Look before
you click.

Paste any address. We open the site in a sealed sandbox, run passive security checks, and only then let you continue.

0t.link/

Every link gets checked.
Even the ones you trust.

That’s zero trust: a free pass because a name looks familiar is how people get phished. The check takes a few seconds and appears before anything reaches your decision.

1

We open it, not you

The site loads in a throwaway browser on our side. Nothing reaches your cookies or session.

2

We run the checks

Certificate, domain age, lookalikes, redirects, reputation, and hidden text, all at once.

3

You decide

You see the preview and a plain-English verdict. Go through, wait, or keep the report.

When something’s off, you’ll know why.

No vague warning. You get the exact reason, so you can make the call.

0t.link/payp0l-verify.example
  • Registered 3 days ago
  • Looks like paypal.com with a 0 in place of the o
  • Password form posts to another domain

The same checks, for AI agents.

Add 0t as an MCP server and your agent checks every URL before it fetches it. Pages come back as clean text, with hidden instructions stripped out.

Free for people. The same engine for agents at https://0t.link/mcp.

{
  "mcpServers": {
    "0t": { "url": "https://0t.link/mcp" }
  }
}