Check a link before you tap it.

Paste a link from a text, an email or a message and see where it actually goes, and what about it looks wrong.

This runs on your own device. The link is never sent to OneHaven and we never open it. There is one optional extra step, clearly marked, that looks up the domain name with the public registry. Nothing else you paste here ever leaves your phone.

You can paste the whole text message. We will find the link in it.

What this can and cannot tell you

It can tell you what the address itself says. Which domain actually owns it, whether the name you recognise is really the owner or just a label, whether the characters are what they appear to be, and whether the link hides its destination.

It cannot tell you a link is safe. It does not open the link, follow redirects, or check anyone's list of known bad sites, because doing that would mean sending your link to a server. A brand new scam page on a perfectly ordinary looking domain will pass every check here. Nothing stood out is not the same as this is fine.

If you are unsure, the answer is always the same and it always works: do not tap it. Go to the company yourself, through their app, your own bookmark, or the number printed on your card.

How to read a web address

This is the most reliable check there is, and you can do it without any tool at all.

  1. Find the last part before the first single slash. That is the domain.
  2. Read it backwards from the dot. The real owner is the word immediately before the .com, .net or .org. Everything in front of that is just a label, and anyone can put any label there.
  3. Everything after the first slash belongs to whoever owns that domain. It cannot change who they are.
yourbank.example/alerts/verify   belongs to yourbank yourbank.secure-verify.example/alerts   belongs to secure-verify yourbank-support.example   a different domain anyone can buy

If you already tapped it

Tapping a link is usually not the moment things go wrong. Entering something is. If you did not type a password, a card number or a code, the realistic risk is low: close the page, and do not go back to it.

If you did enter something, move quickly. Change that password from a different device, starting with your email, then call your bank on the number printed on your card. There is a full walkthrough on the scam library page, including who to report it to.