Lookyloo Website Analysis

Lookyloo is CIRCL’s public service for examining websites. It captures a page in a browser and displays a tree of the domains, requests, redirects, and resources loaded while visiting it. This helps analysts understand the behavior of a suspicious link without opening it in their own browser.
Users who encounter a suspicious URL in an email or while browsing can submit it to the online Lookyloo instance.
How to use the service?
Open the Lookyloo capture page, enter the URL to investigate, and start the capture. Lookyloo loads the page in an isolated browser and makes the resulting analysis available through its web interface.
Do not submit URLs containing credentials, access tokens, personal information, or other sensitive data to the public instance.
What does the service show?
Lookyloo records and presents the activity generated by the captured page, including:
- the redirect chain followed by the browser;
- the hostname and URL tree for loaded resources;
- HTTP requests and responses;
- cookies and other contextual information from the capture; and
- indicators that can support further investigation.
The results provide investigation context; they are not a guarantee that a URL is safe or malicious.
Can I run my own instance?
Yes. Lookyloo is open-source software. See the Lookyloo source-code repository for its documentation, installation instructions, and ways to contribute.
How do I report a malicious URL to CIRCL?
Lookyloo is an analysis service, not an incident-reporting form. If the capture confirms suspicious or malicious activity, follow CIRCL’s guidance for reporting an incident.