When to use it
You received a suspicious link or email. You want to check passive traces without opening risky content.
Phishing workflow
A workflow for checking a link without opening it in a risky way or entering data.
Passive and safe research workflow
When to use it
You received a suspicious link or email. You want to check passive traces without opening risky content.
What you get
Phishing assessment note, confidence level, sources, and suggested defensive action.
Safety boundary
This workflow is not for exploitation, probing, or unauthorized scanning. It reads public records, records dates and uncertainty, and avoids turning signals into final claims.
Simple order
Record domain, path, parameters, and redirects without signing in.
Check: No credentials or sensitive data are entered.
Read SPF, DKIM, DMARC, sender alignment, and header anomalies.
Check: Header results are not treated as the only proof.
Check RDAP, DNS, certificates, archives, and reputation sources.
Check: New registration or lookalike signals are dated.
Add confidence, false-positive limits, and a safe response option.
Check: No live exploitation or bypass step is included.
Real tools to open
Report language
The URL shows phishing-like signals in passive sources; it should be handled as a defensive triage finding, not as a final attribution.
Move to evidence notesSources
Access Now Digital Security Helpline
OPSEC and researcher safety
Use to protect the researcher, reduce exposure, and avoid unnecessary collection.
Open sourceAlienVault OTX
Threat intelligence
Use for IOC context, reputation checks, and defensive security notes.
Open sourceCISA Cybersecurity Best Practices
OPSEC and researcher safety
Use to protect the researcher, reduce exposure, and avoid unnecessary collection.
Open sourceDNSDumpster
Domain and DNS intelligence
Use for domain ownership context, DNS records, certificates, and passive web traces.
Open sourceDNSViz
Domain and DNS intelligence
Use for domain ownership context, DNS records, certificates, and passive web traces.
Open sourceEFF Surveillance Self-Defense
OPSEC and researcher safety
Use to protect the researcher, reduce exposure, and avoid unnecessary collection.
Open source