Where does that link really go?
Shortened links from bit.ly, t.co, tinyurl, and QR codes hide their destination — which is exactly why scammers love them. Paste one below and our server follows the redirects for you, showing the full chain and final domain while your device stays out of it.
How to judge the result
Reassuring
- One or two hops ending at a domain that matches the sender
- An https final destination
- A recognizable brand domain, spelled exactly right
Suspicious
- Long chains through multiple tracking domains
- A final domain imitating a brand with typos or extra words
- Links that end at login or payment pages you did not expect
- Chains that mix multiple URL shorteners
What this tool can and cannot see
The trace follows HTTP redirects — the mechanism shorteners and trackers use. It cannot see JavaScript redirects that run after a page loads, and some links behave differently per visitor (a scam page may show content only to phone users, for example). A clean trace lowers the risk; it does not certify the page. For a second signal, check the final domain's registration age with our whois lookup — legitimate brands have old domains.
Checking links from QR codes
QR codes are the newest delivery route for disguised links. Decode the image first with our QR code decoder (it runs offline in your browser), then expand whatever link it contains here. Two checks, and the sticker-on-a-parking-meter scam has nothing left to hide behind.