What we can and cannot catch
A link checker, not a virus scanner. We check the address, not your files.
What it catches
Known-bad addresses
Checked against an offline threat list of ~88,000 entries.
Where the link really goes
Redirects are followed to the final destination.
Brand impersonation
paypal-secure-login.xyz is not PayPal, and the address says so.
Young domains
A domain registered days ago that asks for a password is a warning.
Broken encryption
http:// pages, expired, self-signed and mismatched certificates.
Reputation
VirusTotal's engines are consulted on links we cannot settle locally.
Two things it cannot do
We would rather say so than let you assume.
A brand-new scam page
Set up hours ago on a normal-looking domain with a valid certificate, no list knows about it yet. You may see only a mild warning.
A hacked real website
If a long-established site is broken into and one page serves something harmful, the address itself still looks perfectly normal to us.
We never say “Safe” while a warning is showing, and when a check cannot run we say so instead of guessing. Treat “Safe” as “nothing found”, not as a guarantee.
Privacy
- The link you check is sent to our API to be analysed. Nothing else is.
- Your history lives in this browser's local storage and never leaves it.
- No account, no tracking script, no advertising.
© 2026 Omnileb Tech