VirusTotal check
See whether security vendors flag a domain for malware, phishing, spam or anything suspicious, what each one says, and how VirusTotal’s community rates it.
Questions
What does this check?
It reads VirusTotal’s report for the domain: the latest verdict of each of about 90 security vendors (antivirus companies, URL blocklists and threat-intelligence feeds), the categories vendors assign, and the community score from VirusTotal users. It doesn’t scan the site itself or open any link.
How should I read the result?
Three or more vendors calling a domain malicious is a strong signal: treat its links as dangerous. One or two detections are often false positives, especially for new domains or shared hosting, so look at what each vendor says. “Suspicious” is weaker than malicious. A clean result means no vendor flags it today; brand-new phishing sites can go unnoticed for hours.
Why is the result a few hours old?
VirusTotal’s free API allows only a few lookups a minute, so each domain’s report is kept for 6 hours and shared by everyone who checks it. The date VirusTotal last analysed the domain is shown with every result. For a fresh analysis, open the domain on VirusTotal and ask it to rescan.
My domain is flagged by mistake. How do I fix it?
VirusTotal only shows what each vendor reports, so the listing has to be fixed by that vendor. Find the vendor’s false-positive or review form, explain what the domain is, and ask it to re-check. Clean up first if the site was compromised. VirusTotal picks up the change at its next analysis.
What does “VirusTotal has no report” mean?
No one has submitted or scanned the domain on VirusTotal yet, so no vendor has a verdict. That is common for new or little-used domains and says nothing either way about safety.
Who sees the domain I check?
The domain is sent from our server to VirusTotal (owned by Google), which may keep a record of lookups. Your IP address isn’t sent, the API keys stay on our server, and tanase.ai doesn’t log what you check.