Paste a link (URL) — we flag phishing/impersonation risks from its structure alone. No model, no lookup, no upload. A rough guide.
Paste a link (URL) — we flag phishing/impersonation risks from its structure alone. No model, no lookup, no upload. A rough guide. Free with no sign-up, and the analysis runs inside your browser — files never leave your device. On our public gate (30 real + 52 AI images) it measured 96.3% at original quality and 91.5% on recompressed copies, with zero real photos confidently mislabelled as AI. Treat it as an indicator, not proof: the newest commercial generators evade every detector.
Before you click a link (URL) from a text, email or social message, estimate its phishing/scam risk from the address structure alone. It analyses only the URL string without visiting the page, so it is safe.
Fake sites imitate real domains. A classic trick puts a well-known brand name in a subdomain or prefix while the real domain is unfamiliar — naver-login.com, kakao.security-check.co. Look-alike characters (o as 0, l as 1 — homographs) are common too.
Shortened URLs (bit.ly, etc.) hide the final destination, so be careful when the source is uncertain. An @ sign in the address, an excessively long path, a raw IP-address link, and unusual top-level domains (.zip, .top) all add risk.
The padlock (HTTPS) in the address bar only means the connection is encrypted — not that the site is honest. Most phishing sites now use HTTPS too. Entering login or payment details because "there's a padlock" is the most common mistake.
The real check is the second-to-last part of the domain. login.naver.com belongs to naver.com, but naver.login-secure.com belongs to login-secure.com — someone else's site.
No. It analyses only the structure of the URL string and never actually connects. Check freely.
It only means few structural risk signals. A freshly created phishing domain can look clean, so always reach login/payment through official routes.