What the URL scan checks
The scanner normalizes a submitted HTTP or HTTPS URL, checks the hostname against the Phishing.Database active-domain feed, and checks hostnames found in the redirect chain. It also presents separate DNS, HTTP and WHOIS checks so you can see which signals completed.
- Exact hostname matching against a public phishing-domain list.
- Redirect host checks where the HTTP check can follow the destination.
- DNS records, response headers, registration data and scan status.
How to interpret results
A feed match is a warning that the hostname appears in that dataset. A miss is not proof a URL is safe: new or targeted threats may not be listed. This check does not execute the page, inspect its behavior in a sandbox, or analyze every URL path. Treat results as one input to a security decision.
Privacy and limitations
The URL scanner does not require a VirusTotal API key. Submitted URLs are checked by the ATROXIS service and public data providers used for the listed checks. Avoid submitting private, authenticated, or confidential URLs.