QWhat does the link auditor check?
It inspects redirect chains, TLS certificates, domain registration age, typosquatting and homograph look-alikes, URL shorteners, path entropy, and — optionally — public reputation feeds.
See where a link really goes before you open it. One box expands the full redirect chain, reads the TLS certificate, checks how old the domain is and flags look-alike spellings — without loading the page in your browser.
The console above runs the four checks people reach for most. Each tool also has its own page with the full explanation, worked examples and its own FAQ.
Check any URL for lookalike domains, homograph tricks, odd entropy and known bad reputation before you open it.
Threat DetectionInspect a suspicious link, strip its tracking parameters and preview where it lands — without visiting it yourself.
Threat DetectionExpand short links and follow every hop — 301, 302, 307, 308 and meta refresh — with loop detection and headers.
DiagnosticsQuery ICANN RDAP for a domain’s real registration date, registrar and age — brand-new domains are worth a second look.
DiagnosticsRead a live TLS handshake: issuer, subject alternative names, cipher suite and exactly how many days until expiry.
InfrastructureDecode a QR code image or payload to reveal the URL hidden inside it, then trace where that URL goes.
Threat DetectionMake high-resolution QR codes for links, text or WiFi with custom colours and error correction, then download SVG or PNG.
UtilitiesGenerate strong random passwords, memorable passphrases and PINs with crypto.getRandomValues(), with live entropy and cracking-time estimates.
UtilitiesMeasure a password’s entropy in bits and see how long it would resist a GPU cracking rig. Typed characters never leave your browser.
UtilitiesGenerate an embeddable SVG trust badge for your own site showing TLS and DMARC status.
UtilitiesOpening an unknown link can start a download, load a credential form or hand over a session token. Expanding it here reads the headers and the certificate without loading the page, so nothing runs on your machine.
A short link rarely points straight at its destination. It usually passes through several 301/302 hops and a shortener like bit.ly or t.co. The tracer follows every hop and shows the final landing URL.
A domain can be registered with Cyrillic or Greek letters that look identical to Latin ones — paypaI.com next to paypal.com. Mixed script sets are flagged and the raw Punycode (xn--) form is shown.
Machine-generated subdomains and paths look random: /auth/a8f9x29b1z. A Shannon entropy score puts a number on that randomness, which helps separate generated hosts from ordinary ones.
ICANN RDAP publishes when a domain was registered. A bank that has existed for fifteen years does not send you a link from a domain registered yesterday, so the registration date is a cheap sanity check.
A printed or emailed QR code gives you no way to read the destination before your camera opens it. Decoding the image here shows the URL in plain text first, then traces where it goes.
What runs in your browser, what runs at the edge, and why nothing is written down.
The other half of the same problem: SPF, DKIM, DMARC and BIMI on your own domain.
Punycode, RDAP, SAN, TLS 1.3 — the terms these results use, defined in one place.
Answers about accuracy, what is stored, and what each tool can and cannot see.
It inspects redirect chains, TLS certificates, domain registration age, typosquatting and homograph look-alikes, URL shorteners, path entropy, and — optionally — public reputation feeds.
No. The audit uses DNS lookups, a TLS handshake and HTTP header probes at the edge. No page scripts are executed, so nothing can run a drive-by download on your machine.
Scores run 0-100 from weighted signals: 0-15 is clean, 16-35 low risk, 36-60 worth a closer look, and 61-100 suspicious. The score is a summary of the checks below it, not a verdict on its own.
Yes. Drop a QR code image into the dropzone and the encoded URL is extracted in your browser, then audited like any other link.
No. The URL you submit is resolved in memory at the edge and returned to you. Nothing is written to a database or a log, and there are no accounts.