How to inspect a short link before you open it
A short link hides the destination until something resolves it. That is useful for a clean URL and also useful to someone sending a phishing page. Linkora splits destinations into three outcomes: rejected, allowed with a warning, or redirected immediately.
Rejected before a code exists
- Any scheme other than http or https, including javascript: and data:.
- A username or password embedded in the URL.
- localhost, .local, .internal, and single-label hostnames.
- Private, loopback, link-local, and carrier-grade NAT addresses, including dotted forms with leading zeros.
- A destination on this service’s own host, which would create a redirect loop.
- A host an administrator has placed on the denylist.
Allowed, but stopped on a warning page
Some URLs are technically valid and still a common place to hide a trick. Linkora marks them as caution and, unless an administrator turns the interstitial off, shows a page that names the host and the reason. Nothing is fetched from the destination while that decision is made. The service does not connect to the URL, which avoids using the shortener as a proxy into someone else’s network.
- A public IP address instead of a domain.
- Punycode labels (xn--), which can imitate another brand.
- A deep stack of subdomains.
- A nonstandard port.
- Another shortener, such as bit.ly or tinyurl.com, which hides one more hop.
- Hostname labels such as login or verify on a domain that is not a well-known provider.
- A very long URL, or non-ASCII characters in the original text.
The warning page does not refresh itself and does not load the destination in a frame. Continuing is a form submission with a short-lived signed token. A prefetch of the short link does not count as agreement and does not count as a human click.
What you can still do
Read the host before you continue. If the short link was supposed to be a document from a company, and the host is an unrelated domain, close it. If you think the link is malicious, use the abuse report on this site and include the short code. Reports are stored and reviewed; they do not silently delete the link by themselves.