How to use Suspicious URL and Homograph Inspector
- Paste the address as text without visiting it.
- Run the inspection and compare the encoded host with its decoded Unicode form.
- Read script and character observations alongside the host, path and any username segment.
- Treat the findings as clues; verify the intended destination separately before trusting the link.
Example: Suspicious URL and Homograph Inspector
Inspect a host that mixes visually similar characters.
Options
- URL to inspect without opening
- Up to 4,096 characters. The host is decoded locally; no link is visited and no reputation service is queried.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Read the host rather than an attractive path
A brand name in a path or username does not establish the site’s identity. The parsed host identifies the destination in the supplied address. Similar-looking Unicode letters can belong to different scripts and represent a different host. Review both encoded and decoded forms instead of relying on appearance alone.
A clean-looking address can still be unsafe
The inspector performs local syntax and character analysis, not malware detection, DNS lookup, certificate verification or a reputation check. Absence of a mixed-script observation is not proof of safety. Use a destination you independently know, particularly for sign-in or payment tasks, rather than opening a doubtful address to test it.
Questions about Suspicious URL and Homograph Inspector
Does inspection visit the link?
No. The page parses the entered text locally.
Is a punycode domain automatically harmful?
No. Punycode also represents legitimate internationalized names. Compare the decoded label with the name you expected.
Does a clear result prove a URL is safe?
No. These are structural observations, not a reputation or content check.