Works with full URLs, shortened links, and bare domains.
Found this useful? Leave a review on Trustpilot ↗
🔒 URLs you submit are never stored, visited, or shared. Analysis is performed server-side and the URL is discarded immediately after your result is returned. Results are for informational purposes only. Scamanot does not guarantee the safety or legitimacy of any URL.
Know What You're Looking At
How scammers hide in plain sight.
Phishing URLs are designed to look legitimate at a glance. Here's how to read a URL — and the tricks scammers use to fool you.
Anatomy of a phishing URL
- Fake brand name — looks real, isn't
- Actual domain — always after the last dot before the first slash
- Path — can be designed to look official
The real domain is always what appears immediately before the first / — not what scammers write before it. In the example above, PayPal has nothing to do with this URL.
`paypal.evil.com` — PayPal is the subdomain, not the domain. The real site is evil.com.
`arnazon.com`, `paypa1.com`, `g00gle.com` — one character off from a trusted brand.
`.ru`, `.cn`, `.tk`, `.ml` endings on URLs claiming to be US institutions are a major red flag.
bit.ly, tinyurl, t.co — legitimate uses exist, but scammers use them to hide the real destination.
`xK9mP2-verify.com` — newly registered domains with no history, built specifically for one scam campaign.
`/verify-now`, `/account-suspended`, `/urgent-action` — path names designed to create panic before you look closely.
Common Questions
Before you paste that link.
More Scamanot Tools
The link cleared. Now investigate everything else.
Straight Answers
The questions people ask most — answered directly.
Will checking the URL visit the website?
No — and this is a critical point. Submitting the URL to our checker does not cause your browser to visit it. All analysis is performed server-side through a Cloudflare Worker that examines the URL structure, domain registration, and threat intelligence without ever loading the page in a browser. You are never exposed to the destination.
Can I check a shortened URL like bit.ly?
Yes. Paste the shortened URL exactly as it appeared. Our analyzer resolves shortened links server-side to examine the final destination without exposing you to it — one of the most dangerous features of shortened URLs is that you can't see where they go until it's too late.
What if the URL comes back clean but I'm still suspicious?
Trust your instincts. A clean result means no known threat signals were detected — not that the site is definitively safe. Brand new phishing sites won't yet appear in threat databases. If the context around the link is suspicious (unexpected message, urgency, request for personal info), don't click regardless of our result.
Does HTTPS mean a URL is safe?
No — and this is one of the most dangerous misconceptions online. HTTPS means the connection is encrypted, not that the site is trustworthy. Scammers routinely use HTTPS on phishing sites. The padlock icon in your browser does NOT mean the site is legitimate. Always check the actual domain, not just the protocol.
Why Scamanot Exists
Built by someone who's been there.
Scamanot was founded by Robert Scott Singleton — 63 years old, online since 1992, and a scam victim more times than he cares to count. Car dealers. Email schemes. Fake online sellers. He watched fraud grow from an obscure curiosity into a billion-dollar catastrophe targeting everyday people.
"When it happens, you don't say anything. You just go quiet. Forget about it. Move on. That's what I did for decades. That's what most people do. And that silence — that's exactly what scammers are counting on."
So he built something about it. Every tool on Scamanot is AI-powered, free to use, and built on one principle: nobody should have to just go quiet and move on. Your searches are never stored. The AI runs server-side only. We find the truth. We never expose yours.
Founder
Robert Scott Singleton
Founded
2026
Online since
1992
Data stored
Zero. None. Ever.