Redirect Analysis
Follow up to 10 redirects and expose the full redirect chain to catch cloaked threats.
How this check works · illustration
Run a URL scan before users click. Check the domain and destination IP, follow redirect chains, detect phishing or malware signals, and return a risk verdict your SOC, gateway, or product backend can act on.
curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant50 free requests/month · instant API key · no signup form
Illustration dated 2026-09-01. Indicators, providers, scores and observations are fictional. This is not a current result for these addresses.
https://login.example.com/account
Example redirect chain
Response 1 · HTTP 302
https://login.example.com/account
Response 2 · HTTP 200
https://login.example.com/confirm
A redirect and a successful HTTP response do not establish that a destination is safe. Compare the final address with reputation evidence.
Sources flagging
3of 4 sources
Confidence
80 %
The score and confidence are illustrative values. Confidence describes support for the assessment; it is not a percentage of sources or a probability of compromise.
Example categories
Example source observations
| Source | Observation |
|---|---|
| Example feed A | Flagged |
| Example feed B | Flagged |
| Example feed C | Flagged |
| Example feed D | Not listed |
“Not listed” means this source has no listing in the example. It is not a clean bill of health.
How to interpret it
Compare source observations, dates and technical context before taking action. This example makes no attribution to a threat actor.
Real reports depend on the indicator, available sources and access level. Missing data is shown explicitly. These panels illustrate how to read the data; they are not an API response schema.
1M+
URLs Indexed
10
Redirect Depth
< 2 s
Scan Time
99 %
Phishing Detection
Connect the signals, then examine the context.
Follow up to 10 redirects and expose the full redirect chain to catch cloaked threats.
ML-powered detection of phishing pages, even for brand-new sites not yet in blocklists.
Detect drive-by downloads, exploit kits, and malicious JavaScript on destination pages.
Check certificate validity, issuer, and detect suspicious certificate patterns.
Get visual screenshots of scanned pages for manual verification.
Check against Google Safe Browsing, PhishTank, and other authoritative sources.
Check URLs in emails before users click to prevent phishing.
Scan URLs shared in Slack, Teams, or other chat platforms.
Verify advertiser landing pages are safe before serving ads.
Power safe browsing extensions with real-time URL checks.
URLs are the primary attack vector for delivering phishing pages, malware downloads, and exploit kits to unsuspecting users. A single malicious click can compromise credentials, install ransomware, or grant attackers persistent access to corporate networks. URL scanning provides a critical security layer by analyzing links before users interact with them, checking not just the visible URL but following redirect chains, inspecting landing pages, and detecting threats that evade traditional blocklists.
Our URL scanner performs multi-source assessment in multiple stages: first, we parse and validate the URL structure looking for suspicious patterns and encoding tricks. Next, we check the domain and IP against reputation databases. Then we follow up to 10 redirects, recording each hop in the chain to expose cloaked destinations. For advanced scans, we render the page in a sandboxed browser, capture screenshots, analyze JavaScript behavior, and check for credential harvesting forms or malicious downloads. All results are available in under 2 seconds.
Attackers weaponize URLs in numerous ways: phishing URLs mimic legitimate login pages to harvest credentials, malware URLs trigger drive-by downloads when visited, redirect chains bounce through multiple domains to evade detection, URL shorteners obscure malicious destinations, typosquatted URLs exploit typing mistakes, and watering hole URLs compromise trusted sites to target specific organizations. Our scanner detects all these patterns using signature-based detection, machine learning, and behavioral analysis.
Implement URL scanning at multiple layers for defense in depth: scan URLs in emails before delivery, check links in chat messages and collaboration platforms, integrate with browser extensions for continuous monitoring, add scanning to your web proxy, and validate URLs in customer submissions to prevent abuse of your platform. Our API enables all these use cases with consistent threat intelligence and customizable risk thresholds for different security contexts.
A page for each malicious URL with enough intelligence for a report: threat type, URLhaus record, files it served and host.
Check domain risk scores
Anti-phishing URL lists
Scan multiple indicators
Close the page, then deal with what you typed, downloaded or allowed after the click.
Read the address, check the domain and the business behind it, and pay only in a way you can dispute.
Join thousands of security teams using isMalicious to protect their infrastructure.
No credit card required · Free API key