or notify anyone. You can safely test an address you would never actually click.

What do "safe", "suspicious" and "unsafe" mean?

"Unsafe" means clear warning signs were found — do not open the link, sign in or enter any details. "Suspicious" means there is enough doubt to stop and confirm through a channel you already trust, such as typing the company's real address yourself. "Safe" means nothing harmful is known about the address right now.

Can a link still be dangerous if the result says "safe"?

Yes. Brand-new phishing and scam sites often go live before anyone has reported them, so a "safe" result lowers the odds without removing them. Treat it as a strong signal, not a guarantee, and trust your instinct if something still feels wrong.

Does it work on shortened or redirect links?

Yes. Paste a shortened link and it is checked, including where it points. If a short link resolves to an unexpected destination, treat it with extra caution even when the verdict looks clean.

Should I paste a link that contains a login code or personal details?

No. If a URL contains a password, a one-time code or an account token, check the site's main address instead — for example example.com rather than example.com/reset?token=abc123.

It said the security sources were temporarily unavailable. What should I do?

Occasionally a check cannot be completed. Wait a short while and try again, and do not treat a link as safe simply because it could not be checked.

Checking messages

What kinds of messages can I check?

Any short written message you are unsure about — an SMS, a WhatsApp or iMessage, a Messenger or Instagram DM, or the text of an email. Paste the words themselves; you do not need to forward anything.

Does the message need to contain a link?

No. Many scams never include a link — they ask you to reply, call a number or move the conversation elsewhere. The check works on the wording and structure of the message alone.

A message from a company I actually use was flagged. What should I do?

Do not act on the message itself. Open the company's official app, type their website address yourself, or call the number on a statement or the back of your card. Never use the contact details supplied in a message you are unsure about.

My message is not in English. Will the check still work?

The analysis is tuned for English and gives a weaker read on other languages. Treat the result as a rough guide and lean on your own judgement.

Checking QR codes

How do I check a QR code?

Upload a photo or a screenshot of the code. The checker reads the web address hidden inside it and then checks that address the same way the URL checker does, returning a plain safe, suspicious or unsafe verdict.

Is my QR code image uploaded or stored?

The image is read on your device to pull out the address inside it; the picture itself is not uploaded. Only the address it contains is checked.

What is "quishing"?

Quishing is phishing that uses a QR code instead of a written link. A common version is a fake code stuck over a real one on a poster, a parking meter or a letter, so a quick scan sends you to a look-alike payment or login page.

Privacy

Do you store the links or messages I check?

Links and messages are not kept in a form that identifies you, and messages are not stored in a readable form. A short, domain-only record of link checks — for example example.com, never the full address or anything after it — is kept for about 30 days so the service can run and improve.

Do you show adverts or sell my data?

There are no adverts, and nothing you check is sold or shared for marketing. The checkers exist to give a quick safety reading, not to profile you.

Results and trust

How current is the information behind a check?

Link checks draw on large, continuously updated records of websites reported for phishing, malware, fraud and other abuse, so newly listed sites are picked up quickly. Message checks combine automated analysis with extra review of borderline cases.

The result and my instinct disagree. What should I do?

Follow your instinct and take the slower, safer path. Reach the organisation through its official app or a web address you typed yourself, and do not enter passwords, codes or card details on a page you opened from a link.

I think a result is wrong, or I found a scam the checker missed. Can I report it?

The records behind the check come from large abuse-reporting networks that many organisations contribute to. If a site tried to scam you, reporting it to your bank, your local fraud service and the brand being impersonated does the most good.