1. Paste a link or email
Copy a URL or the body of a suspicious message and paste it into Cactus.
Online safety help
Beyond links and emails, Cactus checks texts, websites, passwords and more — with simple how-to guides and a weekly scam alert to help you stay ahead.
Checking an email's content instead? Check an email New here? Start here → 🌵 The Daily Scam
Paste a link and see where it really goes, before you click.
Paste a text, WhatsApp or Messenger message and we point out the scam signs.
Paste the email. We check every link and look for the usual phishing tricks.
Upload a photo of the code and we read the link hidden inside it.
Gift card, e-transfer or crypto - see which payments can't be undone.
Paste a file's hash (its fingerprint) to see how many antivirus engines flag it.
Paste up to 20 links, one per line, and get one table with all the results.
Check the site's certificate and encryption, and get a grade from A+ to F.
A site registered last week is a red flag. See its age, owner and registrar (WHOIS).
Enter a real domain to see the look-alike (typosquat) versions scammers register.
Check it against billions of leaked passwords. It never leaves your browser.
See which companies leaked your address, so you know where to change your password.
Get a random password, or a passphrase you can actually remember.
Photos carry hidden GPS and camera data (EXIF). Strip it without uploading anything.
See your public IP and what it reveals about you.
These are for people who run a website, a domain, or company email.
Check whether SPF, DKIM and DMARC are set up to stop spoofing, and get a grade.
Answer two questions and copy the exact SPF and DMARC DNS records into your zone.
Grade the HTTP security headers your site sends - HSTS, CSP and the rest.
Every certificate ever issued for a domain is public. See what those CT logs reveal.
Certbot timing out, a CAA error, DNS not propagated? We run Let's Encrypt's own (ACME) checks and explain the failure.
See a domain's A, MX, NS, TXT and CAA records in one place.
See who owns an IP and whether it's on public spam or abuse blocklists.
Enter an address with its prefix (CIDR) for the network, broadcast and host range.
Scam of the week
Marketplace scamA sold-out show, a stranger selling tickets at face value, and a request to e-Transfer first. The tickets never arrive - or were sold to a dozen people - and an accepted e-Transfer is almost impossible to get back.
Copy a URL or the body of a suspicious message and paste it into Cactus.
Cactus looks for common warning signs — lookalike domains, urgency wording, known unsafe matches — and gives a confidence percentage.
You get plain-language reasons and a recommended next step before you click.
Yes. Every tool on Cactus is free and bilingual, with no account or sign-up required. If you find it useful, you can support the project with a small donation.
Paste the URL into the link checker. Cactus inspects it for phishing signs, lookalike domains, suspicious redirects, the domain's age, and matches against threat-intelligence sources, then gives a clear safety score.
Don't click any links or download attachments. Paste the email into the email checker, which analyzes its links, urgency wording, and sender headers, and explains the risks in plain language.
Phishing is a scam where attackers impersonate a trusted person or company to trick you into clicking a malicious link, entering a password, or sharing personal information. Cactus helps you spot these attempts before you act.
Cactus processes each check on the server to produce your result and doesn't require an account. See the Privacy page for exactly what each tool sends to third parties and what is kept.
Run into a term you don't know? Browse the plain-language security glossary