Take a link apart
Before you click, find out where a link really goes. Paste it: you get its real domain, the parts anyone can make up, and the tricks used to make it look legitimate.
Try with:
How do you read a web address?
A web address is read from the right, not from the left. The part that counts is the domain someone actually bought, just before the extension. Everything to its left is free text, chosen by the owner of that domain.
So in paypal.securite-client.xyz, the domain bought is securite-client.xyz. The word paypal at the front was simply added by its owner, exactly as you could add it to your own domain. On a phone, where the address bar is short, only that beginning is visible.
What tricks does this tool spot?
The analysis is purely structural, and covers the patterns seen most often:
- a well-known brand placed in a subdomain or in the path, while the domain belongs to someone else
- a domain containing a brand name without being that organisation's official domain, the ameli-remboursement.fr pattern
- letters borrowed from another alphabet, a Cyrillic a inside apple, invisible to the eye
- the @ trick, where everything before the sign is only decoration
- link shorteners, risky extensions, executable files, open redirects and tracking parameters
What this tool cannot tell you
It reads the address, nothing else. It never opens the link, so it cannot know what the page contains, nor follow a shortener to its destination. A clean verdict means the address holds no visible trap: it does not mean the site is honest. A legitimate domain can be compromised, and a perfectly ordinary address can host a scam.
Frequently asked questions
Is the link sent somewhere when I analyse it?
No. The whole analysis runs in your browser, from the text of the address alone. Nothing is sent to our server or to any third party, and the link is never opened. You can cut your connection and the tool still works.
How do I find the real domain of a link?
Read the address from the right. The real domain is the last two parts before the first slash, for example securite-client.xyz in paypal.securite-client.xyz. Anything to the left of it is chosen freely by the owner of that domain.
Why can a link look like apple.com and not be?
Because some letters of other alphabets are visually identical to Latin ones. A Cyrillic a inside apple gives an address that looks perfect on screen but points to an entirely different domain. The tool flags this mixing of alphabets.
Can the tool follow a shortened link?
No, and that is deliberate: following it would mean opening the link, therefore sending a request. The tool tells you the destination is hidden, which is precisely the useful information.
Does a clean verdict mean the site is safe?
No. It means the address itself carries no visible trap. A legitimate domain can be compromised, and an ordinary address can host a scam. Keep the usual reflex: never enter a password or bank details on a page reached from a message.
Other tools

Don't miss the next analysis