Paste a link to see what it is really made of: every component, the percent-encoding peeled off layer by layer, an editable
table of query parameters with a one-click tracker stripper, and a safety panel that flags embedded credentials, punycode
and lookalike hosts, path traversal, header injection, dangerous schemes and secrets carried in the query string.
Need the encoding step on its own? Use the
URL encoder and decoder; for the
xn-- form of an internationalised host use the
punycode converter.
The parser itself never sends the link anywhere.
How to read the safety panel: every line is a pattern that shows up in real phishing and malformed links, not a
verdict about the site. A
notice line is normal for many legitimate URLs (a
http link is simply not encrypted,
and an IP address host is common on internal networks), a
caution line deserves a second look, and a
risk line means
the link is doing something a plain link never needs to do. The checks look at the text of the URL only: this page never
fetches the link, resolves the host, or contacts the site behind it.
Encoding note: a host written with
xn-- is a punycode host. Because lookalike characters from other
scripts render almost identically, decode it before you trust it — the
punycode converter
does that, and the
URL encoder handles the
%xx form you can see in the decoding table.
Privacy: parsing, decoding and every check run in your browser. The URL you paste is never uploaded, and
nothing is stored after you close the page.