LINK & URL SUITE · 10 TOOLS

Link & URL Auditor

See where a link really goes before you open it. One box expands the full redirect chain, reads the TLS certificate, checks how old the domain is and flags look-alike spellings — without loading the page in your browser.

The link is never opened
Free, no sign-up
Nothing stored
The suite

The console above runs the four checks people reach for most. Each tool also has its own page with the full explanation, worked examples and its own FAQ.

Background

What each check actually tells you

Why check a link first?

Opening an unknown link can start a download, load a credential form or hand over a session token. Expanding it here reads the headers and the certificate without loading the page, so nothing runs on your machine.

How redirect chains unwrap

A short link rarely points straight at its destination. It usually passes through several 301/302 hops and a shortener like bit.ly or t.co. The tracer follows every hop and shows the final landing URL.

Punycode look-alike domains

A domain can be registered with Cyrillic or Greek letters that look identical to Latin ones — paypaI.com next to paypal.com. Mixed script sets are flagged and the raw Punycode (xn--) form is shown.

Entropy in a URL path

Machine-generated subdomains and paths look random: /auth/a8f9x29b1z. A Shannon entropy score puts a number on that randomness, which helps separate generated hosts from ordinary ones.

Why domain age matters

ICANN RDAP publishes when a domain was registered. A bank that has existed for fifteen years does not send you a link from a domain registered yesterday, so the registration date is a cheap sanity check.

QR codes hide their URL

A printed or emailed QR code gives you no way to read the destination before your camera opens it. Decoding the image here shows the URL in plain text first, then traces where it goes.

Further reading

Guides and reference

How IncogSay is built

What runs in your browser, what runs at the edge, and why nothing is written down.

Read it →

Email Suite

The other half of the same problem: SPF, DKIM, DMARC and BIMI on your own domain.

Open the suite →

Glossary

Punycode, RDAP, SAN, TLS 1.3 — the terms these results use, defined in one place.

Look it up →

FAQ

Answers about accuracy, what is stored, and what each tool can and cannot see.

Browse the FAQ →

Link & URL Auditor — frequently asked questions

QWhat does the link auditor check?

It inspects redirect chains, TLS certificates, domain registration age, typosquatting and homograph look-alikes, URL shorteners, path entropy, and — optionally — public reputation feeds.

QDoes it visit the link or run its JavaScript?

No. The audit uses DNS lookups, a TLS handshake and HTTP header probes at the edge. No page scripts are executed, so nothing can run a drive-by download on your machine.

QHow is the risk score calculated?

Scores run 0-100 from weighted signals: 0-15 is clean, 16-35 low risk, 36-60 worth a closer look, and 61-100 suspicious. The score is a summary of the checks below it, not a verdict on its own.

QCan I check a QR code?

Yes. Drop a QR code image into the dropzone and the encoded URL is extracted in your browser, then audited like any other link.

QIs any of this stored?

No. The URL you submit is resolved in memory at the edge and returned to you. Nothing is written to a database or a log, and there are no accounts.