You can inspect a suspicious link without opening the page on your own computer. Paste it into urlscan.io, and the service visits it in a remote browser. The report shows what happened during that visit and usually includes a screenshot. Choose the scan's visibility before you submit, and keep private links out of public scans.
In a public scan from August 26, 2026, urlscan flagged a page as potentially malicious and named Ledger as the brand it appeared to impersonate. It also records where the scan ran and where the link led.
The report for the suspected Ledger phishing page

What the scanner records
The report includes redirects, contacted domains and details of the page's secure connection. Those records describe one observed visit, not everything the site could ever do. A site can also change its response based on which browser it thinks is visiting.
Urlscan can flag suspected copies of brands it tracks, but its FAQ warns that the checks can be wrong. It records files downloaded during a scan without deciding whether those files contain malware. The report gives you evidence to inspect, not a promise that the link is safe.
Detection limits in urlscan's FAQ, how sites identify visiting browsers
Copy without opening a preview
On a desktop, right-click the link and choose the command that copies its address. Paste that address into the scanner. The words displayed in a link can hide a completely different destination, so copy the address rather than retyping its label.
On an iPhone, touching and holding a link in Safari opens a preview of the page. Use a desktop to copy a suspicious address if you aren't sure how your phone handles previews. Don't follow links out of the scan report if your aim is to avoid visiting the suspect site.
Check who can see the scan
Before submitting anything, check the visibility setting. Public scans appear on urlscan's front page and in its public search. Search engines can see them too. In 2022, Positive Security found password-reset links, shared documents and other private material in public scan records, some submitted by automated security tools.
The unlisted setting keeps a scan out of public search, but vetted researchers and commercial customers can still access it. The private setting restricts search access to you and, if your team account is set active, its members. You're still sending the link and the page it opens to urlscan. A private report can also be opened by someone who knows its unique link.
Don't submit password-reset links or confidential pages unless you're comfortable sharing them with the service. Sensitive information can appear on the page even when the address looks harmless. The screenshot below shows the visibility control to check before you submit.

Positive Security's scan-leak research, Urlscan's visibility guidance
An old scan can't show changes made after it ran. A fresh scan gives you a fresh observation, but a missing warning still doesn't establish safety. Leave your browser's phishing and malware warnings turned on and use the report to investigate the link before deciding what to do with it.





