Phishing & URL Scanner
Live

Decide before you click.

Paste a URL. Dralvia returns a verdict in seconds, with the exact signals that triggered it, no black box, no "the model says trust me." Every finding is traceable, exportable, and ready for the next analyst on the rotation.

No account for your first scan100+ signals checkedEvidencePack export
Product preview

URL scanning

See Dralvia in action.

Submit a URL, choose the scan depth, and follow progress and results from one place.

  • Paste a URL or domain
  • Choose fast or deep review
  • Follow the queue and result history

This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Dralvia URL & Phishing Scanner workspace preview
Product preview · URL & Phishing Scanner
Signal coverage

100+ signals. One verdict. A full chain of custody.

Every verdict is the sum of evidence, not a probability from a model you cannot inspect. Here is what Dralvia checks on a single URL.

Typosquatting & brand impersonation

Damerau-Levenshtein distance, homoglyph substitution (Cyrillic / Latin), subdomain abuse, and IDN punycode unwrapping checked against a brand watchlist.

Domain age & registration

Registration date, registrar reputation, privacy-proxy use, and recent ownership changes, newly registered lookalikes are flagged immediately.

DNS & infrastructure

A / AAAA / NS / MX consistency, shared-host clustering, IP reputation, and reverse-DNS sanity to spot disposable hosting.

TLS & certificate

Issuer, SAN list, validity window, certificate-transparency log appearances, and certificate reuse across known-malicious siblings.

Redirect-chain capture

Hop-by-hop unwrap of meta-refresh, JavaScript, and 30x redirects, with every intermediate URL re-scored, the final destination is never trusted just because it looks clean.

Page content & form analysis

Cloned login pages, credential-exfil endpoints, hidden fields, and known phishing-kit fingerprints.

Threat-intel cross-reference

Live cross-check against OpenPhish, PhishTank, and URLhaus, plus Dralvia's own continuous crawl of new infrastructure.

Behaviour history

How the domain has scored over time, how often it has been queried, and whether the verdict has changed since the last scan.

How it works

From paste to verdict in seconds.

01 · Ingest

Paste anything URL-shaped

Full URL, root domain, shortlink, redirector, or a deep query path. Dralvia normalises and detects the input type before routing.

02 · Analyse

100+ checks run in parallel

Network probes, content fetches, threat-intel cross-checks, and classifiers fire concurrently. Each is timeboxed and independently scored.

03 · Verdict

Score, evidence, action

A clear risk verdict, structured findings, redirect capture, and a one-click EvidencePack (PDF or JSON). Block, monitor, or share from the same screen.

Seconds
Typical scan time
100+
Signals per verdict
5
Risk levels surfaced
PDF · JSON
EvidencePack formats
Built for the team that gets the ticket

Phishing triage that ends in an action, not another tab.

A permalink for every result

Each scan gets a stable link. Hand it to the next analyst, drop it in chat, or attach it to a ticket, the verdict reproduces with full evidence.

Redirect-chain unwrap

Shortlinks, meta-refresh, JavaScript hops, and tracker bounces are followed and re-scored. A clean-looking final page is never trusted on its own.

Pattern memory

If a kit you have seen before reappears at a new domain, Dralvia surfaces it, phishing-kit fingerprints, shared infrastructure, and recycled login pages all cluster.

Continuous monitoring

Add a target to watch. Dralvia re-scans on a schedule and alerts via email or webhook when the verdict changes, useful for brand monitoring and IR.

EvidencePack export

Every finding, signal, header dump, and redirect capture bundled into a single artifact, for compliance, customer comms, and IR handoff.

API + SDKs

The same engine is available as a REST API and Python / JavaScript SDKs. Pipe gateway, ticketing, or browser-extension events into Dralvia and bring verdicts back inline.

Who uses it

For people who need the verdict, not the lecture.

SOC analysts

Triage user-reported emails in seconds. The verdict, signal trail, and EvidencePack become the ticket body, no more screenshots and narration.

IT & help desk

Paste the URL a user clicked. Get a one-page verdict you can show them, plus an artifact your security lead can audit later.

Managed service providers

Per-workspace scoping, API access, and brand-monitor alerts. Wrap Dralvia into your own portal, or run it standalone for client triage.

FAQ

Honest answers.

Dralvia is a verdict and evidence engine that returns a structured risk decision you can act on. Inline blocking is delivered through the Dralvia browser extension and Secure Web Gateway, both live today. For most teams the API plus extension combination is the path to in-line enforcement.

Scan your first suspicious URL.

No account required for your first analysis. Paste a URL, see the full evidence chain, and decide whether it leaves your inbox.