HomeFree Tools › Scam Email Checker
Free · Checks every link at once

Is this email a phishing attempt?

Do not click anything in it. Select the whole message, paste it below, and Scanify pulls out every link, unwraps the tracking redirects your mail provider added, and checks each destination separately.

Up to 20 links per paste · nothing stored No account · No card · Free
20
links per check
0
messages stored
7
signals per link
Free
no sign-up

Phishing works because a message arrives at a moment when its story is plausible. A delivery is genuinely due. A password genuinely did expire recently. An invoice from that supplier genuinely does arrive monthly. The attacker only has to be believable for the few seconds between reading and clicking.

This page removes the clicking from that sequence. Paste the message and every link in it is checked separately, so you can decide with evidence rather than instinct.

Why checking every link matters

A phishing email is rarely made of a single malicious link. It is usually one dangerous link surrounded by genuine ones, pointing at the real company's homepage, privacy policy and social accounts. Those real links are camouflage. They make the message look right if you spot-check one or two, and they help it past filters that judge a message by its overall reputation.

Checking all of them at once turns that tactic against the sender. When nineteen links go to a real bank and one goes to a domain registered four days ago, the message answers itself.

What Scanify does with the text

Nothing you paste is stored. The text is processed to extract links and then discarded. Only the extracted addresses are checked, so redact anything sensitive before pasting if you prefer, though it never leaves the request.

The warning signs no scanner can read for you

Urgency and threatened loss

Almost every phishing message manufactures time pressure: an account closing, a payment failing, a refund expiring, a delivery being returned. Urgency exists to stop you checking. Its presence is itself the signal.

An unexpected request to authenticate

Real organisations do not email you a link and ask you to log in to avoid a consequence. If an account genuinely needs attention, you will find the same message after navigating to the site yourself.

A sender address that nearly matches

Read the full address, not the display name, which is trivially forged. Look for extra words, hyphens, unusual endings and digits standing in for letters. A message from a free mail provider claiming to be a bank is finished right there.

A greeting with no name

"Dear customer" from a company that has had your name for years suggests a list rather than a relationship. Increasingly personalised phishing exists, so a correct name proves nothing in the other direction.

Requests for credentials, codes or payment details

No legitimate organisation asks for a password, a full card number or a one-time code by email. A one-time code request is particularly serious, because it usually means someone already has your password and is trying to get past the second factor in real time.

An attachment you did not expect

Invoices, receipts and scanned documents from unfamiliar senders are a standard malware delivery route. If you need to open one, check it first with the file scanner rather than opening it to see what it is.

What to do with the result

  1. Any link flagged high or critical: treat the message as an attack. Do not reply, do not click, and report it through your mail client so the provider learns from it.
  2. All links clean but the message feels wrong: trust the feeling. A brand-new phishing page can be clean for hours before any engine catches it. Reach the organisation through a number or address you already had.
  3. A link to a shortener: expand it with the link expander to see where it lands.
  4. Mixed results: one bad link among many good ones is the classic shape of a real phishing message, not a reason to relax.

If you already clicked or entered something

A note on what this tool is not

This checks the links in a message. It does not authenticate the sender, inspect mail headers for forged routing, or analyse attachments. Those are separate jobs. Header analysis in particular requires the raw source of the message and is the right next step when a message passes every link check and still looks wrong.

Frequently asked questions

How do I know if an email is a phishing scam?
Check the links without clicking them, which is what this page does. Then look at the human signals: manufactured urgency, an unexpected request to log in, a sender address that only nearly matches, and any request for a password, card number or one-time code.
Is it safe to paste an email here?
Yes. The text is used only to extract web addresses and is then discarded. Nothing is stored, and only the extracted links are checked.
What if the email has no links?
Then there is nothing for this tool to check. Messages with only an attachment or a phone number use different attack routes: check attachments with the file scanner, and treat any number in an unexpected message as untrusted rather than calling it.
Why did a link in a real company's email get flagged?
Legitimate marketing mail often routes links through tracking redirectors, which produces long redirect chains that look evasive. Read the individual signals in the result rather than the score alone. A long chain ending on the company's real domain is very different from one ending somewhere unrelated.
Can you tell me if the sender address is forged?
Not from pasted body text. Confirming a forged sender requires the raw message source and an analysis of its routing headers. This tool answers the more immediate question of where the links go.
All the links came back clean. Is the email definitely safe?
No. A phishing page put up an hour ago can pass every blocklist until someone reports it. If the message asks you to do something unexpected, verify through a channel you already trust regardless of what the link check said.

Other free Scanify tools

URL Scanner Phishing Checker QR Code Checker Link Expander Fake Website Checker Scam Email Checker Bulk Checker File Scanner