Skip to content

CS2 Scam Link Checker

Short answer

Paste any link you were sent before logging in. The checker compares it with the real Steam and marketplace domains and flags lookalikes, like extra letters or swapped characters. It also checks an open list of over 10,000 known phishing domains. Never enter your Steam login on a page you reached from chat.

Try:

We never open the link. The checks run in your browser. Only the domain name is sent to our server to look it up in the phishing list.

Suspicious

Real destination: steamcomminity.com

This link has warning signs of a fake site. Do not log in. Open the real site by typing the address yourself.

  • "steamcomminity" is 1 letter away from "steamcommunity" (Valve (Steam Community and Market)). This is a classic lookalike spelling.
  • Checking the phishing list...

Before you log in anywhere

  • Got the link in a chat, comment or friend request? Treat it as a scam until you are sure.
  • Only type your Steam password or Steam Guard code on a site run by Valve, and read the address bar yourself.
  • Scammers use clever misspellings to make links look like they come from Valve. If in doubt, do not click.
  • Steam Support will never ask for your password or Steam Guard code.

Learn more: fake Steam login pages, API key scams and spotting scam trading sites.

Phishing list: DevSpen/scam-links (public domain). A link that is not on the list can still be a scam.

Domains we treat as the real thing

DomainOwner
steamcommunity.comValve (Steam Community and Market)
steampowered.comValve (Steam store, help, login and checkout)
store.steampowered.comValve (Steam store)
help.steampowered.comValve (Steam Support)
counter-strike.netValve (Counter-Strike 2 website)

Subdomains count too, so login.steampowered.com matches steampowered.com. Marketplace domains are added as we add each marketplace review.

Paste a link that someone sent you. The checker reads the real domain from the link and runs a set of tests on it. You get one of three results:

  • Known phishing (red): the domain is on an open list of Steam and Discord phishing sites.
  • Suspicious (amber): the domain shows warning signs, like a lookalike spelling of a real site.
  • Safe-looking (green): we found no warning signs. This does not prove the site is safe.

Each result lists the reasons, in plain words, so you can see why a link was flagged.

No. We never load the pasted link. The spelling tests run in your browser. To check the phishing list, only the domain name (like example.com) is sent to our server, never the full link. That keeps you safe and keeps any tracking codes in the link private.

What checks does it run?

CheckWhat it catchesExample
Official matchThe real Valve domains and their subdomainsstore.steampowered.com
Phishing listDomains reported as Steam or Discord scamsDomains on the DevSpen list
Lookalike spelling1 or 2 letters changed, added or removedsteamcomminity.com
Lookalike lettersNumbers or letters from other alphabetsst3amcommunity.com, a Cyrillic "е"
Hidden lettersAddresses that start with xn-- (punycode)xn--stamcommunity-x3k.com
Extra wordsA real name with words addedsteamcommunity-trade.com
Wrong endingThe real name on another domain endingsteamcommunity.ru
Subdomain trickThe real name placed before the true domainsteamcommunity.com.ru
@ trickText before an @ that the browser ignoressteampowered.com@evil.example
Number addressA bare IP address instead of a namehttp://203.0.113.5/login

Steam itself warns about this. Its Mobile Authenticator FAQ says: "Bad guys often try clever mis-spellings to make links look like they come from Valve. If you're in doubt, don't click on them."

Which domains are real?

These are the Valve domains the checker treats as official:

  • steamcommunity.com, the Steam Community and Community Market
  • steampowered.com, including store.steampowered.com and help.steampowered.com
  • counter-strike.net, the Counter-Strike 2 website

Subdomains of these count as real, so login.steampowered.com passes. Marketplace domains are added as we add each marketplace review, taken from the site address in our review data.

Where does the phishing list come from?

We use the open DevSpen/scam-links list on GitHub. It collects phishing and malicious links that focus on Steam and Discord scams, and it is released into the public domain under the Unlicense. A script downloads the list into our site, and the checker shows the date of the last download.

The list is community-run, so it can miss brand new domains. That is why the spelling checks matter. A fresh scam domain will not be on any list yet, but it still has to look like the real thing to fool you.

How does lookalike detection work?

The checker takes each part of the domain and compares it with the real names, like steamcommunity and steampowered. It counts how many single-letter changes turn one into the other. One or two changes is a classic scam trick, so it gets flagged.

Before comparing, it swaps common lookalikes back to plain letters. The number 0 becomes o, 1 becomes l, 3 becomes e, and "rn" becomes m. Letters from the Cyrillic and Greek alphabets that look like Latin letters get swapped too. So steamcornmunity.com and a version with a Cyrillic "е" are both caught.

A stranger sends you https://steamcommunity.com.ru/tradeoffer/new/ and says "check my trade offer". This domain is a real entry on the phishing list we downloaded on 24 Sep 2026.

  1. The site you would really visit is steamcommunity.com.ru, a Russian address. It is not steamcommunity.com.
  2. The checker sees steamcommunity.com inside the address and flags it as a subdomain trick.
  3. It then finds the domain on the phishing list.

Result: Known phishing site. A real Steam trade offer link always lives on steamcommunity.com itself.

A friend sends you https://steamcommunity.com/tradeoffer/new/?partner=123.

  1. The domain is exactly steamcommunity.com.
  2. That is an official Valve domain, so the result is Official Valve domain (green).

Even then, stay careful. A real trade link can still be part of a scam, for example a trade that swaps a valuable skin for a cheap one. Read the trade window before you confirm.

Do not open it, and never type your Steam login or Steam Guard code on it. If you want to visit Steam, type the address yourself or use the Steam app.

If you already logged in on a fake page, act fast. Change your password from the Steam app or client, check your Steam Guard settings and look for trade offers you did not make. Our guides explain what to look for:

When should I use this checker?

Use it every time a link asks you to sign in through Steam, especially links from chat, comments, Discord or friend requests. Use it before you log in to any trading site you have not used before.

If the site passes and you plan to sell there, compare what you would keep with the marketplace fee calculator. And if a trade goes wrong, the trade hold calculator shows how long CS2 Trade Protection lets a trade be reversed.

Frequently asked questions

How do I know if a Steam link is real?

Real Steam pages live on steamcommunity.com and steampowered.com (including store.steampowered.com and help.steampowered.com). Anything else that asks for your Steam login is not Steam, even if the name looks close.

What does a fake Steam link look like?

It often swaps one letter (steamcomminity.com), adds words (steamcommunity-tradeoffer.com), uses a different ending (steamcommunity.ru) or puts the real name first (steamcommunity.com.ru). All four are real entries on the phishing list, and the checker flags each of them.

Does this tool open the link I paste?

No. The checks run in your browser, and only the domain name is sent to our server to look it up in the phishing list. The page itself is never loaded.

The checker says safe-looking. Is the site safe?

Not for sure. It only means we found no warning signs and the domain is not on the list. New scam sites appear every day, so still check who sent you the link.

Where does the phishing list come from?

It is the open DevSpen/scam-links list on GitHub, which collects Steam and Discord scam domains and is released into the public domain. We download it with a script and show the date.

What should I do if I already logged in on a fake site?

Change your Steam password right away from the Steam app or client, check your Steam Guard settings and trade offers. Read our guide on securing your Steam account.

Try next