Link inspector
See where a link really goes before you open or shorten it: the real host, lookalike letters, hidden redirects and tracking parameters.
Runs entirely in your browser. Nothing you enter here is sent to the server.
Only the text is read. This page never visits the link, never looks the name up and never sends it anywhere. In a longer message the first link is used.
What each warning means
The link is taken apart by the browser's own URL parser, the same one that would follow it, so what you see here is where a click really goes. Nothing is fetched: this page does not know what the site says, only how the link is written.
- Something before an @
- In
https://[email protected]the site isevil.example. Everything before the@is a user name the site is free to ignore. - A bare IP address
- No name, so nothing says whose server it is. Numbers can be
written in odd ways that still work:
http://3232235777is192.168.1.1. Private and loopback addresses point into your own network or computer. - Mixed alphabets
- Cyrillic
аand Latinalook the same and are different letters, sopаypal.comwith one Cyrillic letter is someone else's site. The browser sends such names to DNS asxn--; both forms are shown. - Invisible characters
- Zero-width spaces and direction overrides change how a link reads without changing where it goes.
- Not http or https
javascript:runs code,data:carries a whole page with it,file:opens something on your own disk. None of these gets an Open button.- Links inside a link
- Parameters like
url=,next=orredirect=often hold the address you are sent on to. Press Inspect to check that one the same way. - Tracking parameters
utm_*,fbclid,gclidand friends tell someone where the click came from. The clean copy leaves them out and keeps everything else exactly as it was.
No warning does not mean the site is safe. A well-formed link to a freshly registered lookalike domain passes every check here.
Other tools
- Code scanner — Read QR codes and barcodes with your camera or from an image. Every format ZXing knows.
- Code generator — Make a QR code, Data Matrix, Aztec, PDF417 or a linear barcode and download it.
- Base converter — Encode and decode between text and Base2 through Base85, or convert integers between any two bases.
- Hash generator — MD5, SHA family, CRC32 and MySQL5 over text or a file. The file is read in your browser.
- JWT decoder — Read a JSON Web Token's header and claims, with every timestamp as a date. Decoded right here; the token is never sent or stored.
- SSH key fingerprint — SHA256 and MD5 fingerprints, key type and size, and SSHFP records for a public key. Private keys are refused unread.
- Password generator — Random passwords from a CSPRNG, with the character classes you pick.
- TOTP generator — Turn a TOTP secret or otpauth:// link into the current code. The secret stays on your device.
- Timestamp converter — Unix time to a calendar date and back, in every format at once. Live clock included.
- Subnet calculator — IPv4 and IPv6: network, range, host count, masks and reverse-DNS pointers.
- Image resizer — Resize and convert an image without it ever leaving your browser. Re-encoding drops EXIF and GPS.
- IP info — Your public IPv4 and IPv6, as this server sees them.
- PHP obfuscator — Wrap PHP so it self-decodes at runtime. Runs on the server; the code is never stored.