Advanced URL phishing detection — Heuristics + Google Safe Browsing + VirusTotal

0
URLs Scanned
0
Threats Found
15+
Detection Signals
Try:
Try:
Try:
Accepts:
Detects: spoofed senders · urgency tactics · phishing URLs · brand impersonation
- -
Scanning in progress
🔍
Heuristics
Waiting...
🛡️
Google Safe Browsing
Waiting...
🔬
VirusTotal
Waiting...

0/ 100
Risk Indicators
URL Features

How phishing detection works

🎯 What is PhishRadar?

PhishRadar analyzes URLs, IP addresses, domains, and file hashes to detect phishing attempts and malicious content. It combines three independent detection layers — each with different strengths — for maximum accuracy and coverage.

🔍 Detection Layers
🔍 Layer 1 — Heuristic Analysis
Instant

Analyzes 15+ structural signals in the URL itself — no external API needed. Works entirely offline and returns results immediately.

● IP address used as domain
● No HTTPS encryption
● Suspicious TLD (.xyz, .tk, .ml...)
● Brand name impersonation
● Unusually long URL
● High URL entropy (random-looking)
● Multiple hyphens in domain
● Suspicious keywords (login, verify...)
● Encoded characters (%20, %2F...)
● Excessive subdomains
● Many digits in domain
● Newly registered domain (WHOIS)
🛡️ Layer 2 — Google Safe Browsing API
~1 second

Checks the URL against Google's constantly updated threat lists — the same database Chrome uses to show "This site may be harmful" warnings. 10,000 free requests/day.

Malware Phishing / Social Engineering Unwanted Software Potentially Harmful Apps
🔬 Layer 3 — VirusTotal API
~15 seconds

Submits the URL to 70+ antivirus and security engines simultaneously. Each engine independently determines if the URL is malicious, suspicious, or clean. The more engines that flag it, the higher the risk score boost.

📧 Email Scanner — Phishing Email Analysis
Instant

Paste any suspicious email (with headers and body) to get a structured phishing risk score. Works without any external API — all analysis runs locally using header inspection and URL heuristics.

● Spoofed sender domain
● Reply-To ≠ From mismatch
● Brand impersonation in From address
● Urgency keywords in subject line
● Phishing keywords in body
● Suspicious/malicious embedded URLs
● HTML-heavy email body
● Supports raw email + headers
📊 Risk Score Explained
0–39
LIKELY SAFE
No significant signals detected across all layers
40–69
SUSPICIOUS
Some signals detected — proceed with caution
70–100
PHISHING
High confidence threat — do not visit this URL
🔎 Lookup Tools
🔗 URL Scanner

Full 3-layer analysis of any URL. Combines heuristics, Google Safe Browsing, and VirusTotal for the most comprehensive result.

🌐 IP Address

Check if an IP is known for hosting malware, phishing pages, or command-and-control servers. Shows country, ASN, and 94 engine verdicts.

🏠 Domain

Full domain reputation check — registrar, age, categories, and engine verdicts. Older domains with clean history are more trustworthy.

🔑 File Hash

Check if a file (by MD5/SHA1/SHA256) is known malware — without uploading or opening it. Instant lookup against 76+ engines.

📧 Email Scanner

Paste a raw email (headers + body) and get a full phishing analysis — detects spoofed senders, Reply-To mismatches, urgency tactics, brand impersonation, and scans every embedded URL.

⚠️ Disclaimer

PhishRadar is a security research and educational tool. A clean result does not guarantee a URL is safe — new phishing pages may not yet be indexed. Always exercise caution with unsolicited links.