Security guides

How URL Radar Analyses a Suspicious Link

See how URL Radar combines bounded fetching, explainable detection rules, isolated rendering and privacy-safe correlation.

Radar validates the target, collects bounded evidence, correlates independent signals and reports both findings and analysis limits.

1. Validate the public destination

Radar accepts public HTTP and HTTPS URLs and blocks private, loopback, metadata and system network ranges. Redirect destinations are validated at each hop.

2. Collect a bounded response

Strict time, size, redirect and concurrency limits reduce abuse. Static analysis examines the response without executing scripts or opening downloads.

3. Apply explainable checks

Independent rules examine URL structure, reputation, domain and hosting context, TLS, redirects, page content, forms, scripts, clipboard behaviour and file-delivery signals. Findings retain a reason and severity.

4. Use isolated rendering selectively

Eligible scans may run in a separate credential-free browser environment. It records bounded network and behaviour evidence, may perform one controlled verification interaction and never submits forms or runs system commands.

5. Correlate without overstating

Radar combines related signals and can identify privacy-bounded shared infrastructure across eligible public reports. Correlation informs investigation but does not independently make a malicious verdict.

6. Show limits

Challenges, timeouts and incomplete coverage are labelled. A low score means strong warning signs were not observed in the available evidence; it is not a guarantee of safety.

Read the complete methodology

Continue learning

Explore the detection catalogue.

Browse detectionsCheck a link