Skip to main content
Threat Intelligence

URL Scanner Scan URLs for phishing, malware, and hidden redirects

Run a URL scan before users click. Check the domain and destination IP, follow redirect chains, detect phishing or malware signals, and return a risk verdict your SOC, gateway, or product backend can act on.

No credit card required · Free API key

Try it now⌘K
Try
Output
verdict
malicious · 35 / 89 sources
country
DE · AS60729
confidence
0.75
latency
47 ms · cache HIT
Live sample response

What you get per URL scan. Chain, certificate, page behavior.

Real scan of a PayPal phishing URL — redirect chain, page signals, and verdict

live samplePOST /api/v1/scan/url

200 OK · 0 ms
Inputhttps://secure-login.paypa1-verify.com/account/confirm?token=a8f3

Redirect chain · 3 hops

  1. 1301https://secure-login.paypa1-verify.com/account/confirm?token=a8f3
  2. 2302https://paypa1-verify.com/r?sid=9x2
  3. 3200https://paypa1-verify.com/harvest.php

SSL certificate

IssuerLet's Encrypt
Valid from2026-03-15
Expires2026-06-15
Cert age44 days
Self-signedno

Domain age

12days old — NRD flag

Verdict

PHISHING

Categories

phishingcredential-harvestingbrand-impersonationmalware

Risk factor breakdown

Brand impersonation38.0
Threat feeds32.0
Page behavior16.0
SSL / domain age8.0

Source verdicts

Google Safe Browsingphishing
PhishTankconfirmed
OpenPhishconfirmed
URLhausclean

Page behavior signals

PayPal login form detecteddetected
Password input harvestingdetected
Brand logo scrapeddetected
Hidden iframedetected
External JS injectionnot detected

Signals detected

4of 5 checks

Final destination

https://paypa1-verify.com/harvest.php

sample3 hops4 sourcesenrichmentLevel: full

Also includes: HTTP headers · JS analysis · Embedded resources · Related infrastructure · MITRE tactics

0M+

URLs Indexed

0

Redirect Depth

< 0 s

Scan Time

0 %

Phishing Detection

Capabilities

Key features. Everything you need to protect your infrastructure and users.

Redirect Analysis

Follow up to 10 redirects and expose the full redirect chain to catch cloaked threats.

Phishing Detection

ML-powered detection of phishing pages, even for brand-new sites not yet in blocklists.

Malware Scanning

Detect drive-by downloads, exploit kits, and malicious JavaScript on destination pages.

SSL/TLS Analysis

Check certificate validity, issuer, and detect suspicious certificate patterns.

Screenshot Capture

Get visual screenshots of scanned pages for manual verification.

Safe Browsing

Check against Google Safe Browsing, PhishTank, and other authoritative sources.

Applications

Use cases. How security teams use this tool.

Email Link Scanning

Check URLs in emails before users click to prevent phishing.

Chat/Messaging Security

Scan URLs shared in Slack, Teams, or other chat platforms.

Ad Verification

Verify advertiser landing pages are safe before serving ads.

Browser Extensions

Power safe browsing extensions with real-time URL checks.

Why URL Scanning Matters

URLs are the primary attack vector for delivering phishing pages, malware downloads, and exploit kits to unsuspecting users. A single malicious click can compromise credentials, install ransomware, or grant attackers persistent access to corporate networks. URL scanning provides a critical security layer by analyzing links before users interact with them, checking not just the visible URL but following redirect chains, inspecting landing pages, and detecting threats that evade traditional blocklists.

How URL Scanning Works

Our URL scanner performs multi-source assessment in multiple stages: first, we parse and validate the URL structure looking for suspicious patterns and encoding tricks. Next, we check the domain and IP against reputation databases. Then we follow up to 10 redirects, recording each hop in the chain to expose cloaked destinations. For advanced scans, we render the page in a sandboxed browser, capture screenshots, analyze JavaScript behavior, and check for credential harvesting forms or malicious downloads. All results are available in under 2 seconds.

Common URL-Based Threats

Attackers weaponize URLs in numerous ways: phishing URLs mimic legitimate login pages to harvest credentials, malware URLs trigger drive-by downloads when visited, redirect chains bounce through multiple domains to evade detection, URL shorteners obscure malicious destinations, typosquatted URLs exploit typing mistakes, and watering hole URLs compromise trusted sites to target specific organizations. Our scanner detects all these patterns using signature-based detection, machine learning, and behavioral analysis.

Protecting Your Organization from URL Threats

Implement URL scanning at multiple layers for defense in depth: scan URLs in emails before delivery, check links in chat messages and collaboration platforms, integrate with browser extensions for continuous monitoring, add scanning to your web proxy, and validate URLs in customer submissions to prevent abuse of your platform. Our API enables all these use cases with consistent threat intelligence and customizable risk thresholds for different security contexts.

Support

Frequently asked questions.

How does URL scanning work?

We analyze the URL structure, follow redirects, check the final destination against threat databases, and optionally render the page to detect dynamic threats.

Do you follow URL redirects?

Yes, we follow up to 10 redirects and report the full redirect chain, helping you catch cloaked malicious URLs.

Can you detect zero-day phishing sites?

Yes, we use machine learning and heuristic analysis to detect brand-new phishing sites that haven't been reported yet.

Do you capture screenshots?

Yes, our advanced scanning option captures screenshots of the rendered page for visual verification.
Get started

Ready to get started?

Join thousands of security teams using isMalicious to protect their infrastructure.

No credit card required · Free API key