Questions

Short answers. Where one is a summary of something with more to it, the link underneath goes to the part of the reference that treats it properly.

  1. How can you tell whether a link is safe before clicking it?

    Look at the registered domain rather than the text of the link - that is the only part the sender had to pay for, and the part a look-alike has to get wrong. Four things are worth establishing: how long ago it was registered, whether the certificate was issued for that name, whether anyone has already reported it, and where it finally lands after any redirects. This tool checks all four and shows its reasoning. None of it settles the question on its own - judge the request being made of you, not only the link.

    What happens when you press Check

  2. I already clicked a suspicious link - what should I do?

    If you only loaded the page and typed nothing, the usual outcome is nothing at all. If you entered a password, change it now on the real site - reached by typing the address in yourself, never by following a link in the message - and change it anywhere you reused it. Turn on two-factor authentication while you are there. If you entered card details, call your bank. If you opened a downloaded file, run a malware scan. Then report the message, so the next person gets a warning instead of a surprise.

  3. Is it safe to open a suspicious link just to check it?

    Not in your own browser. Every request here is made from our server, never from yours, so the site being checked sees our address and never your IP, cookies or session. The one thing to know is that fetching a link can be the same as clicking it: a password reset, unsubscribe or magic sign-in link may be spent by being loaded, whoever loads it.

    What happens to the link you paste

  4. What does the risk score actually mean?

    It is the sum of the findings, capped to 0–100 and split into four bands: Minimal 0–14, Low 15–39, Medium 40–69, High 70–100. Every point traces back to a named finding with a fixed published value, so the number can be disagreed with rather than taken on faith.

    Every scoring weight

  5. Does a low score mean the site is safe?

    No. A low score means none of the common phishing indicators were found, which is not the same as evidence that a site is trustworthy. A domain registered this morning appears on no blacklist, holds a perfectly valid free certificate, and can score in the low teens while being a trap. Each result also carries a confidence level, because a low score from two completed checks is worth far less than the same score from seven.

    What this will not catch

  6. Is the link I paste stored anywhere?

    No. It is analysed, shown to you, and forgotten - no history, no lookup table, no counter, no analytics, no accounts. Two services unavoidably see the address, Google Safe Browsing and PhishTank, because checking a URL against them means sending it.

    The cookies, the caches, and who else sees it

  7. What is typosquatting, and how is it detected here?

    A typosquatted domain is registered to be misread as a well-known one - paypa1.com for paypal.com, or a Cyrillic а in place of a Latin one. Names are compared after folding the characters that are easy to confuse, and a brand is also looked for inside a longer name, spelled correctly or one character out.

    How the brand match runs

  8. Why can it not tell me anything about a .be, .de or .it domain's age?

    Those registries publish no RDAP registration data at all. Where the date cannot be obtained the age check reports as unavailable and the result's confidence drops - never as a pass. A lookup that failed must not read as evidence that a domain is clean.

    The rest of what it misses

Still a risk indicator, not a safety guarantee. A low score means none of the common phishing indicators were found - not that a site can be trusted. What this will not catch.