TruthLens tools
Paste a link and read how it is built — which site you would actually be visiting, whether the characters are what they appear to be, and what the query string will do. Everything is parsed in this tab.
Paste any link — from a text message, an email, or a post. You will see which site you would really be visiting, and what to look at before you open it.
Nothing you type leaves this browser tab. 2000 character limit.
This tool never navigates to the address you paste. It does not visit the link on your behalf.
This cannot tell you if a site is safe. It reads the shape of a link, nothing more. HTTPS does not prove a website is trustworthy and suspicious-looking syntax does not prove it is malicious. A link-only check cannot find every phishing page — no tool can. When in doubt, do not enter passwords or payment details.
The registrable domain is the last two labels before the first slash — in https://login.secure.bank-example.com.verify/account that is verify.com. Everything left of it was chosen by whoever controls that domain and can be made to say anything. This is the single most useful thing to check, and it takes two seconds.
It performs no DNS lookup, no WHOIS query, no reputation check against a blocklist, and no malware scan — those need either a paid API or a service that rate-limits aggressively. It also never requests the URL, which is deliberate: a tool that visited arbitrary pasted addresses on the user's behalf would be an abuse vector, and sending them to a backend would make the backend vulnerable to request forgery.
No, and nothing that only looks at a link can. Phishing pages hosted on compromised legitimate domains look completely ordinary. What this does is show you which site you would really be going to, so you can compare that with who you expected.
Because subdomains, punycode and non-standard ports are all used by real services. Each signal here states what it does not prove for exactly that reason. The flags are prompts to look closer, not verdicts.
No. HTTPS encrypts the connection so others cannot read it — it says nothing about who runs the site. Every phishing page can have a valid certificate, and most do.
No. That requires either a paid API or a public list that rate-limits hard, and a blocklist result is easy to over-trust. This stays entirely in your browser so you can read the reasoning yourself.
Never. Nothing is fetched, from your browser or from any server. That is a safety property, not a limitation — a tool that visited pasted addresses would expose the site that runs it to being used as a request proxy.
Read the registrable domain yourself, ask whether you expected the message, and never enter details through a link that arrived unexpectedly. If it looks wrong, go to the site by typing the address.