OSINT Radar
Web & URL OSINT Operational

URL Void

www.urlvoid.com

URL Void checks website reputation and blacklist status across 30+ security engines to assess whether a URL is safe or malicious.

Free Open Source #URL Void #Web & URL OSINT tools #Web & URL OSINT resources #website #url #reputation #void #analysis #assessment #blocklist
Open tool

Pivot map

You have url domain
You get page content infrastructure mentions

Use this map to decide whether URL Void accepts the lead you are holding, and what kind of lead it may return for the next step.

Pivot from here

Outputs from URL Void can become inputs for the next tool. These are the most relevant follow-on pivots in the library.

Investigator Use

URL Void is a free website reputation and safety checker that queries multiple security databases and blacklists simultaneously to assess whether a URL or domain is malicious. For security analysts, OSINT investigators, and anyone evaluating suspicious links, URL Void provides rapid aggregated threat intelligence from dozens of sources in a single query.


The service queries over 30 security vendors and reputation services including Google Safe Browsing, SURBL, PhishTank, MalwareBytes, Fortinet, McAfee, Comodo, and others. Results show which specific engines flagged the URL as malicious alongside a total detection count — similar to how VirusTotal aggregates antivirus scan results for files. A URL flagged by many independent services carries significantly higher confidence of being malicious than one flagged by a single engine.


For OSINT investigations, URL Void is a standard first-pass check when encountering a suspicious URL in a phishing report, threat intelligence feed, or social media post. The aggregated view saves time compared to checking each security vendor individually, and the historical data shows whether a domain has a prior history of malicious use — even if current flagging is minimal.


The domain age indicator in URL Void results is an important contextual signal: very new domains (registered within days or weeks) are higher risk, as established legitimate businesses typically have older domains. High detection counts combined with a very recent registration date is a strong indicator of a newly launched malicious campaign.


URL Void also supports IP address lookups, checking the reputation of specific IP addresses against the same database network. This is useful when investigating the hosting infrastructure behind suspicious domains — checking whether the same IP hosts other known-malicious domains.


The API allows programmatic queries for integration into SOC workflows, SOAR platforms, and custom threat intelligence tooling.


Limitations include coverage of novel threats — URL Void relies on prior reporting from security vendors, so very new attacks may not yet appear in any database. The service is most reliable for known threats and infrastructure with established reputation. Pair with URLScan.io and manual analysis for comprehensive coverage.


Record the query date, flagged engines count, and total engine count when documenting URL Void results in security reports.

Before You Pivot

Record Context

Capture the target, search terms, and why this source is relevant before you leave the page.

Preserve Evidence

Archive volatile pages, save screenshots, and keep timestamps for anything that may change.

Corroborate

Treat one tool as a lead source. Confirm important findings with independent sources.

Related tools