URL Safety Checker
Check a link against reputable threat-intelligence databases before you open it. Results are attributed to each provider — Zurl never claims a URL is guaranteed safe.
How to use the URL Safety Checker
Step 1: Paste the link you are unsure about.
Step 2: Select Check safety.
Step 3: Read what each threat-intelligence provider reported.
What this check can and cannot do
Threat databases are built from millions of reports and automated scans. When a URL is on one of them, that is a strong signal — browsers block those pages outright. What a database cannot do is vouch for a page nobody has reported yet. That is why the result says “no known threat”, not “safe”.
Other warning signs
- The link arrived unexpectedly, especially with urgency (“your account will be closed”).
- The domain is close to, but not exactly, one you know — check it with the URL parser, which flags look-alike characters.
- A short link hides the destination — resolve it first with the URL expander.
- The page asks for a password or payment details you would not normally enter there.
Report abuse of a Zurl link
If a zurl.world short link leads somewhere harmful, report it. When a threat-intelligence provider is configured, Zurl also refuses to create short links to destinations the provider classifies as malicious.
Frequently asked questions
- How does the URL safety checker work?
- Zurl sends the URL to the configured threat-intelligence services — Google Safe Browsing and/or VirusTotal — and shows exactly what each one reported. Zurl does not invent its own verdict and does not visit the page.
- Does “No known threat detected” mean the link is safe?
- No. It means the providers have no record of the URL being dangerous. New phishing pages appear every minute and may not be listed yet. Treat unexpected links with caution whatever this tool says.
- What is the difference between suspicious and malicious?
- Malicious means a provider classifies the URL as phishing, malware or unwanted software, or several security vendors agree it is harmful. Suspicious means a weaker signal — for example a single vendor flag. Unable to determine means the providers have no information either way.
- Which providers are used?
- Google Safe Browsing, which powers the warnings in Chrome, Firefox and Safari, and VirusTotal, which aggregates results from dozens of security vendors. Each result is labelled with its source.
- Is the URL shared with third parties?
- Yes — checking a URL means sending it to the providers listed. Do not check URLs containing private tokens or personal data. Zurl caches results for about 30 minutes and does not keep a history of what you checked.