HomeFree Tools › Link Expander
Free · Headers only · The page never loads

Where does that short link actually go?

Shorteners hide the destination by design. Paste one here and Scanify follows every redirect on its own servers, shows you the full chain, and checks the page at the end of it. Your browser never touches the link.

Up to 10 hops · headers only, no page content No account · No card · Free
10
hops followed
0
page content loaded
5s
time budget
Free
no sign-up

A shortened link is a promise you cannot inspect. Somebody hands you eight characters after a slash and asks you to trust that the other end is what they say it is. Most of the time it is. The times it is not are exactly the times that matter.

This page expands the link for you. Scanify requests the address from its own servers, follows each redirect it is given, and shows you the entire path. Crucially, it never downloads the page itself, only the headers that say where to go next, so nothing on the destination gets a chance to run.

Why shorteners are a security problem

Link shorteners exist for good reasons: character limits, print materials, click analytics, tidy referral links. But the same mechanism that makes them useful makes them ideal for delivery of anything you would refuse if you could see it.

How to read the redirect chain

The chain Scanify shows you is the sequence of addresses the link walks through. Most legitimate links have zero or one hop. A few patterns deserve attention.

A long chain

Four or more hops is unusual for an honest link. Chains that long are typically affiliate laundering or an attempt to shake off scanners that only follow one or two redirects.

Crossing many different domains

A link that passes through three or more unrelated domains is being routed rather than simply forwarded. That is normal in advertising technology and abnormal in a message from a friend.

An HTTPS to HTTP step

If any hop drops from an encrypted connection to an unencrypted one, everything after that point is visible to anyone on the network path. Scanify flags this explicitly because it is both a privacy failure and a sign of a carelessly built scam page.

A destination that does not match the pitch

The most useful check is the simplest. If a message claims to be your bank and the chain ends on a domain that is not your bank's, the question is settled regardless of any other signal.

What the tool checks at the end of the chain

Revealing the destination is half the job. Scanify then checks that destination for the signals that separate a real site from a scam page: how old the domain is, whether the TLS certificate is valid and matches the hostname, whether Google Safe Browsing already knows about it, and whether the hostname is imitating a well-known brand through a lookalike spelling or a credential-bait word.

Shorteners are not evidence of wrongdoing on their own. Scanify scores a hop from a known shortener far lower than an unexpected redirect from an ordinary domain, because the first is the tool working as intended and the second is a sign something is being hidden.

Which shorteners are supported

All of them. Scanify does not work from a list of known services; it follows whatever redirect the server returns, so it handles bit.ly, tinyurl.com, t.co, goo.gl, ow.ly, buff.ly, is.gd, cutt.ly, rebrand.ly, lnkd.in, custom branded shorteners and one-off redirectors identically. It also unwraps the tracking wrappers that email systems add, so a link mangled by a corporate mail gateway still resolves to its true destination.

Safer habits around shortened links

  1. Copy, do not click. On desktop, right-click and copy the link address. On a phone, press and hold and choose Copy link address. Then paste it here.
  2. Be suspicious of shorteners in email. Legitimate businesses rarely shorten links in transactional mail. They have no character limit and every reason to show you their own domain.
  3. Treat a shortener in an SMS as hostile by default. Text-message scams about parcels, tolls and bank alerts are overwhelmingly built on shortened links.
  4. Re-check links that have been around a while. Because some destinations can be edited after publication, a link in an old post is worth re-expanding before use.
  5. Never sign in through a shortened link. If a page reached this way asks for credentials, leave and navigate to the service directly.

How the expansion works technically

Scanify issues a request for the address and reads only the response headers. When the server answers with a redirect status and a location header, Scanify records the new address and repeats, up to ten hops, within a shared five-second budget. The response body is discarded the moment it arrives, so no scripts, images or tracking pixels from any page in the chain are ever fetched. Requests that would resolve to a private or internal network address are refused outright.

Frequently asked questions

How do I see where a bit.ly link goes without clicking it?
Copy the link rather than clicking it, paste it into this page and press Expand. Scanify follows the redirects on its own servers and shows you the final destination along with every hop in between.
Is it safe to expand a link this way?
Yes. The request happens on Scanify's servers, not in your browser, and only response headers are read. The page content is never downloaded, so nothing on the destination can run.
Can a short link change where it points?
Some shortening services let the owner edit the destination after the link has been shared. That is why a link which looked fine weeks ago is worth re-checking before you use it.
Why does the chain stop before a real page?
Scanify follows up to ten hops within a five-second budget and stops early if a host is unreachable or a loop appears. When that happens the result is marked as truncated, showing how far it got.
Does this work with links from Outlook or Gmail?
Yes. Corporate mail systems wrap links in their own tracking addresses. Scanify unwraps the common formats automatically so you see the real destination rather than the wrapper.
Does a shortened link mean something is wrong?
No. Shorteners have legitimate uses and are extremely common in marketing and social media. The concern is that they remove your ability to judge the destination, which is exactly what this tool restores.

Other free Scanify tools

URL Scanner Phishing Checker QR Code Checker Link Expander Fake Website Checker Scam Email Checker Bulk Checker File Scanner